Skip to main content
Integrations connect third-party applications to your workspace. They work in two directions:
  • Inbound — a cloud provider sends OASM the assets it knows about, so your inventory stays current without manual imports.
  • Outbound — OASM sends alerts to the channels your team already uses, so the right people hear about new findings.
Integrations are workspace-scoped. You connect, configure, and manage them in the workspace selected in the sidebar. The same application can be connected to several workspaces independently.

Kinds of integrations

Every integration belongs to one category. The category decides what the integration does and which fields its connection form shows.

Available integrations

AWS

Discover public-exposure resources across accounts and regions

Cloudflare

Sync zones and DNS records into targets and assets

Vercel

Discover projects and their production domains

Slack

Send alerts to a Slack channel via incoming webhook

Telegram

Send alerts to paired Telegram chats via a bot

Webhook

Forward events to any endpoint you control

Key concepts

Connect an integration

1

Select the target workspace

Choose the workspace in the workspace menu at the top of the sidebar. The Integrations page always applies to the selected workspace.
2

Open the Applications tab

In the console sidebar, open Integrations. The Applications tab lists every available application. Use the search box to find one by name, or the category dropdown to filter the list.
3

Open the application

Select the application card. The connection form opens as a sheet on the right.
4

Enter a name and fill in the configuration

Enter an Integration name, then fill in the app-specific fields — for example, an API token or webhook URL. Each guide below lists the exact fields.
5

Configure the notification toggles

Notification integrations also show Event and Severity switches. Use them to choose what the integration sends. Cloud providers skip this step and show a Sync schedule instead.
6

Connect

Select Connect. OASM validates the configuration, stores it, and the integration moves to the Connected tab.
For a notification integration, OASM sends a welcome message as soon as it connects. If that message fails — for example, because a Slack webhook was revoked — the integration stays connected and the failure is logged.

Manage a connected integration

Open the Connected tab and select an integration card to open its detail sheet.
Disconnecting an integration is permanent. Its configuration cannot be recovered, and you must reconnect it from the Applications tab to use it again.

Secrets and security

Configuration fields that hold credentials are encrypted at rest and never shown in full after you save them.
  • Sensitive fields — API tokens, bot tokens, secret keys, session tokens, external IDs, and refresh tokens — are encrypted with the workspace key before storage.
  • In the console and API responses, a stored secret appears masked as **** followed by its last four characters.
  • To keep a stored secret, leave the masked field untouched when editing. To replace it, type a new value.
  • If a test or sync fails after you edit another field, confirm the secret is still valid — an empty replacement leaves the integration misconfigured.
Non-secret fields such as a Slack webhook URL or a webhook endpoint URL are stored as provided. Treat every credential as sensitive: rotate tokens on a schedule and after personnel changes.

What notification integrations send

OASM forwards three event types to notification integrations: The Event switches on the connection form control which of these types the integration receives. The Severity switches are part of the same form; Critical and High are on by default, while Medium, Low, and Info are off. Events that are not in the list above — for example, workspace invitations or analysis-completed events — are delivered to the in-console notification center only. See Notifications for the full list of events.

Schedule asset syncs

Cloud provider integrations can sync automatically on a cron schedule.
1

Open the integration

In the Connected tab, select the cloud provider integration to open its detail sheet.
2

Open the edit form

Select Edit.
3

Turn on the schedule

Turn on Sync schedule, then build a schedule in the cron builder. Schedules are stored in UTC.
4

Save

Select Save. The schedule is registered immediately and the next run time appears on the detail sheet.
  • A schedule is optional. With it off, the integration syncs only when you select Sync now.
  • Schedules apply to cloud providers only. Notification and ticketing integrations do not support them.
  • AWS workload identity integrations cannot use a schedule because their token is short-lived. Set the schedule to off and run manual syncs instead.
  • Only one sync runs per integration at a time. Selecting Sync now while a sync is pending returns the existing job rather than starting a second one.

Permissions

Integrations are guarded by two permissions: If a control is hidden or disabled, your role lacks integration.write. See Permissions and Members.

Notifications

See the events that can be forwarded to notification integrations

API keys

Manage workspace credentials used by integrations and API clients

Troubleshooting

Diagnose connection and delivery problems