Prerequisites
- A Vercel account or team with at least one project.
- A Vercel access token with permission to read projects. Create one in Account Settings → Tokens.
- For team-scoped tokens, the team ID — optional for most tokens.
Connect Vercel
1
Open the Applications tab
In the console sidebar, open Integrations and select the Applications tab.
2
Open Vercel
Select the Vercel card.
3
Enter a name and access token
Enter an Integration name, then paste your Vercel Access Token.
4
Add a team ID (optional)
If the token belongs to a team and you want to target a specific team, enter its Team ID. Leave it blank to use the token’s default scope.
5
Set a sync schedule (optional)
Turn on Sync schedule and build a cron schedule, or leave it off to sync manually. See Schedule asset syncs.
6
Connect
Select Connect. OASM validates the token against Vercel before saving the integration.
What Vercel sync finds
The sync lists every project the token can read, then each project’s production custom domains.- Domains are grouped by their apex name. Each apex — for example,
example.com— becomes one domain target. - Each hostname under an apex — for example,
www.example.com— becomes an asset under that target. - Default
<project>.vercel.apphosts and unverified custom domains are included, because they are live and scannable. - Wildcard domains, redirects, and preview or branch hosts are excluded. A preview host is not production attack surface.
- Vercel exposes no DNS records, so discovered assets start without records. Scanners fill them in later.
The sync never fabricates a hostname. If a project has no production custom domain, no target is created for it.
Test and sync
- Test Integration performs a read-only check against the Vercel API and confirms the token works. It writes nothing.
- Sync now queues a real sync. The detail sheet shows the last run time.
- A scheduled sync uses the same code path as Sync now.
Troubleshooting
A project or domain is missing
A project or domain is missing
Confirm the token can read the project and that the domain is a verified production custom domain. Wildcards, redirects, and preview hosts are intentionally excluded.
The wrong team's projects are synced
The wrong team's projects are synced
The token’s scope decides which projects are visible. For team-scoped tokens, set the Team ID, or use a token issued for the team you want.
Related
Targets
Review the apex domains Vercel sync adds
Assets
See the hostnames discovered under each apex
Integrations overview
Learn how connections, secrets, and schedules work
