> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oasm.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Integrations

> Connect third-party applications to pull assets in and push alerts out of your workspace

Integrations connect third-party applications to your workspace. They work in two directions:

* **Inbound** — a cloud provider sends OASM the assets it knows about, so your inventory stays current without manual imports.
* **Outbound** — OASM sends alerts to the channels your team already uses, so the right people hear about new findings.

<Info>
  Integrations are **workspace-scoped**. You connect, configure, and manage them in the workspace selected in the sidebar. The same application can be connected to several workspaces independently.
</Info>

## Kinds of integrations

Every integration belongs to one category. The category decides what the integration does and which fields its connection form shows.

| Category | Direction | What it does | Applications |
| - | - | - | - |
| **Cloud provider** | Inbound | Pulls assets from a cloud account into your inventory on a schedule | [AWS](/integrations/aws), [Cloudflare](/integrations/cloudflare), [Vercel](/integrations/vercel) |
| **Notification** | Outbound | Forwards security events to a chat channel or endpoint | [Slack](/integrations/slack), [Telegram](/integrations/telegram), [Webhook](/integrations/webhook) |
| **Ticketing** | Outbound | Creates tracked work items from findings | Not yet available — see [Ticketing](/integrations/ticketing) |

## Available integrations

<Card icon="cloud" title="AWS" horizontal href="/integrations/aws">
  Discover public-exposure resources across accounts and regions
</Card>

<Card icon="cloud" title="Cloudflare" horizontal href="/integrations/cloudflare">
  Sync zones and DNS records into targets and assets
</Card>

<Card icon="triangle" title="Vercel" horizontal href="/integrations/vercel">
  Discover projects and their production domains
</Card>

<Card icon="slack" title="Slack" horizontal href="/integrations/slack">
  Send alerts to a Slack channel via incoming webhook
</Card>

<Card icon="send" title="Telegram" horizontal href="/integrations/telegram">
  Send alerts to paired Telegram chats via a bot
</Card>

<Card icon="webhook" title="Webhook" horizontal href="/integrations/webhook">
  Forward events to any endpoint you control
</Card>

## Key concepts

<Table>
  | Concept | Description |
  | - | - |
  | Integration | A connection between one third-party application and one workspace. |
  | Category | The integration's job: cloud provider, notification, or ticketing. Fixed by the application. |
  | App type | The specific third-party application — for example, `cloudflare` or `slack`. |
  | Configuration | The app-specific settings an integration needs, such as an API token. Validated when you save. |
  | Applications tab | The catalog of integrations you can connect. |
  | Connected tab | The integrations already connected to the current workspace. |
</Table>

## Connect an integration

<Steps>
  <Step title="Select the target workspace">
    Choose the workspace in the workspace menu at the top of the sidebar. The Integrations page always applies to the selected workspace.
  </Step>

  <Step title="Open the Applications tab">
    In the console sidebar, open **Integrations**. The **Applications** tab lists every available application. Use the search box to find one by name, or the category dropdown to filter the list.
  </Step>

  <Step title="Open the application">
    Select the application card. The connection form opens as a sheet on the right.
  </Step>

  <Step title="Enter a name and fill in the configuration">
    Enter an **Integration name**, then fill in the app-specific fields — for example, an API token or webhook URL. Each guide below lists the exact fields.
  </Step>

  <Step title="Configure the notification toggles">
    Notification integrations also show **Event** and **Severity** switches. Use them to choose what the integration sends. Cloud providers skip this step and show a **Sync schedule** instead.
  </Step>

  <Step title="Connect">
    Select **Connect**. OASM validates the configuration, stores it, and the integration moves to the **Connected** tab.
  </Step>
</Steps>

For a notification integration, OASM sends a welcome message as soon as it connects. If that message fails — for example, because a Slack webhook was revoked — the integration stays connected and the failure is logged.

## Manage a connected integration

Open the **Connected** tab and select an integration card to open its detail sheet.

| Action | Where | Notes |
| - | - | - |
| Edit | **Edit** | Change the name or configuration. Saving re-validates the configuration. |
| Test | **Test Integration** | Sends a test message. For cloud providers, runs a read-only dry run instead. |
| Sync now | **Sync now** (cloud providers) | Queues an immediate asset sync. The sync runs in the background. |
| Pair devices | **Telegram Pairing** (Telegram only) | Pair or remove Telegram chats. See [Telegram](/integrations/telegram). |
| Disconnect | **...** menu → **Disconnect** | Permanently removes the integration from the workspace. |

<Danger>
  Disconnecting an integration is permanent. Its configuration cannot be recovered, and you must reconnect it from the **Applications** tab to use it again.
</Danger>

## Secrets and security

Configuration fields that hold credentials are encrypted at rest and never shown in full after you save them.

* Sensitive fields — API tokens, bot tokens, secret keys, session tokens, external IDs, and refresh tokens — are **encrypted with the workspace key** before storage.
* In the console and API responses, a stored secret appears masked as `****` followed by its last four characters.
* To keep a stored secret, leave the masked field untouched when editing. To replace it, type a new value.
* If a test or sync fails after you edit another field, confirm the secret is still valid — an empty replacement leaves the integration misconfigured.

<Info>
  Non-secret fields such as a Slack webhook URL or a webhook endpoint URL are stored as provided. Treat every credential as sensitive: rotate tokens on a schedule and after personnel changes.
</Info>

## What notification integrations send

OASM forwards three event types to notification integrations:

| Event | When it fires |
| - | - |
| **New asset detected** | Discovery finds a new asset for a target. |
| **Scan incomplete** | A scan ends before its workflow finishes. |
| **New vulnerability found** | A scan detects a new vulnerability on an asset. |

The **Event** switches on the connection form control which of these types the integration receives. The **Severity** switches are part of the same form; **Critical** and **High** are on by default, while **Medium**, **Low**, and **Info** are off.

Events that are not in the list above — for example, workspace invitations or analysis-completed events — are delivered to the in-console notification center only. See [Notifications](/notifications) for the full list of events.

## Schedule asset syncs

Cloud provider integrations can sync automatically on a cron schedule.

<Steps>
  <Step title="Open the integration">
    In the **Connected** tab, select the cloud provider integration to open its detail sheet.
  </Step>

  <Step title="Open the edit form">
    Select **Edit**.
  </Step>

  <Step title="Turn on the schedule">
    Turn on **Sync schedule**, then build a schedule in the cron builder. Schedules are stored in **UTC**.
  </Step>

  <Step title="Save">
    Select **Save**. The schedule is registered immediately and the next run time appears on the detail sheet.
  </Step>
</Steps>

* A schedule is optional. With it off, the integration syncs only when you select **Sync now**.
* Schedules apply to cloud providers only. Notification and ticketing integrations do not support them.
* **AWS workload identity** integrations cannot use a schedule because their token is short-lived. Set the schedule to off and run manual syncs instead.
* Only one sync runs per integration at a time. Selecting **Sync now** while a sync is pending returns the existing job rather than starting a second one.

## Permissions

Integrations are guarded by two permissions:

| Permission | Allows |
| - | - |
| `integration.read` | View the catalog, connected integrations, and their configuration. |
| `integration.write` | Connect, edit, test, sync, and disconnect integrations. |

If a control is hidden or disabled, your role lacks `integration.write`. See [Permissions](/permissions) and [Members](/members).

## Related

<Card icon="bell" title="Notifications" horizontal href="/notifications">
  See the events that can be forwarded to notification integrations
</Card>

<Card icon="key" title="API keys" horizontal href="/api-keys">
  Manage workspace credentials used by integrations and API clients
</Card>

<Card icon="triangle-alert" title="Troubleshooting" horizontal href="/troubleshooting">
  Diagnose connection and delivery problems
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.