Skip to main content
The Vercel integration reads the projects in a Vercel account and the production domains attached to them. Each apex domain becomes a scan target, and each hostname under it becomes an asset.

Prerequisites

  • A Vercel account or team with at least one project.
  • A Vercel access token with permission to read projects. Create one in Account Settings → Tokens.
  • For team-scoped tokens, the team ID — optional for most tokens.

Connect Vercel

1

Open the Applications tab

In the console sidebar, open Integrations and select the Applications tab.
2

Open Vercel

Select the Vercel card.
3

Enter a name and access token

Enter an Integration name, then paste your Vercel Access Token.
4

Add a team ID (optional)

If the token belongs to a team and you want to target a specific team, enter its Team ID. Leave it blank to use the token’s default scope.
5

Set a sync schedule (optional)

Turn on Sync schedule and build a cron schedule, or leave it off to sync manually. See Schedule asset syncs.
6

Connect

Select Connect. OASM validates the token against Vercel before saving the integration.

What Vercel sync finds

The sync lists every project the token can read, then each project’s production custom domains.
  • Domains are grouped by their apex name. Each apex — for example, example.com — becomes one domain target.
  • Each hostname under an apex — for example, www.example.com — becomes an asset under that target.
  • Default <project>.vercel.app hosts and unverified custom domains are included, because they are live and scannable.
  • Wildcard domains, redirects, and preview or branch hosts are excluded. A preview host is not production attack surface.
  • Vercel exposes no DNS records, so discovered assets start without records. Scanners fill them in later.
The sync never fabricates a hostname. If a project has no production custom domain, no target is created for it.

Test and sync

  • Test Integration performs a read-only check against the Vercel API and confirms the token works. It writes nothing.
  • Sync now queues a real sync. The detail sheet shows the last run time.
  • A scheduled sync uses the same code path as Sync now.

Troubleshooting

The token is invalid, expired, or lacks project read access. Generate a new token in Vercel and reconnect.
Confirm the token can read the project and that the domain is a verified production custom domain. Wildcards, redirects, and preview hosts are intentionally excluded.
The token’s scope decides which projects are visible. For team-scoped tokens, set the Team ID, or use a token issued for the team you want.

Targets

Review the apex domains Vercel sync adds

Assets

See the hostnames discovered under each apex

Integrations overview

Learn how connections, secrets, and schedules work