Integrations / Semgrep
Semgrep
Semgrep AppSec Platform for deployments, projects, findings, rules, scans, and software security evidence.
API key
Indexes
Actions
Events
What Telara does
Capability matrix
Before you connect
Prerequisites
A Semgrep AppSec Platform org you can administer.
Admin who can create an API token under Settings.
Vendor setup
Get the credential
1
Open Tokens
In Semgrep Cloud, go to Settings → Tokens (or Settings → API tokens).
2
Create a token
Click Create new token. Name it for Telara. Copy it once. Prefer a service account token over a personal token when you can.
3
Paste in Telara
Settings → Integrations → Semgrep. Paste the token into the field Telara shows.
In Telara
Connect in Telara
API key
Semgrep API or service token.
In Telara, open Settings → Integrations, choose this connector, and paste the key into the fields Telara shows.
Fields Telara asks for
- API token
Knowledge
What gets indexed
| Resource | Coverage |
|---|---|
| Security finding | Partial — not every record the vendor holds is synced |
Sync
Freshness & sync
| Resource | Lag | Deletions |
|---|---|---|
| Security finding | Up to 1 day | Removed records disappear on the next full sync |
Data handling
Permissions & data handling
Telara has not published a permission list for this connector yet. Treat the vendor consent screen as the source of truth until this page lists scopes.
Excluded from semantic search: Security finding.
After connect
Verify it worked
After you save, Telara runs a read-only check against the account. The integration shows as connected when that check succeeds.
Honesty
Known limitations
A token that cannot read findings connects and then lists none.
Semgrep Community (local CLI only) has no org token to paste.

