Skip to main content
Telara

Integrations / Snyk

Snyk logo

Snyk

Snyk security platform for organizations, projects, targets, issues, dependencies, packages, and vulnerability evidence.

OAuth 2.0
Indexes
Actions
Events

What Telara does

Capability matrix

Before you connect

Prerequisites

A Snyk organization you can administer.
Org admin, or permission to create a service account token.

Vendor setup

Get the credential

1
Prefer Connect
Settings → Integrations → Snyk. Approve access in Snyk. You do not register a Snyk App.
2
Token fallback
In Snyk, Account settings → General → API Token (or a service account token). Paste it in Telara.

Permissions Telara requests

  • org.read
    OAuth 2.0
  • org.project.read
    OAuth 2.0
  • org.project.snapshot.read
    OAuth 2.0
  • org.project.create
    OAuth 2.0
  • org.project.edit
    OAuth 2.0
  • org.project.delete
    OAuth 2.0
  • org.project.status
    OAuth 2.0
  • org.project.test
    OAuth 2.0
  • org.project.ignore.create
    OAuth 2.0
  • org.project.ignore.edit
    OAuth 2.0
  • org.project.ignore.delete
    OAuth 2.0
  • org.project.tag.edit
    OAuth 2.0
  • org.project.attributes.edit
    OAuth 2.0
  • org.collection.create
    OAuth 2.0
  • org.collection.edit
    OAuth 2.0
  • org.collection.delete
    OAuth 2.0
  • org.package.test
    OAuth 2.0

In Telara

Connect in Telara

OAuth 2.0

Snyk App OAuth credentials.

In Telara, open Settings → Integrations, choose this connector, and click Connect. Telara sends you to the vendor to approve access, then returns you here. You do not create an OAuth app or paste a client secret.

API key

Snyk API or service account token.

In Telara, open Settings → Integrations, choose this connector, and paste the key into the fields Telara shows.

Fields Telara asks for
  • API token

Knowledge

What gets indexed

ResourceCoverage
OrganizationPartial — not every record the vendor holds is synced
TargetPartial — not every record the vendor holds is synced
VulnerabilityPartial — not every record the vendor holds is synced
ProjectsPartial — not every record the vendor holds is synced

Sync

Freshness & sync

ResourceLagDeletions
OrganizationUp to 1 hourRemoved records disappear on the next full sync
TargetUp to 1 hourRemoved records disappear on the next full sync
VulnerabilityUp to 1 hourRemoved records disappear on the next full sync
ProjectsUp to 1 hourRemoved records disappear on the next full sync

Data handling

Permissions & data handling

The scopes above are the permissions this connector requests. They come from the catalog, not from a hand-written page.

Excluded from semantic search: Organization, Target, Vulnerability, Projects.

After connect

Verify it worked

After you save, Telara runs a read-only check against the account. The integration shows as connected when that check succeeds.

Honesty

Known limitations

Personal tokens only see orgs that user belongs to.
A token from a different Snyk region (SNYK-US vs EU) will not read the org you meant.