> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oasm.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Vercel

> Discover Vercel projects and their production domains as attack surface targets and assets

The Vercel integration reads the projects in a Vercel account and the production domains attached to them. Each apex domain becomes a scan target, and each hostname under it becomes an asset.

## Prerequisites

* A Vercel account or team with at least one project.
* A Vercel **access token** with permission to read projects. Create one in **Account Settings → Tokens**.
* For team-scoped tokens, the **team ID** — optional for most tokens.

## Connect Vercel

<Steps>
  <Step title="Open the Applications tab">
    In the console sidebar, open **Integrations** and select the **Applications** tab.
  </Step>

  <Step title="Open Vercel">
    Select the **Vercel** card.
  </Step>

  <Step title="Enter a name and access token">
    Enter an **Integration name**, then paste your **Vercel Access Token**.
  </Step>

  <Step title="Add a team ID (optional)">
    If the token belongs to a team and you want to target a specific team, enter its **Team ID**. Leave it blank to use the token's default scope.
  </Step>

  <Step title="Set a sync schedule (optional)">
    Turn on **Sync schedule** and build a cron schedule, or leave it off to sync manually. See [Schedule asset syncs](/integrations/overview#schedule-asset-syncs).
  </Step>

  <Step title="Connect">
    Select **Connect**. OASM validates the token against Vercel before saving the integration.
  </Step>
</Steps>

## What Vercel sync finds

The sync lists every project the token can read, then each project's production custom domains.

* Domains are grouped by their **apex** name. Each apex — for example, `example.com` — becomes one **domain** target.
* Each hostname under an apex — for example, `www.example.com` — becomes an **asset** under that target.
* Default `<project>.vercel.app` hosts and unverified custom domains are included, because they are live and scannable.
* Wildcard domains, redirects, and preview or branch hosts are excluded. A preview host is not production attack surface.
* Vercel exposes no DNS records, so discovered assets start without records. Scanners fill them in later.

<Info>
  The sync never fabricates a hostname. If a project has no production custom domain, no target is created for it.
</Info>

## Test and sync

* **Test Integration** performs a read-only check against the Vercel API and confirms the token works. It writes nothing.
* **Sync now** queues a real sync. The detail sheet shows the last run time.
* A scheduled sync uses the same code path as **Sync now**.

## Troubleshooting

<Accordion title="Connect fails with an authorization error">
  The token is invalid, expired, or lacks project read access. Generate a new token in Vercel and reconnect.
</Accordion>

<Accordion title="A project or domain is missing">
  Confirm the token can read the project and that the domain is a verified production custom domain. Wildcards, redirects, and preview hosts are intentionally excluded.
</Accordion>

<Accordion title="The wrong team's projects are synced">
  The token's scope decides which projects are visible. For team-scoped tokens, set the **Team ID**, or use a token issued for the team you want.
</Accordion>

## Related

<Card icon="crosshair" title="Targets" horizontal href="/target">
  Review the apex domains Vercel sync adds
</Card>

<Card icon="box" title="Assets" horizontal href="/asset">
  See the hostnames discovered under each apex
</Card>

<Card icon="plug" title="Integrations overview" horizontal href="/integrations/overview">
  Learn how connections, secrets, and schedules work
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.