- Inbound — a cloud provider sends OASM the assets it knows about, so your inventory stays current without manual imports.
- Outbound — OASM sends alerts to the channels your team already uses, so the right people hear about new findings.
Integrations are workspace-scoped. You connect, configure, and manage them in the workspace selected in the sidebar. The same application can be connected to several workspaces independently.
Kinds of integrations
Every integration belongs to one category. The category decides what the integration does and which fields its connection form shows.Available integrations
AWS
Discover public-exposure resources across accounts and regions
Cloudflare
Sync zones and DNS records into targets and assets
Vercel
Discover projects and their production domains
Slack
Send alerts to a Slack channel via incoming webhook
Telegram
Send alerts to paired Telegram chats via a bot
Webhook
Forward events to any endpoint you control
Key concepts
Connect an integration
1
Select the target workspace
Choose the workspace in the workspace menu at the top of the sidebar. The Integrations page always applies to the selected workspace.
2
Open the Applications tab
In the console sidebar, open Integrations. The Applications tab lists every available application. Use the search box to find one by name, or the category dropdown to filter the list.
3
Open the application
Select the application card. The connection form opens as a sheet on the right.
4
Enter a name and fill in the configuration
Enter an Integration name, then fill in the app-specific fields — for example, an API token or webhook URL. Each guide below lists the exact fields.
5
Configure the notification toggles
Notification integrations also show Event and Severity switches. Use them to choose what the integration sends. Cloud providers skip this step and show a Sync schedule instead.
6
Connect
Select Connect. OASM validates the configuration, stores it, and the integration moves to the Connected tab.
Manage a connected integration
Open the Connected tab and select an integration card to open its detail sheet.Disconnecting an integration is permanent. Its configuration cannot be recovered, and you must reconnect it from the Applications tab to use it again.
Secrets and security
Configuration fields that hold credentials are encrypted at rest and never shown in full after you save them.- Sensitive fields — API tokens, bot tokens, secret keys, session tokens, external IDs, and refresh tokens — are encrypted with the workspace key before storage.
- In the console and API responses, a stored secret appears masked as
****followed by its last four characters. - To keep a stored secret, leave the masked field untouched when editing. To replace it, type a new value.
- If a test or sync fails after you edit another field, confirm the secret is still valid — an empty replacement leaves the integration misconfigured.
Non-secret fields such as a Slack webhook URL or a webhook endpoint URL are stored as provided. Treat every credential as sensitive: rotate tokens on a schedule and after personnel changes.
What notification integrations send
OASM forwards three event types to notification integrations:
The Event switches on the connection form control which of these types the integration receives. The Severity switches are part of the same form; Critical and High are on by default, while Medium, Low, and Info are off.
Events that are not in the list above — for example, workspace invitations or analysis-completed events — are delivered to the in-console notification center only. See Notifications for the full list of events.
Schedule asset syncs
Cloud provider integrations can sync automatically on a cron schedule.1
Open the integration
In the Connected tab, select the cloud provider integration to open its detail sheet.
2
Open the edit form
Select Edit.
3
Turn on the schedule
Turn on Sync schedule, then build a schedule in the cron builder. Schedules are stored in UTC.
4
Save
Select Save. The schedule is registered immediately and the next run time appears on the detail sheet.
- A schedule is optional. With it off, the integration syncs only when you select Sync now.
- Schedules apply to cloud providers only. Notification and ticketing integrations do not support them.
- AWS workload identity integrations cannot use a schedule because their token is short-lived. Set the schedule to off and run manual syncs instead.
- Only one sync runs per integration at a time. Selecting Sync now while a sync is pending returns the existing job rather than starting a second one.
Permissions
Integrations are guarded by two permissions:
If a control is hidden or disabled, your role lacks
integration.write. See Permissions and Members.
Related
Notifications
See the events that can be forwarded to notification integrations
API keys
Manage workspace credentials used by integrations and API clients
Troubleshooting
Diagnose connection and delivery problems
