diff --git a/integrations-catalog/README.md b/integrations-catalog/README.md index bef5f03b5f..422f7f8f0c 100644 --- a/integrations-catalog/README.md +++ b/integrations-catalog/README.md @@ -2,9 +2,9 @@ Public catalog of all compliance integrations available in the [CompAI](https://trycomp.ai) platform. -**583 integrations** across 9 categories. +**590 integrations** across 9 categories. -> Last updated: 2026-05-11 +> Last updated: 2026-08-09 ## What's in this catalog @@ -33,25 +33,26 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ ## Summary by category -- **Security** — 134 integrations +- **Security** — 136 integrations - **Productivity** — 120 integrations -- **HR & People** — 63 integrations +- **HR & People** — 64 integrations - **Monitoring** — 56 integrations -- **Cloud** — 54 integrations -- **Development** — 54 integrations +- **Cloud** — 56 integrations +- **Development** — 56 integrations - **Communication** — 47 integrations - **Infrastructure** — 33 integrations - **Identity & Access** — 22 integrations ## Full catalog -### Cloud (54) +### Cloud (56) | Integration | Slug | Auth | Checks | Sync | |-------------|------|------|--------|------| -| [Airbyte](integrations/airbyte.json) | `airbyte` | api_key | 2 | | +| [Airbyte](integrations/airbyte.json) | `airbyte` | custom | 2 | | | [Aiven](integrations/aiven.json) | `aiven` | api_key | 2 | | -| [Anthropic](integrations/anthropic.json) | `anthropic` | custom | 2 | | +| [Anthropic](integrations/anthropic.json) | `anthropic` | custom | 2 | ✓ | +| [Aptible](integrations/aptible.json) | `aptible` | custom | 8 | | | [Box](integrations/box.json) | `box` | oauth2 | 2 | | | [Braintree](integrations/braintree.json) | `braintree` | custom | 3 | | | [Brex](integrations/brex.json) | `brex` | api_key | 1 | | @@ -70,7 +71,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Egnyte](integrations/egnyte.json) | `egnyte` | custom | 3 | ✓ | | [Elastic Cloud](integrations/elastic-cloud.json) | `elastic-cloud` | custom | 2 | | | [Firebase](integrations/firebase.json) | `firebase` | oauth2 | 2 | | -| [Fireworks AI](integrations/fireworks-ai.json) | `fireworks-ai` | api_key | 2 | | +| [Fireworks AI](integrations/fireworks-ai.json) | `fireworks-ai` | custom | 2 | | | [Fivetran](integrations/fivetran.json) | `fivetran` | basic | 2 | | | [Fly.io](integrations/fly.json) | `fly` | api_key | 2 | | | [Groq](integrations/groq.json) | `groq` | api_key | 2 | | @@ -84,6 +85,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [MotherDuck](integrations/motherduck.json) | `motherduck` | api_key | 2 | | | [Neon](integrations/neon.json) | `neon` | api_key | 2 | | | [Netlify](integrations/netlify.json) | `netlify` | api_key | 2 | | +| [OpenStack](integrations/openstack.json) | `openstack` | custom | 2 | | | [Oracle Cloud Infrastructure](integrations/oracle-cloud.json) | `oracle-cloud` | custom | 3 | | | [Pinecone](integrations/pinecone.json) | `pinecone` | api_key | 3 | | | [Quave Cloud](integrations/quave-cloud.json) | `quave-cloud` | custom | 4 | | @@ -109,7 +111,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | Integration | Slug | Auth | Checks | Sync | |-------------|------|------|--------|------| | [ActiveCampaign](integrations/activecampaign.json) | `activecampaign` | custom | 2 | | -| [Aircall](integrations/aircall.json) | `aircall` | basic | 3 | ✓ | +| [Aircall](integrations/aircall.json) | `aircall` | custom | 3 | ✓ | | [beehiiv](integrations/beehiiv.json) | `beehiiv` | api_key | 2 | | | [Bird](integrations/bird.json) | `bird` | custom | 2 | | | [Braze](integrations/braze.json) | `braze` | custom | 2 | | @@ -128,7 +130,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Hunter](integrations/hunter.json) | `hunter` | custom | 2 | | | [Intercom](integrations/intercom.json) | `intercom` | custom | 2 | | | [Iterable](integrations/iterable.json) | `iterable` | custom | 2 | | -| [Kit (ConvertKit)](integrations/convertkit.json) | `convertkit` | api_key | 2 | | +| [Kit (ConvertKit)](integrations/convertkit.json) | `convertkit` | custom | 2 | | | [Knock](integrations/knock.json) | `knock` | api_key | 2 | | | [Kustomer](integrations/kustomer.json) | `kustomer` | custom | 1 | | | [Loops](integrations/loops.json) | `loops` | api_key | 2 | | @@ -156,7 +158,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Wistia](integrations/wistia.json) | `wistia` | custom | 2 | | | [Zoom](integrations/zoom.json) | `zoom` | oauth2 | 2 | | -### Development (54) +### Development (56) | Integration | Slug | Auth | Checks | Sync | |-------------|------|------|--------|------| @@ -176,14 +178,15 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Coder](integrations/coder.json) | `coder` | custom | 4 | ✓ | | [Docker Hub](integrations/docker-hub.json) | `docker-hub` | custom | 3 | | | [Flagsmith](integrations/flagsmith.json) | `flagsmith` | custom | 2 | | +| [FlutterFlow](integrations/flutterflow.json) | `flutterflow` | custom | 1 | | | [GitBook](integrations/gitbook.json) | `gitbook` | api_key | 2 | | | [GitHub](integrations/github.json) | `github` | api_key | 2 | | | [GitHub Copilot](integrations/github-copilot.json) | `github-copilot` | oauth2 | 3 | | | [GitLab](integrations/gitlab.json) | `gitlab` | custom | 3 | | | [Harness](integrations/harness.json) | `harness` | api_key | 2 | | | [Hightouch](integrations/hightouch.json) | `hightouch` | api_key | 3 | | -| [Inngest](integrations/inngest.json) | `inngest` | api_key | 2 | | -| [Jenkins](integrations/jenkins.json) | `jenkins` | basic | 2 | | +| [Inngest](integrations/inngest.json) | `inngest` | custom | 2 | | +| [Jenkins](integrations/jenkins.json) | `jenkins` | custom | 2 | | | [JFrog Artifactory](integrations/jfrog.json) | `jfrog` | custom | 2 | | | [Jira](integrations/jira.json) | `jira` | custom | 2 | | | [LambdaTest](integrations/lambdatest.json) | `lambdatest` | basic | 2 | | @@ -203,7 +206,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [ReadMe](integrations/readme.json) | `readme` | basic | 2 | | | [Replicate](integrations/replicate.json) | `replicate` | custom | 2 | | | [Shortcut](integrations/shortcut.json) | `shortcut` | api_key | 2 | | -| [SonarCloud](integrations/sonarqube-cloud.json) | `sonarqube-cloud` | api_key | 2 | | +| [SonarCloud](integrations/sonarqube-cloud.json) | `sonarqube-cloud` | custom | 2 | | | [SonarQube Server](integrations/sonarqube-server.json) | `sonarqube-server` | custom | 3 | | | [Sonatype Nexus Repository](integrations/sonatype-nexus.json) | `sonatype-nexus` | custom | 4 | | | [Speakeasy](integrations/speakeasy.json) | `speakeasy` | api_key | 2 | | @@ -214,8 +217,9 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [TestRail](integrations/testrail.json) | `testrail` | custom | 2 | | | [Travis CI](integrations/travis-ci.json) | `travis-ci` | custom | 2 | | | [Trigger.dev](integrations/trigger-dev.json) | `trigger-dev` | custom | 2 | | +| [Xano](integrations/xano.json) | `xano` | custom | 1 | | -### HR & People (63) +### HR & People (64) | Integration | Slug | Auth | Checks | Sync | |-------------|------|------|--------|------| @@ -239,10 +243,10 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Freshteam](integrations/freshteam.json) | `freshteam` | custom | 3 | ✓ | | [Greenhouse](integrations/greenhouse.json) | `greenhouse` | basic | 2 | | | [Gusto](integrations/gusto.json) | `gusto` | oauth2 | 2 | | +| [HiBob](integrations/hibob.json) | `hibob` | basic | 2 | | | [HiBob](integrations/bob.json) | `bob` | basic | 2 | ✓ | -| [HiBob](integrations/hibob.json) | `hibob` | custom | 2 | | | [HireRight](integrations/hireright.json) | `hireright` | custom | 1 | | -| [Humaans](integrations/humaans.json) | `humaans` | custom | 1 | | +| [Humaans](integrations/humaans.json) | `humaans` | custom | 2 | | | [Justworks](integrations/justworks.json) | `justworks` | oauth2 | 2 | ✓ | | [Keka](integrations/keka.json) | `keka` | custom | 4 | ✓ | | [Kenjo](integrations/kenjo.json) | `kenjo` | custom | 2 | ✓ | @@ -253,6 +257,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Namely](integrations/namely.json) | `namely` | custom | 1 | | | [Navan](integrations/navan.json) | `navan` | custom | 1 | | | [Nectar](integrations/nectar-hr.json) | `nectar-hr` | custom | 1 | | +| [Odoo](integrations/odoo.json) | `odoo` | custom | 2 | | | [Oyster HR](integrations/oyster-hr.json) | `oyster-hr` | custom | 1 | | | [Pave](integrations/pave.json) | `pave` | custom | 1 | | | [Paychex](integrations/paychex.json) | `paychex` | custom | 2 | | @@ -293,9 +298,9 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [ConductorOne](integrations/conductorone.json) | `conductorone` | custom | 5 | ✓ | | [CyberArk](integrations/cyberark.json) | `cyberark` | custom | 3 | | | [Descope](integrations/descope.json) | `descope` | custom | 2 | | -| [Duo Security](integrations/duo-security.json) | `duo-security` | custom | 2 | | | [Duo Security](integrations/duo.json) | `duo` | custom | 2 | | -| [Frontegg](integrations/frontegg.json) | `frontegg` | api_key | 2 | | +| [Duo Security](integrations/duo-security.json) | `duo-security` | custom | 2 | | +| [Frontegg](integrations/frontegg.json) | `frontegg` | custom | 2 | | | [FusionAuth](integrations/fusionauth.json) | `fusionauth` | custom | 4 | ✓ | | [JumpCloud](integrations/jumpcloud.json) | `jumpcloud` | custom | 4 | ✓ | | [Microsoft Entra ID](integrations/entra-id.json) | `entra-id` | custom | 4 | ✓ | @@ -318,7 +323,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Akamai](integrations/akamai.json) | `akamai` | custom | 3 | | | [Backblaze B2](integrations/backblaze.json) | `backblaze` | custom | 2 | | | [Bunny.net](integrations/bunny-net.json) | `bunny-net` | custom | 2 | | -| [Cisco Meraki](integrations/cisco-meraki.json) | `cisco-meraki` | api_key | 2 | | +| [Cisco Meraki](integrations/cisco-meraki.json) | `cisco-meraki` | custom | 2 | | | [Cloudflare](integrations/cloudflare.json) | `cloudflare` | custom | 4 | | | [Confluent Cloud](integrations/confluent-cloud.json) | `confluent-cloud` | custom | 4 | | | [Coolify](integrations/coolify.json) | `coolify` | custom | 2 | | @@ -328,7 +333,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [env0](integrations/env0.json) | `env0` | basic | 2 | | | [Fastly](integrations/fastly.json) | `fastly` | api_key | 2 | | | [KeyCDN](integrations/keycdn.json) | `keycdn` | custom | 2 | | -| [Kong Konnect](integrations/kong.json) | `kong` | api_key | 2 | | +| [Kong Konnect](integrations/kong.json) | `kong` | custom | 2 | | | [Koyeb](integrations/koyeb.json) | `koyeb` | api_key | 2 | | | [Miradore](integrations/miradore.json) | `miradore` | custom | 5 | | | [ngrok](integrations/ngrok.json) | `ngrok` | api_key | 2 | | @@ -354,7 +359,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ |-------------|------|------|--------|------| | [ActivTrak](integrations/activtrak.json) | `activtrak` | custom | 3 | | | [Airbrake](integrations/airbrake.json) | `airbrake` | api_key | 2 | | -| [Amplitude](integrations/amplitude.json) | `amplitude` | api_key | 2 | | +| [Amplitude](integrations/amplitude.json) | `amplitude` | custom | 2 | | | [Anodot](integrations/anodot.json) | `anodot` | custom | 2 | | | [Auvik](integrations/auvik.json) | `auvik` | custom | 2 | | | [Axiom](integrations/axiom.json) | `axiom` | custom | 2 | | @@ -362,7 +367,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Bugsnag](integrations/bugsnag.json) | `bugsnag` | api_key | 2 | | | [Checkly](integrations/checkly.json) | `checkly` | custom | 2 | | | [Coralogix](integrations/coralogix.json) | `coralogix` | custom | 2 | | -| [Cronitor](integrations/cronitor.json) | `cronitor` | basic | 2 | | +| [Cronitor](integrations/cronitor.json) | `cronitor` | custom | 2 | | | [CrowdStrike LogScale](integrations/logscale.json) | `logscale` | custom | 2 | | | [Dynatrace](integrations/dynatrace.json) | `dynatrace` | api_key | 2 | | | [Elastic Cloud](integrations/elastic.json) | `elastic` | custom | 2 | | @@ -371,15 +376,15 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Grafana Cloud](integrations/grafana-cloud.json) | `grafana-cloud` | custom | 4 | | | [Heap](integrations/heap.json) | `heap` | custom | 2 | | | [Hex](integrations/hex.json) | `hex` | api_key | 2 | | -| [Highlight](integrations/highlight-io.json) | `highlight-io` | api_key | 2 | | +| [Highlight](integrations/highlight-io.json) | `highlight-io` | custom | 2 | | | [Honeybadger](integrations/honeybadger.json) | `honeybadger` | custom | 2 | | | [Honeycomb](integrations/honeycomb.json) | `honeycomb` | api_key | 2 | | | [Incident.io](integrations/incident-io.json) | `incident-io` | api_key | 2 | | | [Instatus](integrations/instatus.json) | `instatus` | custom | 2 | | | [LogicMonitor](integrations/logicmonitor.json) | `logicmonitor` | custom | 5 | | | [LogRocket](integrations/logrocket.json) | `logrocket` | api_key | 2 | | -| [Logz.io](integrations/logz-io.json) | `logz-io` | custom | 3 | | | [Logz.io](integrations/logzio.json) | `logzio` | custom | 2 | | +| [Logz.io](integrations/logz-io.json) | `logz-io` | custom | 3 | | | [Lumigo](integrations/lumigo.json) | `lumigo` | custom | 1 | | | [Mezmo](integrations/mezmo.json) | `mezmo` | custom | 2 | | | [Mezmo (LogDNA)](integrations/logdna.json) | `logdna` | custom | 2 | | @@ -445,12 +450,12 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Cornerstone OnDemand](integrations/cornerstone.json) | `cornerstone` | custom | 2 | ✓ | | [Coupa](integrations/coupa.json) | `coupa` | custom | 2 | ✓ | | [Coursera for Business](integrations/coursera-business.json) | `coursera-business` | custom | 2 | ✓ | -| [Docebo](integrations/docebo.json) | `docebo` | custom | 2 | ✓ | +| [Docebo](integrations/docebo.json) | `docebo` | custom | 3 | ✓ | | [DocuSign](integrations/docusign.json) | `docusign` | oauth2 | 2 | | | [Domo](integrations/domo.json) | `domo` | custom | 2 | | | [Dropbox Business](integrations/dropbox-business.json) | `dropbox-business` | oauth2 | 3 | ✓ | -| [Dropbox Sign](integrations/dropbox-sign.json) | `dropbox-sign` | custom | 1 | | | [Dropbox Sign](integrations/hellosign.json) | `hellosign` | basic | 2 | | +| [Dropbox Sign](integrations/dropbox-sign.json) | `dropbox-sign` | custom | 1 | | | [Dub.co](integrations/dub.json) | `dub` | api_key | 2 | | | [Dynamics 365](integrations/dynamics-365.json) | `dynamics-365` | custom | 3 | | | [Expensify](integrations/expensify.json) | `expensify` | custom | 1 | | @@ -534,7 +539,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Zoho CRM](integrations/zoho-crm.json) | `zoho-crm` | oauth2 | 3 | ✓ | | [Zuora](integrations/zuora.json) | `zuora` | custom | 2 | | -### Security (134) +### Security (136) | Integration | Slug | Auth | Checks | Sync | |-------------|------|------|--------|------| @@ -568,7 +573,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Checkmarx](integrations/checkmarx.json) | `checkmarx` | custom | 2 | | | [Cisco Secure Endpoint](integrations/cisco-secure-endpoint.json) | `cisco-secure-endpoint` | custom | 3 | | | [Cisco Umbrella](integrations/cisco-umbrella.json) | `cisco-umbrella` | custom | 2 | | -| [Cobalt](integrations/cobalt.json) | `cobalt` | api_key | 2 | | +| [Cobalt](integrations/cobalt.json) | `cobalt` | custom | 2 | | | [Code42 Incydr](integrations/code42-incydr.json) | `code42-incydr` | custom | 5 | | | [Cohesity](integrations/cohesity.json) | `cohesity` | custom | 3 | | | [Commvault](integrations/commvault.json) | `commvault` | custom | 3 | | @@ -624,6 +629,7 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Netskope](integrations/netskope.json) | `netskope` | custom | 4 | | | [Nightfall AI](integrations/nightfall-ai.json) | `nightfall-ai` | api_key | 4 | | | [NinjaOne (NinjaRMM)](integrations/ninjaone.json) | `ninjaone` | custom | 3 | | +| [NINJIO](integrations/ninjio.json) | `ninjio` | custom | 1 | | | [NordPass](integrations/nordpass.json) | `nordpass` | custom | 3 | | | [OneTrust](integrations/onetrust.json) | `onetrust` | custom | 3 | | | [Orca Security](integrations/orca-security.json) | `orca-security` | custom | 2 | | @@ -635,10 +641,11 @@ curl https://raw.githubusercontent.com/trycompai/comp/main/integrations-catalog/ | [Proofpoint TAP](integrations/proofpoint-tap.json) | `proofpoint-tap` | basic | 3 | | | [Qualys VMDR](integrations/qualys.json) | `qualys` | custom | 4 | | | [Rapid7](integrations/rapid7.json) | `rapid7` | custom | 2 | | +| [RoboForm](integrations/roboform.json) | `roboform` | custom | 2 | | | [Rubrik](integrations/rubrik.json) | `rubrik` | custom | 3 | | | [SafeBase](integrations/safebase.json) | `safebase` | api_key | 2 | | | [Scalefusion](integrations/scalefusion.json) | `scalefusion` | api_key | 2 | | -| [Secureframe](integrations/secureframe.json) | `secureframe` | api_key | 2 | | +| [Secureframe](integrations/secureframe.json) | `secureframe` | custom | 2 | | | [SecurityScorecard](integrations/securityscorecard.json) | `securityscorecard` | custom | 5 | | | [Semgrep](integrations/semgrep.json) | `semgrep` | api_key | 2 | | | [SentinelOne](integrations/sentinelone.json) | `sentinelone` | api_key | 5 | | diff --git a/integrations-catalog/index.json b/integrations-catalog/index.json index 4c5aa0d98b..0a2981dfb3 100644 --- a/integrations-catalog/index.json +++ b/integrations-catalog/index.json @@ -1,17 +1,17 @@ { - "generatedAt": "2026-05-11T18:03:02.706Z", - "total": 583, - "sourceCount": 583, - "uniqueSlugs": 583, + "generatedAt": "2026-08-09T18:30:13.052Z", + "total": 590, + "sourceCount": 590, + "uniqueSlugs": 590, "byCategory": { - "HR & People": 63, - "Security": 134, + "HR & People": 64, + "Security": 136, "Productivity": 120, "Infrastructure": 33, "Communication": 47, "Monitoring": 56, - "Cloud": 54, - "Development": 54, + "Cloud": 56, + "Development": 56, "Identity & Access": 22 }, "integrations": [ @@ -172,7 +172,7 @@ "slug": "airbyte", "name": "Airbyte", "category": "Cloud", - "authType": "api_key", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/airbyte.json" @@ -181,7 +181,7 @@ "slug": "aircall", "name": "Aircall", "category": "Communication", - "authType": "basic", + "authType": "custom", "checkCount": 3, "syncSupported": true, "file": "integrations/aircall.json" @@ -235,7 +235,7 @@ "slug": "amplitude", "name": "Amplitude", "category": "Monitoring", - "authType": "api_key", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/amplitude.json" @@ -255,7 +255,7 @@ "category": "Cloud", "authType": "custom", "checkCount": 2, - "syncSupported": false, + "syncSupported": true, "file": "integrations/anthropic.json" }, { @@ -285,6 +285,15 @@ "syncSupported": false, "file": "integrations/apple-business-manager.json" }, + { + "slug": "aptible", + "name": "Aptible", + "category": "Cloud", + "authType": "custom", + "checkCount": 8, + "syncSupported": false, + "file": "integrations/aptible.json" + }, { "slug": "aqua-security", "name": "Aqua Security", @@ -856,7 +865,7 @@ "slug": "cisco-meraki", "name": "Cisco Meraki", "category": "Infrastructure", - "authType": "api_key", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/cisco-meraki.json" @@ -982,7 +991,7 @@ "slug": "cobalt", "name": "Cobalt", "category": "Security", - "authType": "api_key", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/cobalt.json" @@ -1225,7 +1234,7 @@ "slug": "cronitor", "name": "Cronitor", "category": "Monitoring", - "authType": "basic", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/cronitor.json" @@ -1478,7 +1487,7 @@ "name": "Docebo", "category": "Productivity", "authType": "custom", - "checkCount": 2, + "checkCount": 3, "syncSupported": true, "file": "integrations/docebo.json" }, @@ -1546,22 +1555,22 @@ "file": "integrations/dropbox-business.json" }, { - "slug": "dropbox-sign", + "slug": "hellosign", "name": "Dropbox Sign", "category": "Productivity", - "authType": "custom", - "checkCount": 1, + "authType": "basic", + "checkCount": 2, "syncSupported": false, - "file": "integrations/dropbox-sign.json" + "file": "integrations/hellosign.json" }, { - "slug": "hellosign", + "slug": "dropbox-sign", "name": "Dropbox Sign", "category": "Productivity", - "authType": "basic", - "checkCount": 2, + "authType": "custom", + "checkCount": 1, "syncSupported": false, - "file": "integrations/hellosign.json" + "file": "integrations/dropbox-sign.json" }, { "slug": "druva", @@ -1582,22 +1591,22 @@ "file": "integrations/dub.json" }, { - "slug": "duo-security", + "slug": "duo", "name": "Duo Security", "category": "Identity & Access", "authType": "custom", "checkCount": 2, "syncSupported": false, - "file": "integrations/duo-security.json" + "file": "integrations/duo.json" }, { - "slug": "duo", + "slug": "duo-security", "name": "Duo Security", "category": "Identity & Access", "authType": "custom", "checkCount": 2, "syncSupported": false, - "file": "integrations/duo.json" + "file": "integrations/duo-security.json" }, { "slug": "dynamics-365", @@ -1627,22 +1636,22 @@ "file": "integrations/egnyte.json" }, { - "slug": "elastic-cloud", + "slug": "elastic", "name": "Elastic Cloud", - "category": "Cloud", + "category": "Monitoring", "authType": "custom", "checkCount": 2, "syncSupported": false, - "file": "integrations/elastic-cloud.json" + "file": "integrations/elastic.json" }, { - "slug": "elastic", + "slug": "elastic-cloud", "name": "Elastic Cloud", - "category": "Monitoring", + "category": "Cloud", "authType": "custom", "checkCount": 2, "syncSupported": false, - "file": "integrations/elastic.json" + "file": "integrations/elastic-cloud.json" }, { "slug": "employment-hero", @@ -1765,7 +1774,7 @@ "slug": "fireworks-ai", "name": "Fireworks AI", "category": "Cloud", - "authType": "api_key", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/fireworks-ai.json" @@ -1797,6 +1806,15 @@ "syncSupported": false, "file": "integrations/fleetdm.json" }, + { + "slug": "flutterflow", + "name": "FlutterFlow", + "category": "Development", + "authType": "custom", + "checkCount": 1, + "syncSupported": false, + "file": "integrations/flutterflow.json" + }, { "slug": "fly", "name": "Fly.io", @@ -1900,7 +1918,7 @@ "slug": "frontegg", "name": "Frontegg", "category": "Identity & Access", - "authType": "api_key", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/frontegg.json" @@ -2167,28 +2185,28 @@ "file": "integrations/hexnode.json" }, { - "slug": "bob", + "slug": "hibob", "name": "HiBob", "category": "HR & People", "authType": "basic", "checkCount": 2, - "syncSupported": true, - "file": "integrations/bob.json" + "syncSupported": false, + "file": "integrations/hibob.json" }, { - "slug": "hibob", + "slug": "bob", "name": "HiBob", "category": "HR & People", - "authType": "custom", + "authType": "basic", "checkCount": 2, - "syncSupported": false, - "file": "integrations/hibob.json" + "syncSupported": true, + "file": "integrations/bob.json" }, { "slug": "highlight-io", "name": "Highlight", "category": "Monitoring", - "authType": "api_key", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/highlight-io.json" @@ -2270,7 +2288,7 @@ "name": "Humaans", "category": "HR & People", "authType": "custom", - "checkCount": 1, + "checkCount": 2, "syncSupported": false, "file": "integrations/humaans.json" }, @@ -2332,7 +2350,7 @@ "slug": "inngest", "name": "Inngest", "category": "Development", - "authType": "api_key", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/inngest.json" @@ -2431,7 +2449,7 @@ "slug": "jenkins", "name": "Jenkins", "category": "Development", - "authType": "basic", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/jenkins.json" @@ -2539,7 +2557,7 @@ "slug": "convertkit", "name": "Kit (ConvertKit)", "category": "Communication", - "authType": "api_key", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/convertkit.json" @@ -2593,7 +2611,7 @@ "slug": "kong", "name": "Kong Konnect", "category": "Infrastructure", - "authType": "api_key", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/kong.json" @@ -2743,22 +2761,22 @@ "file": "integrations/logrocket.json" }, { - "slug": "logz-io", + "slug": "logzio", "name": "Logz.io", "category": "Monitoring", "authType": "custom", - "checkCount": 3, + "checkCount": 2, "syncSupported": false, - "file": "integrations/logz-io.json" + "file": "integrations/logzio.json" }, { - "slug": "logzio", + "slug": "logz-io", "name": "Logz.io", "category": "Monitoring", "authType": "custom", - "checkCount": 2, + "checkCount": 3, "syncSupported": false, - "file": "integrations/logzio.json" + "file": "integrations/logz-io.json" }, { "slug": "looker", @@ -3255,6 +3273,15 @@ "syncSupported": false, "file": "integrations/ninjaone.json" }, + { + "slug": "ninjio", + "name": "NINJIO", + "category": "Security", + "authType": "custom", + "checkCount": 1, + "syncSupported": false, + "file": "integrations/ninjio.json" + }, { "slug": "nordpass", "name": "NordPass", @@ -3309,6 +3336,15 @@ "syncSupported": false, "file": "integrations/octopus-deploy.json" }, + { + "slug": "odoo", + "name": "Odoo", + "category": "HR & People", + "authType": "custom", + "checkCount": 2, + "syncSupported": false, + "file": "integrations/odoo.json" + }, { "slug": "okta", "name": "Okta", @@ -3372,6 +3408,15 @@ "syncSupported": false, "file": "integrations/openphone.json" }, + { + "slug": "openstack", + "name": "OpenStack", + "category": "Cloud", + "authType": "custom", + "checkCount": 2, + "syncSupported": false, + "file": "integrations/openstack.json" + }, { "slug": "opsgenie", "name": "Opsgenie", @@ -3975,6 +4020,15 @@ "syncSupported": false, "file": "integrations/roboflow.json" }, + { + "slug": "roboform", + "name": "RoboForm", + "category": "Security", + "authType": "custom", + "checkCount": 2, + "syncSupported": false, + "file": "integrations/roboform.json" + }, { "slug": "rollbar", "name": "Rollbar", @@ -4123,7 +4177,7 @@ "slug": "secureframe", "name": "Secureframe", "category": "Security", - "authType": "api_key", + "authType": "custom", "checkCount": 2, "syncSupported": false, "file": "integrations/secureframe.json" @@ -4318,22 +4372,22 @@ "file": "integrations/socket.json" }, { - "slug": "sonarcloud", + "slug": "sonarqube-cloud", "name": "SonarCloud", - "category": "Security", + "category": "Development", "authType": "custom", "checkCount": 2, "syncSupported": false, - "file": "integrations/sonarcloud.json" + "file": "integrations/sonarqube-cloud.json" }, { - "slug": "sonarqube-cloud", + "slug": "sonarcloud", "name": "SonarCloud", - "category": "Development", - "authType": "api_key", + "category": "Security", + "authType": "custom", "checkCount": 2, "syncSupported": false, - "file": "integrations/sonarqube-cloud.json" + "file": "integrations/sonarcloud.json" }, { "slug": "sonarqube-server", @@ -5145,6 +5199,15 @@ "syncSupported": false, "file": "integrations/wrike.json" }, + { + "slug": "xano", + "name": "Xano", + "category": "Development", + "authType": "custom", + "checkCount": 1, + "syncSupported": false, + "file": "integrations/xano.json" + }, { "slug": "xata", "name": "Xata", diff --git a/integrations-catalog/integrations/15five.json b/integrations-catalog/integrations/15five.json index de18545f25..34237c817b 100644 --- a/integrations-catalog/integrations/15five.json +++ b/integrations-catalog/integrations/15five.json @@ -8,7 +8,7 @@ "authConfig": { "type": "api_key", "config": { - "setupInstructions": "1. Log in to 15Five at https://my.15five.com\n2. Go to Settings → Integrations → API\n3. Generate an API key\n4. Enter it below", + "setupInstructions": "1. Log in to 15Five at https://my.15five.com\n2. Go to Settings → Integrations → API\n3. Generate an API key\n4. Enter it below\n5. If you get a 401 error, try regenerating the API key (15Five keys expire 1 year from creation; API access may vary by plan tier).", "credentialFields": [ { "label": "API Key", diff --git a/integrations-catalog/integrations/1password.json b/integrations-catalog/integrations/1password.json index 9b4dbb31ba..097eff656a 100644 --- a/integrations-catalog/integrations/1password.json +++ b/integrations-catalog/integrations/1password.json @@ -41,7 +41,7 @@ { "slug": "onepassword_signin_attempts", "name": "Employee Access", - "description": "Reviews recent 1Password sign-in attempts for unauthorized access and suspicious activity", + "description": "Reviews recent 1Password sign-in attempts via the Events API and surfaces aggregate evidence (success/failure counts, unique users, unique IPs, latest sign-in). Fails if the Events Reporting token is missing the \"signinattempts\" scope or no sign-ins are returned.", "defaultSeverity": "high", "enabled": true } diff --git a/integrations-catalog/integrations/360learning.json b/integrations-catalog/integrations/360learning.json index c93392c595..63f2ef20e4 100644 --- a/integrations-catalog/integrations/360learning.json +++ b/integrations-catalog/integrations/360learning.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to 360Learning as an admin\n2. Go to Settings > API\n3. Copy your Company ID and API Key (v1 credentials)\n4. If you don't have API credentials, contact your 360Learning Customer Success Partner (CSP)\n5. Enter both values below\n\nNote: API v2 credentials are NOT compatible. Use API v1 credentials only.", + "setupInstructions": "1. Log in to 360Learning as an admin\n2. Go to Settings > API\n3. Copy your Company ID and API Key (v1 credentials)\n4. If you don't have API credentials, contact your 360Learning Customer Success Partner (CSP)\n5. Enter both values below\n\nNote: API v2 credentials are NOT compatible. Use API v1 credentials only.\n\nNote: this integration uses 360Learning API v1, which the vendor plans to sunset in mid-2027. A migration to API v2 will be required before then.", "credentialFields": [ { "label": "API Key", diff --git a/integrations-catalog/integrations/activtrak.json b/integrations-catalog/integrations/activtrak.json index 1b9c7d7ee4..c7644916ff 100644 --- a/integrations-catalog/integrations/activtrak.json +++ b/integrations-catalog/integrations/activtrak.json @@ -33,22 +33,22 @@ "checks": [ { "slug": "activtrak_monitoring_alerting", - "name": "Monitoring & Alerting", - "description": "Verifies ActivTrak activity monitoring is active by checking for recent activity data collected by deployed agents", + "name": "ActivTrak User Activity (Last 7 Days)", + "description": "Confirms ActivTrak agents are reporting activity by reading the working-hours report for the last 7 days; surfaces per-user totals as evidence. Note: this is not an alarm/alert configuration check — it verifies end-to-end monitoring is functioning.", "defaultSeverity": "medium", "enabled": true }, { "slug": "activtrak_employee_access", "name": "Employee Access", - "description": "Lists all ActivTrak console users (consumers) with their roles and group access permissions", + "description": "Lists all ActivTrak console users (consumers) with email, SSO status, and viewable groups for access-review evidence. Uses Authorization: Bearer auth.", "defaultSeverity": "medium", "enabled": true }, { "slug": "activtrak_device_list", "name": "Device List", - "description": "Lists all monitored devices (user agents/clients) registered in ActivTrak", + "description": "Lists all monitored ActivTrak agents (clients) with id/name/domain/alias. Uses Authorization: Bearer auth.", "defaultSeverity": "medium", "enabled": true } diff --git a/integrations-catalog/integrations/airbyte.json b/integrations-catalog/integrations/airbyte.json index b2cfe6d139..b2af9e154c 100644 --- a/integrations-catalog/integrations/airbyte.json +++ b/integrations-catalog/integrations/airbyte.json @@ -4,17 +4,29 @@ "description": "Monitor Airbyte data integration pipelines for connection status and workspace access compliance", "category": "Cloud", "docsUrl": "https://reference.airbyte.com/reference/getting-started", - "baseUrl": "https://api.airbyte.com/", + "baseUrl": "https://api.airbyte.com", "authConfig": { - "type": "api_key", + "type": "custom", "config": { - "setupInstructions": "1. Log in to Airbyte Cloud at https://cloud.airbyte.com\n2. Go to Settings → API Keys\n3. Generate a new API key\n4. Copy and enter it below", + "setupInstructions": "1. Log in to Airbyte Cloud at https://cloud.airbyte.com (or your self-hosted instance).\n2. Go to Settings > Applications.\n3. Create a new Application; copy the Client ID and Client Secret (secret shown only once).\n4. Paste them above. For self-hosted Airbyte, also enter your API Base URL.\n5. Comp will exchange these for short-lived access tokens automatically.", "credentialFields": [ { - "label": "API Key", + "label": "Client ID", + "type": "text", + "required": true, + "helpText": "Airbyte Cloud Application Client ID. Settings > Applications > Create Application." + }, + { + "label": "Client Secret", "type": "password", "required": true, - "helpText": "Found in Airbyte Cloud Settings → API Keys" + "helpText": "Airbyte Cloud Application Client Secret. Shown once at application creation." + }, + { + "label": "API Base URL (optional, self-hosted only)", + "type": "text", + "required": false, + "helpText": "Defaults to https://api.airbyte.com for Airbyte Cloud. For self-hosted Airbyte, enter your instance URL (e.g. https://airbyte.example.com/api/public)." } ] } diff --git a/integrations-catalog/integrations/aircall.json b/integrations-catalog/integrations/aircall.json index 3f3b6c98bb..930299ec8b 100644 --- a/integrations-catalog/integrations/aircall.json +++ b/integrations-catalog/integrations/aircall.json @@ -6,11 +6,23 @@ "docsUrl": "https://developer.aircall.io/api-references/", "baseUrl": "https://api.aircall.io", "authConfig": { - "type": "basic", + "type": "custom", "config": { - "setupInstructions": "1. Log in to Aircall Dashboard at https://dashboard.aircall.io\n2. Go to Company Settings\n3. In the API Keys section, click 'Add a new API key'\n4. Copy the API ID and API Token\n5. Enter them below", - "usernameField": "api_id", - "passwordField": "api_token" + "setupInstructions": "IMPORTANT: Do not enter your Aircall account email and password here. Aircall requires a separate API key, which generates an API ID and API Token. Paste those values below — NOT your account login.\n\nYou must be an Admin or Owner in Aircall to create company-level API keys.\n\n1. Log in to the Aircall Dashboard at https://dashboard.aircall.io\n2. Click on the gear icon, then go to Company Settings > Integrations & API > API Keys\n3. Click \"Add a new API key\" and give it a name (e.g. \"Comp AI\")\n4. Aircall will show you the API ID and API Token once. Both are long random strings.\n5. Copy BOTH values immediately — they are shown only once\n6. Paste the API ID into the \"API ID\" field below and the API Token into the \"API Token\" field\n\nIf the integration shows 403 Forbidden errors later, the API key has likely been regenerated or revoked on the Aircall side. Create a new one and update the values here.", + "credentialFields": [ + { + "label": "API ID", + "type": "text", + "required": true, + "helpText": "The API ID generated in Aircall Dashboard > Company Settings > Integrations & API > API Keys. This is a long random string, NOT your Aircall account email." + }, + { + "label": "API Token", + "type": "password", + "required": true, + "helpText": "The API Token shown alongside the API ID. This is a long random string, NOT your Aircall account password. Aircall shows it only once at creation time." + } + ] } }, "capabilities": [ diff --git a/integrations-catalog/integrations/airtable.json b/integrations-catalog/integrations/airtable.json index 0566821177..b5258eb41e 100644 --- a/integrations-catalog/integrations/airtable.json +++ b/integrations-catalog/integrations/airtable.json @@ -7,7 +7,16 @@ "baseUrl": "https://api.airtable.com/", "authConfig": { "type": "api_key", - "config": {} + "config": { + "setupInstructions": "1. Go to https://airtable.com/create/tokens and sign in.\n2. Click \"Create new token\".\n3. Grant the following scopes:\n - schema.bases:read (list bases and their permission levels)\n - user.email:read (identify the token owner)\n4. Under \"Access\", choose \"All current and future bases in all current and future workspaces\".\n5. Create the token and copy the value (starts with \"pat\").\n6. Paste it into the Personal Access Token field above.\n\nNote: Listing all workspaces requires an Airtable Enterprise plan and additional enterprise scopes. These checks operate at the bases level so they work for every plan tier.", + "credentialFields": [ + { + "label": "Personal Access Token", + "type": "password", + "required": true + } + ] + } }, "capabilities": [ "checks" @@ -18,14 +27,14 @@ { "slug": "airtable_employee_access", "name": "Employee Access", - "description": "Reviews Airtable bases and verifies workspace is properly configured", + "description": "Verifies the Personal Access Token owner and the bases reachable for employee access auditing.", "defaultSeverity": "medium", "enabled": true }, { "slug": "airtable_access_review", "name": "Access Review Log", - "description": "Reviews Airtable workspace configuration for access controls", + "description": "Reviews Airtable bases and their permission levels to support access reviews.", "defaultSeverity": "medium", "enabled": true } diff --git a/integrations-catalog/integrations/amplitude.json b/integrations-catalog/integrations/amplitude.json index c3b3ddf5cb..d985911c00 100644 --- a/integrations-catalog/integrations/amplitude.json +++ b/integrations-catalog/integrations/amplitude.json @@ -4,10 +4,24 @@ "description": "Monitor Amplitude projects and user access for product analytics compliance", "category": "Monitoring", "docsUrl": "https://www.docs.developers.amplitude.com/analytics/apis/management-api/", - "baseUrl": "https://management.us.amplitude.com/", + "baseUrl": "https://core.amplitude.com", "authConfig": { - "type": "api_key", - "config": {} + "type": "custom", + "config": { + "setupInstructions": "1. Sign in to Amplitude as an Organization Admin.\n2. Go to Settings > Organization > SCIM (requires the SCIM/SSO add-on on your plan).\n3. Generate a SCIM API token and copy it (starts with scim_).\n4. Paste the token above and select your data region (US or EU).\n5. Note: SCIM endpoints require the SCIM add-on. If your plan does not include SCIM, the Employee Access check will return an actionable failure.", + "credentialFields": [ + { + "label": "SCIM Token", + "type": "password", + "required": true + }, + { + "label": "Region", + "type": "select", + "required": true + } + ] + } }, "capabilities": [ "checks" diff --git a/integrations-catalog/integrations/anodot.json b/integrations-catalog/integrations/anodot.json index 2f98f6c3bb..3d3b2f831f 100644 --- a/integrations-catalog/integrations/anodot.json +++ b/integrations-catalog/integrations/anodot.json @@ -4,17 +4,23 @@ "description": "Anodot AI-powered monitoring and anomaly detection", "category": "Monitoring", "docsUrl": "https://docs.anodot.com/", - "baseUrl": "https://app.anodot.com/api/v1", + "baseUrl": "https://app.anodot.com", "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Anodot\n2. Settings → Access Tokens\n3. Create a new token\n4. Paste it below", + "setupInstructions": "1. Sign in to Anodot as a customer-admin user.\n2. Settings → API Tokens → +Add → name it and copy the Access Key.\n3. Paste it below as the Access Key.\n4. (Optional) Set Base URL to match your Anodot region.", "credentialFields": [ { - "label": "Access Token", + "label": "Access Key", "type": "password", "required": true, - "helpText": "Anodot → Settings → Access Tokens" + "helpText": "Anodot → Settings → API Tokens → create an Access Key as a customer-admin user." + }, + { + "label": "Anodot Base URL", + "type": "text", + "required": false, + "helpText": "Region URL. Defaults to https://app.anodot.com. Examples: https://eu.anodot.com, https://ap.anodot.com, https://in.anodot.com, https://app-oregon.anodot.com." } ] } diff --git a/integrations-catalog/integrations/anthropic.json b/integrations-catalog/integrations/anthropic.json index 1aa9d62e7f..cb660d9943 100644 --- a/integrations-catalog/integrations/anthropic.json +++ b/integrations-catalog/integrations/anthropic.json @@ -1,17 +1,17 @@ { "slug": "anthropic", "name": "Anthropic", - "description": "AI safety company building Claude. Monitor API access and usage.", + "description": "AI safety company building Claude. Monitor organization member access, API availability, and sync employees from Anthropic.", "category": "Cloud", "docsUrl": "https://docs.anthropic.com/en/api/", "baseUrl": "https://api.anthropic.com", "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Go to console.anthropic.com and sign in\n2. Navigate to Settings > Admin API Keys (requires Organization Admin role)\n3. Create a new Admin API key\n4. Copy the key and enter it above\n5. Note: Admin API keys are required for organization-level checks. Regular API keys only work for model access checks.", + "setupInstructions": "1. Go to console.anthropic.com and sign in as an Organization Admin\n2. Navigate to Settings > Admin keys\n3. Create a new Admin API key (it will start with sk-ant-admin01-)\n4. Copy the key and enter it above\n5. Note: Only Admin API keys can list organization members and manage access. Regular API keys will not work for employee access checks.", "credentialFields": [ { - "label": "API Key", + "label": "Admin API Key", "type": "password", "required": true } @@ -19,10 +19,11 @@ } }, "capabilities": [ - "checks" + "checks", + "sync" ], "supportsMultipleConnections": false, - "syncSupported": false, + "syncSupported": true, "checks": [ { "slug": "anthropic_app_availability", @@ -34,7 +35,7 @@ { "slug": "anthropic_employee_access", "name": "Anthropic Employee Access", - "description": "Review Anthropic organization access by listing API keys, pending invitations, and workspaces", + "description": "Lists all Anthropic organization members with their email, role, and access details for Access Review evidence.", "defaultSeverity": "medium", "enabled": true } diff --git a/integrations-catalog/integrations/aptible.json b/integrations-catalog/integrations/aptible.json new file mode 100644 index 0000000000..0e725941a0 --- /dev/null +++ b/integrations-catalog/integrations/aptible.json @@ -0,0 +1,93 @@ +{ + "slug": "aptible", + "name": "Aptible", + "description": "Monitor Aptible for compliance evidence: database backup posture, log and metric drains, service redundancy, endpoint TLS configuration, network exposure, encryption at rest, deploy traceability, and organization member access.", + "category": "Cloud", + "docsUrl": "https://www.aptible.com/docs", + "baseUrl": "https://api.aptible.com", + "authConfig": { + "type": "custom", + "config": { + "setupInstructions": "1. In Aptible, invite a dedicated user for Comp AI (e.g. compliance-bot@yourcompany.com): Settings > Members > Invite.\n2. Create a custom read-only role: grant 'Full Visibility' on the environments you want monitored and do NOT grant 'Sensitive Access' or any manage permissions. Assign the user only this role.\n3. Make sure 2FA is NOT enabled on this user — automated checks cannot complete 2FA challenges.\n4. If your organization enforces SSO, add this user to the SSO bypass allowlist (Settings > Single Sign-On).\n5. Enter the user's email and password below.", + "credentialFields": [ + { + "label": "Email", + "type": "text", + "required": true, + "helpText": "Email of the dedicated read-only Aptible user created for Comp AI." + }, + { + "label": "Password", + "type": "password", + "required": true, + "helpText": "Password of the dedicated read-only user. Stored encrypted and used only to mint short-lived read tokens." + } + ] + } + }, + "capabilities": [ + "checks" + ], + "supportsMultipleConnections": false, + "syncSupported": false, + "checks": [ + { + "slug": "aptible_backup_posture", + "name": "Backup Posture", + "description": "Verifies automatic backups are enabled for every Aptible managed database and records the environment backup retention policy (daily/monthly/yearly, PITR).", + "defaultSeverity": "high", + "enabled": true + }, + { + "slug": "aptible_monitoring", + "name": "Monitoring & Alerting", + "description": "Verifies each Aptible environment routes logs and metrics to a monitoring destination via log drains and metric drains; production environments without any drain fail.", + "defaultSeverity": "medium", + "enabled": true + }, + { + "slug": "aptible_redundancy", + "name": "Service Redundancy", + "description": "Verifies app services in production Aptible environments run 2+ containers so Aptible distributes them across availability zones for high availability.", + "defaultSeverity": "medium", + "enabled": true + }, + { + "slug": "aptible_tls_https", + "name": "TLS / HTTPS", + "description": "Verifies every public Aptible endpoint terminates TLS via a default-domain certificate, Managed TLS (ACME), or a custom certificate; raw TCP endpoints are flagged for manual review.", + "defaultSeverity": "medium", + "enabled": true + }, + { + "slug": "aptible_public_exposure", + "name": "Network Exposure", + "description": "Inventories Aptible endpoints as internal, IP-filtered, or fully public — informational evidence of the network exposure surface.", + "defaultSeverity": "info", + "enabled": true + }, + { + "slug": "aptible_encryption_at_rest", + "name": "Encryption at Rest", + "description": "Records that Aptible encrypts database volumes at rest by default (platform-enforced), enumerating every managed database as evidence.", + "defaultSeverity": "info", + "enabled": true + }, + { + "slug": "aptible_deploy_traceability", + "name": "Deploy Traceability", + "description": "Records git ref/commit traceability for every deployed Aptible app from deploy operations and code scan results; Docker-image deploys are noted for manual CI review.", + "defaultSeverity": "info", + "enabled": true + }, + { + "slug": "aptible_employee_access", + "name": "Employee Access", + "description": "Lists every member of the Aptible organization with owner/superuser flag, email verification, and 2FA status where reported — one result per person.", + "defaultSeverity": "info", + "enabled": true + } + ], + "checkCount": 8, + "isActive": true +} diff --git a/integrations-catalog/integrations/aqua-security.json b/integrations-catalog/integrations/aqua-security.json index 2ce9471324..05e6269aa7 100644 --- a/integrations-catalog/integrations/aqua-security.json +++ b/integrations-catalog/integrations/aqua-security.json @@ -8,13 +8,25 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to cloud.aquasec.com\n2. Settings → API Keys\n3. Create an API key\n4. Paste it below", + "setupInstructions": "1. Log in to cloud.aquasec.com (Aqua Cloud / CSPM)\n2. Go to Settings → API Keys\n3. Generate an API key — copy both the API Key and the API Secret (secret is shown once)\n4. Paste them below. If your tenant is hosted in EU, change the endpoint to https://eu-1.api.cloudsploit.com", "credentialFields": [ { "label": "API Key", "type": "password", "required": true, - "helpText": "Aqua Platform → Settings → API Keys" + "helpText": "Aqua Platform → Settings → API Keys → API Key" + }, + { + "label": "API Secret", + "type": "password", + "required": true, + "helpText": "Aqua Platform → Settings → API Keys → API Secret (shown once on key creation)" + }, + { + "label": "API Endpoint", + "type": "text", + "required": false, + "helpText": "Default: https://api.cloudsploit.com (US). For EU use https://eu-1.api.cloudsploit.com" } ] } diff --git a/integrations-catalog/integrations/attio.json b/integrations-catalog/integrations/attio.json index c4dd161264..99cef26ece 100644 --- a/integrations-catalog/integrations/attio.json +++ b/integrations-catalog/integrations/attio.json @@ -28,14 +28,14 @@ { "slug": "attio_employee_access", "name": "Employee Access", - "description": "Reviews Attio workspace members and their CRM access permissions", + "description": "Lists Attio workspace members with their access level (admin/member/suspended) and emits per-member evidence.", "defaultSeverity": "medium", "enabled": true }, { - "slug": "attio_access_review", - "name": "Access Review Log", - "description": "Audits Attio workspace member roles for access review compliance", + "slug": "attio_app_availability", + "name": "Application Availability", + "description": "Verifies the Attio API token is active and the workspace is reachable via /v2/self.", "defaultSeverity": "medium", "enabled": true } diff --git a/integrations-catalog/integrations/auvik.json b/integrations-catalog/integrations/auvik.json index 7f910720ed..d357d646b6 100644 --- a/integrations-catalog/integrations/auvik.json +++ b/integrations-catalog/integrations/auvik.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Auvik at https://my.auvik.com\n2. Go to Admin > Integrations > API\n3. Generate an API key if you have not already\n4. Copy the API username and API key\n5. Select your Auvik data region\n6. Enter the values below", + "setupInstructions": "1. Sign in to Auvik using your regional URL (e.g. https://us5.my.auvik.com — the text before \"my.auvik.com\" is your region, such as us5).\n2. Click your username at the bottom-left of the Auvik navigation to open your profile, and find the API Key section. (A dedicated user account for the API is recommended.)\n3. Click Generate (or Regenerate) and copy the API key — Auvik shows it only once.\n4. Your API Username is the email address you sign in to Auvik with.\n5. Below: select the Region that matches your Auvik URL (e.g. US5 for us5.my.auvik.com), then enter the API username (email) and API key.", "credentialFields": [ { "label": "API Username", diff --git a/integrations-catalog/integrations/axiom.json b/integrations-catalog/integrations/axiom.json index 4a2a68e2c7..c158cc6f2f 100644 --- a/integrations-catalog/integrations/axiom.json +++ b/integrations-catalog/integrations/axiom.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Axiom at https://app.axiom.co\n2. Go to Settings > API Tokens\n3. Create a new API token with read access (or use a Personal Access Token)\n4. If using a PAT, also note your Organization ID from Settings > General\n5. Enter the values below", + "setupInstructions": "1. Log in to Axiom at https://app.axiom.co (or https://app.eu.axiom.co for EU)\n2. Go to Settings > API Tokens\n3. Create an API token with read access to datasets and monitors (or use a Personal Access Token)\n4. If using a PAT, also note your Organization ID from Settings > General\n5. Select your region (US or EU)\n6. Enter the values below", "credentialFields": [ { "label": "API Token", @@ -21,6 +21,12 @@ "type": "text", "required": false, "helpText": "Required only if using a Personal Access Token (PAT). Found in Settings > General." + }, + { + "label": "Region", + "type": "select", + "required": false, + "helpText": "Choose the region your Axiom account is hosted in. Defaults to US." } ] } diff --git a/integrations-catalog/integrations/bamboohr.json b/integrations-catalog/integrations/bamboohr.json index 74e4d5eca6..0913528d17 100644 --- a/integrations-catalog/integrations/bamboohr.json +++ b/integrations-catalog/integrations/bamboohr.json @@ -8,13 +8,19 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Go to BambooHR > profile icon > API Keys > Add New Key\n2. Copy the API key\n3. Paste it below along with your BambooHR subdomain", + "setupInstructions": "1. Log in to BambooHR\n2. Click your profile icon (top right) > API Keys > Add New Key\n3. Copy the API key\n4. Enter your BambooHR subdomain and the API key below", "credentialFields": [ + { + "label": "BambooHR Subdomain", + "type": "text", + "required": true, + "helpText": "Your BambooHR subdomain (e.g. 'mycompany' for mycompany.bamboohr.com)" + }, { "label": "API Key", "type": "password", "required": true, - "helpText": "Found in BambooHR > profile icon > API Keys" + "helpText": "Found in BambooHR > profile icon > API Keys > Add New Key" } ] } diff --git a/integrations-catalog/integrations/bigid.json b/integrations-catalog/integrations/bigid.json index 035ab57ef8..9d1e354271 100644 --- a/integrations-catalog/integrations/bigid.json +++ b/integrations-catalog/integrations/bigid.json @@ -13,19 +13,25 @@ "label": "BigID Instance URL", "type": "text", "required": true, - "helpText": "Full URL of your BigID instance (e.g., https://your-company.bigid.cloud)" + "helpText": "Full URL of your BigID instance (e.g., https://your-company.bigid.cloud)." }, { - "label": "Username", + "label": "BigID Refresh Token (recommended)", + "type": "password", + "required": false, + "helpText": "Generate at BigID > Settings > API Tokens. Used to obtain short-lived session tokens via /api/v1/refresh-access-token. Leave blank only if using username/password fallback." + }, + { + "label": "Username (fallback)", "type": "text", - "required": true, - "helpText": "BigID admin username for API access" + "required": false, + "helpText": "BigID admin username. Only required if not using a refresh token." }, { - "label": "Password", + "label": "Password (fallback)", "type": "password", - "required": true, - "helpText": "BigID password for the admin user" + "required": false, + "helpText": "BigID password. Only required if not using a refresh token." } ] } diff --git a/integrations-catalog/integrations/bitdefender-gravityzone.json b/integrations-catalog/integrations/bitdefender-gravityzone.json index be5466bd73..2a4cfb6f0c 100644 --- a/integrations-catalog/integrations/bitdefender-gravityzone.json +++ b/integrations-catalog/integrations/bitdefender-gravityzone.json @@ -41,7 +41,7 @@ { "slug": "device_inventory", "name": "Device List", - "description": "Lists managed and unmanaged devices in the network inventory", + "description": "Lists all Bitdefender GravityZone endpoints with managed status, agent version, and OS details. Uses getEndpointsList API which returns only actual endpoints (not folders or groups).", "defaultSeverity": "medium", "enabled": true }, diff --git a/integrations-catalog/integrations/bob.json b/integrations-catalog/integrations/bob.json index deba040358..b6fd8cf159 100644 --- a/integrations-catalog/integrations/bob.json +++ b/integrations-catalog/integrations/bob.json @@ -8,7 +8,23 @@ "authConfig": { "type": "basic", "config": { - "setupInstructions": "1. Log in to HiBob\n2. Go to Settings → Integrations → API\n3. Create a Service User\n4. Copy the Service User ID and Token\n5. Use Service User ID as username and Token as password below" + "setupInstructions": "1. Log in to HiBob Admin\n2. Go to Settings > Integrations > Service Users\n3. Create a new Service User and grant it People read permission\n4. Copy the Service User ID and the generated Token\n5. Paste both below — HiBob requires HTTP Basic auth with id:token", + "credentialFields": [ + { + "label": "Service User ID", + "type": "text", + "required": true, + "helpText": "The Service User ID shown in HiBob > Settings > Integrations > Service Users (e.g. SERVICE-12345)." + }, + { + "label": "Service User Token", + "type": "password", + "required": true, + "helpText": "The token generated alongside the Service User in HiBob." + } + ], + "usernameField": "service_user_id", + "passwordField": "service_token" } }, "capabilities": [ diff --git a/integrations-catalog/integrations/brex.json b/integrations-catalog/integrations/brex.json index 0380e16b41..0feb7262ff 100644 --- a/integrations-catalog/integrations/brex.json +++ b/integrations-catalog/integrations/brex.json @@ -4,7 +4,7 @@ "description": "Monitor Brex corporate card users and accounts for financial compliance", "category": "Cloud", "docsUrl": "https://developer.brex.com/docs/authentication/", - "baseUrl": "https://api.brex.com/", + "baseUrl": "https://platform.brexapis.com", "authConfig": { "type": "api_key", "config": {} diff --git a/integrations-catalog/integrations/certn.json b/integrations-catalog/integrations/certn.json index 26fb3561c9..1d581ffffd 100644 --- a/integrations-catalog/integrations/certn.json +++ b/integrations-catalog/integrations/certn.json @@ -8,19 +8,13 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Certn at https://app.certn.co/login\n2. Click the Partner tab in the dashboard\n3. Click Refresh Keys to generate a new Client ID and Secret\n4. Copy both values immediately (Secret is only shown once)\n5. Paste them here", + "setupInstructions": "1. Log in to Certn at https://app.certn.co/login\n2. Confirm your account is on CertnCentric (the current platform). If you are still on Certn Legacy, contact Certn support to migrate — the legacy API is being shut off on 2026-08-05.\n3. Go to Settings > API Keys\n4. Create a new API key and copy the value (it is only shown once)\n5. Paste the key here", "credentialFields": [ { - "label": "Client ID", - "type": "text", - "required": true, - "helpText": "Found in Certn Dashboard - Partner tab - API Keys" - }, - { - "label": "Client Secret", + "label": "API Key", "type": "password", "required": true, - "helpText": "Generated when creating/refreshing API keys in the Partner tab. Only shown once at creation time." + "helpText": "CertnCentric API key. Generated in Certn under Settings > API Keys." } ] } diff --git a/integrations-catalog/integrations/checkmarx.json b/integrations-catalog/integrations/checkmarx.json index 567dfd8b63..d8a09ef780 100644 --- a/integrations-catalog/integrations/checkmarx.json +++ b/integrations-catalog/integrations/checkmarx.json @@ -8,13 +8,19 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Checkmarx One\n2. Go to IAM → API Keys\n3. Create a key with read access\n4. Paste it below", + "setupInstructions": "1. Log in to Checkmarx One as an admin\n2. Open Settings > Identity and Access Management > API Keys\n3. Generate an API Key (this is a JWT refresh token)\n4. Select the matching region for your Checkmarx One tenant\n5. Paste the key and save. The integration exchanges it for an OAuth access token at runtime.", "credentialFields": [ { "label": "API Key", "type": "password", "required": true, - "helpText": "Checkmarx One → IAM → API Keys" + "helpText": "Checkmarx One > Settings > Identity and Access Management > API Keys. The tenant is auto-detected from the key." + }, + { + "label": "Region", + "type": "select", + "required": true, + "helpText": "Select the Checkmarx One region matching your tenant URL." } ] } diff --git a/integrations-catalog/integrations/checkr.json b/integrations-catalog/integrations/checkr.json index 149284f85c..e2035cee3b 100644 --- a/integrations-catalog/integrations/checkr.json +++ b/integrations-catalog/integrations/checkr.json @@ -3,12 +3,12 @@ "name": "Checkr", "description": "Monitor Checkr background check candidates for HR verification compliance", "category": "HR & People", - "docsUrl": "https://docs.checkr.com/reference", + "docsUrl": "https://docs.checkr.com/", "baseUrl": "https://api.checkr.com/", "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Checkr at https://dashboard.checkr.com\n2. Go to Developer Settings -> API Keys\n3. Copy your API key\n4. Enter it below", + "setupInstructions": "1. Log in to Checkr at https://dashboard.checkr.com\n2. Go to Account Settings > Developer Settings > API keys\n3. Copy your API key\n4. Enter it below\n\nNote: Both production and staging API keys are supported. The integration automatically detects your key's environment and routes to the correct Checkr API, so no extra configuration is needed. Production and staging keys are separate — use the key for the environment you want to audit.", "credentialFields": [ { "label": "API Key", @@ -28,7 +28,7 @@ { "slug": "checkr_employee_verification", "name": "Employee Verification", - "description": "Verifies Checkr is being used for background check screening", + "description": "Lists all Checkr background check candidates individually with their name, email, and screening status for access review evidence.", "defaultSeverity": "medium", "enabled": true }, diff --git a/integrations-catalog/integrations/cisco-meraki.json b/integrations-catalog/integrations/cisco-meraki.json index b232ccbdfd..7b96b34f16 100644 --- a/integrations-catalog/integrations/cisco-meraki.json +++ b/integrations-catalog/integrations/cisco-meraki.json @@ -6,9 +6,16 @@ "docsUrl": "https://developer.cisco.com/meraki/api-v1/", "baseUrl": "https://api.meraki.com", "authConfig": { - "type": "api_key", + "type": "custom", "config": { - "setupInstructions": "1. Log in to Meraki Dashboard at https://dashboard.meraki.com\n2. Go to Organization > API & Webhooks from the left nav\n3. Select API keys and access from the top tabs\n4. Generate a new API key\n5. Copy and paste it below\n\nNote: Treat your API key like a password. Store it securely." + "setupInstructions": "1. Log in to the Meraki Dashboard at https://dashboard.meraki.com\n2. Click your profile icon (top right) > My profile\n3. Scroll to API access and click Generate new API key\n4. Copy the key (shown once) and paste it above\n5. Ensure your dashboard user has access to the organizations you want to monitor\n\nNote: Treat the API key like a password. Meraki uses the X-Cisco-Meraki-API-Key header for authentication.", + "credentialFields": [ + { + "label": "Meraki Dashboard API Key", + "type": "password", + "required": true + } + ] } }, "capabilities": [ diff --git a/integrations-catalog/integrations/cloudflare.json b/integrations-catalog/integrations/cloudflare.json index b43c673fa7..3fdbd278f5 100644 --- a/integrations-catalog/integrations/cloudflare.json +++ b/integrations-catalog/integrations/cloudflare.json @@ -8,13 +8,13 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Cloudflare Dashboard at https://dash.cloudflare.com.\n2. Go to My Profile > API Tokens > Create Token.\n3. Create a custom token with the following Zone permissions:\n - Zone > Zone Settings > Read\n - Zone > Zone > Read\n - Zone > WAF > Read\n4. Set Zone Resources to 'All zones' (or select specific zones you want to monitor).\n5. Copy the token and enter it below.\n6. Copy the Zone ID(s) from each domain's overview page (right sidebar). You can enter multiple Zone IDs separated by commas.", + "setupInstructions": "1. Log in to the Cloudflare Dashboard at https://dash.cloudflare.com.\n2. Go to My Profile > API Tokens > Create Token > Create Custom Token.\n3. Grant these permissions:\n - Zone > Zone > Read\n - Zone > Zone Settings > Read\n - Zone > WAF > Read\n - (optional) Zone > SSL and Certificates > Read — enables TLS certificate detail in the TLS/HTTPS check\n4. Set Zone Resources to 'All zones' (recommended — lets Comp AI auto-detect every domain).\n5. Click Continue to summary > Create Token, copy the generated token, and paste it below. That's it — Comp AI automatically discovers the zones (domains) your token can access; you do NOT need to enter Zone IDs.\n\nIMPORTANT — use an API Token, NOT the Global API Key:\n - This integration only works with a Cloudflare API Token (created via the Create Token button above).\n - Do NOT paste the Global API Key — it appears lower on the same 'API Tokens' page under the 'API Keys' section (a 37-character key with a View button). It is a different, legacy credential type and Cloudflare will reject it here, causing every check to fail with an authorization error.\n\nNotes:\n - A Cloudflare 'zone' is a DNS domain (e.g. example.com). These checks monitor domain security: TLS/SSL mode, WAF, and zone status.\n - Cloudflare Workers and Pages are account-scoped and have no zones, so they are not covered by these checks.\n - To limit monitoring to specific domains, you can optionally enter their Zone IDs (comma-separated) in the Zone IDs field; otherwise all accessible zones are monitored.", "credentialFields": [ { "label": "API Token", "type": "password", "required": true, - "helpText": "Found in Cloudflare Dashboard > My Profile > API Tokens. Create a custom token with Zone Settings:Read, Zone:Read, and Zone WAF:Read permissions for all zones you want to monitor." + "helpText": "Create a custom API Token in Cloudflare Dashboard > My Profile > API Tokens > Create Token, with Zone:Read, Zone Settings:Read, and Zone WAF:Read for all zones you want to monitor. Must be an API Token — NOT the Global API Key shown in the 'API Keys' section of the same page (the Global API Key will be rejected)." } ] } diff --git a/integrations-catalog/integrations/cloudsmith.json b/integrations-catalog/integrations/cloudsmith.json index d1c39fc094..3054203148 100644 --- a/integrations-catalog/integrations/cloudsmith.json +++ b/integrations-catalog/integrations/cloudsmith.json @@ -16,16 +16,16 @@ "syncSupported": false, "checks": [ { - "slug": "cloudsmith_secure_code", - "name": "Secure Code", - "description": "Verifies Cloudsmith organizations are configured for secure package distribution", + "slug": "cloudsmith_org_access", + "name": "Cloudsmith Organization Access & Repositories", + "description": "Inventories Cloudsmith organizations the API key has access to, lists members with roles and 2FA status, and enumerates repositories with visibility.", "defaultSeverity": "medium", "enabled": true }, { - "slug": "cloudsmith_secure_secrets", - "name": "Secure Secrets", - "description": "Verifies Cloudsmith account is active and artifact signing is configured", + "slug": "cloudsmith_app_availability", + "name": "Cloudsmith API Availability", + "description": "Verifies the Cloudsmith API key is valid and reports the authenticated user and accessible organizations.", "defaultSeverity": "medium", "enabled": true } diff --git a/integrations-catalog/integrations/cobalt.json b/integrations-catalog/integrations/cobalt.json index d33fb235ba..2f60057a82 100644 --- a/integrations-catalog/integrations/cobalt.json +++ b/integrations-catalog/integrations/cobalt.json @@ -4,11 +4,25 @@ "description": "Pentest as a service platform. Monitor security assessments.", "category": "Security", "docsUrl": "https://docs.cobalt.io/", - "baseUrl": "https://api.cobalt.io", + "baseUrl": "https://api.us.cobalt.io", "authConfig": { - "type": "api_key", + "type": "custom", "config": { - "setupInstructions": "1. Log in to Cobalt at https://app.cobalt.io\n2. Go to Settings > API > Generate API Token\n3. Copy the token and paste it below" + "setupInstructions": "Cobalt's PtaaS v2 API requires TWO credentials.\n\nStep 1 — Create an API Token (Authorization: Bearer)\n1. Log in to Cobalt at https://app.cobalt.io\n2. Go to your user menu > Settings > API Tokens\n3. Click \"Generate token\", name it (e.g. \"Comp AI\"), and copy the token value\n\nStep 2 — Get your Organization Token (X-Org-Token)\n1. In Cobalt, go to Settings > Organization > API Tokens\n2. Copy the Organization Token (a base64-looking string starting with \"b3J...\")\n\nStep 3 — Paste both below.\nNotes:\n- Base URL is https://api.us.cobalt.io (not api.cobalt.io — that host returns 404).\n- The user that owns the API token must be a member of the organization the Org Token refers to.", + "credentialFields": [ + { + "label": "API Token", + "type": "password", + "required": true, + "helpText": "Personal API token from Cobalt. Created at https://app.cobalt.io/settings/api-tokens." + }, + { + "label": "Organization Token (X-Org-Token)", + "type": "password", + "required": true, + "helpText": "Required for organization-scoped endpoints (pentests, findings, assets). Find it in Cobalt > Settings > Organization > API Tokens." + } + ] } }, "capabilities": [ diff --git a/integrations-catalog/integrations/coda.json b/integrations-catalog/integrations/coda.json index 82e754b00b..069efa0cfe 100644 --- a/integrations-catalog/integrations/coda.json +++ b/integrations-catalog/integrations/coda.json @@ -4,7 +4,7 @@ "description": "Monitor Coda docs and workspace configuration for documentation compliance", "category": "Productivity", "docsUrl": "https://coda.io/developers/apis/v1", - "baseUrl": "https://coda.io/", + "baseUrl": "https://coda.io/apis/v1", "authConfig": { "type": "api_key", "config": {} diff --git a/integrations-catalog/integrations/codecov.json b/integrations-catalog/integrations/codecov.json index ccd005fd35..689b921b9b 100644 --- a/integrations-catalog/integrations/codecov.json +++ b/integrations-catalog/integrations/codecov.json @@ -4,7 +4,7 @@ "description": "Monitor Codecov code coverage reports to verify tests cover code changes", "category": "Development", "docsUrl": "https://docs.codecov.com/reference/overview", - "baseUrl": "https://codecov.io/", + "baseUrl": "https://api.codecov.io/api/v2", "authConfig": { "type": "api_key", "config": {} diff --git a/integrations-catalog/integrations/codefresh.json b/integrations-catalog/integrations/codefresh.json index 66310feea6..bd9770539f 100644 --- a/integrations-catalog/integrations/codefresh.json +++ b/integrations-catalog/integrations/codefresh.json @@ -8,7 +8,7 @@ "authConfig": { "type": "api_key", "config": { - "setupInstructions": "1. Log in to Codefresh at https://g.codefresh.io\n2. Click your avatar dropdown and select 'User Settings'\n3. Scroll down to 'API Keys' and click 'Generate'\n4. Name your key and select the required scopes (at minimum: Audit, Build, Pipeline)\n5. Copy the generated token" + "setupInstructions": "1. Log in to Codefresh at https://g.codefresh.io\n2. Click your avatar dropdown and select 'User Settings'\n3. Scroll down to 'API Keys' and click 'Generate'\n4. Name your key and select scopes: Audit, Build, Pipeline, and User (User scope required for the Employee Access check)\n5. Copy the generated token and paste it here (do NOT prefix with 'Bearer ')" } }, "capabilities": [ diff --git a/integrations-catalog/integrations/coder.json b/integrations-catalog/integrations/coder.json index f6d4242c68..ad5bffcc99 100644 --- a/integrations-catalog/integrations/coder.json +++ b/integrations-catalog/integrations/coder.json @@ -42,7 +42,7 @@ { "slug": "coder_access_review_log", "name": "Access Review Log", - "description": "Verifies that audit logging is active in Coder with recent entries for access review.", + "description": "Performs an access review of Coder users and their assigned roles.", "defaultSeverity": "medium", "enabled": true }, diff --git a/integrations-catalog/integrations/convertkit.json b/integrations-catalog/integrations/convertkit.json index ebdf4b3604..a67c5b7590 100644 --- a/integrations-catalog/integrations/convertkit.json +++ b/integrations-catalog/integrations/convertkit.json @@ -4,10 +4,19 @@ "description": "Email marketing platform for creators. Monitor account access and subscriber management.", "category": "Communication", "docsUrl": "https://developers.kit.com/v4", - "baseUrl": "https://api.convertkit.com", + "baseUrl": "https://api.kit.com", "authConfig": { - "type": "api_key", - "config": {} + "type": "custom", + "config": { + "setupInstructions": "1. Log in to Kit (formerly ConvertKit) at app.kit.com\n2. Go to Settings (gear icon) > Advanced > API\n3. Under \"API Key (v4)\", click Show and copy the key (this is the v4 key, distinct from the legacy v3 \"API Secret\")\n4. Paste it below\n\nNotes:\n- Only Account Owners can view the v4 API key. Other roles will not see it in Settings.\n- Comp AI uses the Kit v4 API at https://api.kit.com/v4 with the X-Kit-Api-Key header. Older v3 keys / API Secrets will not work.", + "credentialFields": [ + { + "label": "API Key", + "type": "password", + "required": true + } + ] + } }, "capabilities": [ "checks" diff --git a/integrations-catalog/integrations/coursera-business.json b/integrations-catalog/integrations/coursera-business.json index 34252ca005..839d57e25d 100644 --- a/integrations-catalog/integrations/coursera-business.json +++ b/integrations-catalog/integrations/coursera-business.json @@ -4,7 +4,7 @@ "description": "Coursera for Business provides enterprise learning and compliance training, enabling organizations to upskill employees with courses from top universities and industry leaders.", "category": "Productivity", "docsUrl": "https://dev.coursera.com/get-started", - "baseUrl": "https://api.coursera.com/ent", + "baseUrl": "https://api.coursera.org", "authConfig": { "type": "custom", "config": { diff --git a/integrations-catalog/integrations/cronitor.json b/integrations-catalog/integrations/cronitor.json index 10e0dc197a..9c76e64507 100644 --- a/integrations-catalog/integrations/cronitor.json +++ b/integrations-catalog/integrations/cronitor.json @@ -6,7 +6,7 @@ "docsUrl": "https://cronitor.io/docs/api", "baseUrl": "https://cronitor.io", "authConfig": { - "type": "basic", + "type": "custom", "config": { "setupInstructions": "1. Log in to Cronitor at https://cronitor.io\n2. Go to Settings - API Settings\n3. Copy your SDK Integration API Key (provides full access to monitors, sites, status pages)\n4. Enter it below", "credentialFields": [ @@ -16,8 +16,7 @@ "required": true, "helpText": "Found in Cronitor Settings - API Settings. Use the SDK Integration key for full API access." } - ], - "usernameField": "api_key" + ] } }, "capabilities": [ diff --git a/integrations-catalog/integrations/cycode.json b/integrations-catalog/integrations/cycode.json index 45be11234d..91fc3a6105 100644 --- a/integrations-catalog/integrations/cycode.json +++ b/integrations-catalog/integrations/cycode.json @@ -8,13 +8,19 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Cycode\n2. Go to Settings → API Tokens\n3. Generate a new API token\n4. Paste it below", + "setupInstructions": "1. Log in to Cycode\n2. Go to Settings → API Tokens\n3. Generate a new API token — Cycode will display a Client ID and a Secret\n4. Copy both values and paste them below\n5. The token must belong to a role with read access to Projects and Violations", "credentialFields": [ { - "label": "API Token", + "label": "Client ID", + "type": "text", + "required": true, + "helpText": "Cycode → Settings → API Tokens → Generate Token (copy the Client ID)." + }, + { + "label": "Client Secret", "type": "password", "required": true, - "helpText": "Cycode → Settings → API Tokens → Generate Token" + "helpText": "Cycode → Settings → API Tokens → Generate Token (copy the Secret shown alongside the Client ID)." } ] } diff --git a/integrations-catalog/integrations/datadog.json b/integrations-catalog/integrations/datadog.json index 926bc58c21..67837209d6 100644 --- a/integrations-catalog/integrations/datadog.json +++ b/integrations-catalog/integrations/datadog.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Go to Datadog > Organization Settings > API Keys and copy your API Key.\n2. Go to Organization Settings > Application Keys, create a key with scopes: monitors_read + synthetics_read.\n3. Enter your Datadog site (e.g. datadoghq.com for US, datadoghq.eu for EU).", + "setupInstructions": "You will need both an API Key and an Application Key from Datadog.\n\nStep 1 — Create an API Key\n1. In Datadog, go to Organization Settings > API Keys\n2. Click New Key, name it (e.g. \"Comp AI\"), and copy the key\n\nStep 2 — Create an Application Key with the required scopes\n1. Go to Organization Settings > Application Keys\n2. Click New Key, name it (e.g. \"Comp AI App Key\")\n3. Add ALL four scopes — each is needed for a specific check:\n - monitors_read (Monitoring & Alerting check)\n - synthetics_read (Synthetic Tests check)\n - audit_logs_read (Audit Logging check)\n - user_access_read (User Management check)\n4. Click Save and copy the key\n\nImportant: Application Keys inherit the creator's role permissions. The user creating the key must have the equivalent read access for each scope, or the key will be created without that scope (causing 403 \"Failed permission authorization checks\" errors when running the check).\n\nStep 3 — Enter both keys + your Datadog site below\nDatadog Site options:\n - datadoghq.com (US1, default)\n - us3.datadoghq.com (US3)\n - us5.datadoghq.com (US5)\n - datadoghq.eu (EU1, Germany)\n - ap1.datadoghq.com (AP1, Japan)\n - ap2.datadoghq.com (AP2, Australia)\n - ddog-gov.com (US1-FED, US Government)\n - us2.ddog-gov.com (US2-FED, US Government)\n\nOptional: For the Monitoring & Alerting check, you can set a \"Monitor tag filter\" (e.g. env:prod) in the check settings to scope only relevant monitors. Leave empty to check all monitors.", "credentialFields": [ { "label": "API Key", @@ -20,7 +20,7 @@ "label": "Application Key", "type": "password", "required": true, - "helpText": "Found in Datadog > Organization Settings > Application Keys. Requires scopes: monitors_read, synthetics_read" + "helpText": "Found in Datadog > Organization Settings > Application Keys" } ] } diff --git a/integrations-catalog/integrations/descope.json b/integrations-catalog/integrations/descope.json index 65fc48cdcb..79b830711f 100644 --- a/integrations-catalog/integrations/descope.json +++ b/integrations-catalog/integrations/descope.json @@ -8,13 +8,19 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Descope\n2. Go to Settings → Company → Management API Keys\n3. Create or copy a management key\n4. Paste it below", + "setupInstructions": "1. Log in to your Descope console (https://app.descope.com).\n2. Copy your Project ID from Settings → Project → Project ID.\n3. Go to Settings → Company → Management Keys and create or copy a key.\n4. Paste both values below.", "credentialFields": [ + { + "label": "Project ID", + "type": "text", + "required": true, + "helpText": "Descope → Settings → Project → Project ID (starts with P...)" + }, { "label": "Management Key", "type": "password", "required": true, - "helpText": "Descope → Settings → Company → Management API Keys" + "helpText": "Descope → Settings → Company → Management Keys" } ] } diff --git a/integrations-catalog/integrations/docebo.json b/integrations-catalog/integrations/docebo.json index 9fcdcb76cd..da7e0efddb 100644 --- a/integrations-catalog/integrations/docebo.json +++ b/integrations-catalog/integrations/docebo.json @@ -39,19 +39,26 @@ "checks": [ { "slug": "employee_access", - "name": "Employee Access", - "description": "Lists all Docebo LMS users with their account status and role for access review", + "name": "Docebo Employee Access Review", + "description": "Retrieves all Docebo LMS users with their access levels and status for periodic access review.", "defaultSeverity": "medium", "enabled": true }, { "slug": "rbac", - "name": "Role-based Access Controls", - "description": "Lists Docebo user groups for role-based access control review", + "name": "Docebo Role-Based Access Control Groups", + "description": "Lists all Docebo groups used to implement role-based access control and course assignment.", "defaultSeverity": "medium", "enabled": true + }, + { + "slug": "docebo_course_inventory", + "name": "Docebo Course Inventory", + "description": "Lists all courses configured in Docebo for compliance training visibility.", + "defaultSeverity": "low", + "enabled": true } ], - "checkCount": 2, + "checkCount": 3, "isActive": true } diff --git a/integrations-catalog/integrations/elastic.json b/integrations-catalog/integrations/elastic.json index 346825cf16..da0d621b9c 100644 --- a/integrations-catalog/integrations/elastic.json +++ b/integrations-catalog/integrations/elastic.json @@ -4,23 +4,17 @@ "description": "Monitor Elastic Cloud cluster health and user accounts for monitoring and access review compliance", "category": "Monitoring", "docsUrl": "https://www.elastic.co/docs/api/", - "baseUrl": "https://elastic.co/", + "baseUrl": "https://api.elastic-cloud.com/api/v1", "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Kibana\n2. Go to Stack Management > Security > API keys\n3. Create an API key with cluster:monitor and security permissions\n4. Copy the API Key ID and the API Key secret value\n5. Paste them into the fields below", + "setupInstructions": "1. Log in to Elastic Cloud at https://cloud.elastic.co\n2. Go to Organization → API keys\n3. Click \"Create API key\"\n4. Select \"Organization viewer\" role (minimum)\n5. Copy the generated key and paste it below", "credentialFields": [ { - "label": "API Key ID", - "type": "text", - "required": true, - "helpText": "The ID portion of your Elasticsearch API key (shown when the key is created)" - }, - { - "label": "API Key Secret", + "label": "API Key", "type": "password", "required": true, - "helpText": "The secret value of your Elasticsearch API key (shown once at creation time)" + "helpText": "Elastic Cloud → Organization → API keys → Create API key (Organization viewer minimum)." } ] } diff --git a/integrations-catalog/integrations/entra-id.json b/integrations-catalog/integrations/entra-id.json index 183d494056..900b8a6580 100644 --- a/integrations-catalog/integrations/entra-id.json +++ b/integrations-catalog/integrations/entra-id.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Go to Azure Portal → Microsoft Entra ID → App registrations\n2. Click 'New registration', name it 'CompAI Integration'\n3. Under API permissions, add Microsoft Graph (Application):\n - User.Read.All\n - Directory.Read.All\n - AuditLog.Read.All\n4. Click 'Grant admin consent'\n5. Go to Certificates & secrets → New client secret\n6. Copy the Tenant ID, Application ID, and Client Secret below", + "setupInstructions": "1. Go to Azure Portal → Microsoft Entra ID → App registrations\n2. Click 'New registration', name it 'CompAI Integration'\n3. Under API permissions → Add a permission → Microsoft Graph → Application permissions, add:\n - User.Read.All\n - Directory.Read.All\n - AuditLog.Read.All\n - AccessReview.Read.All\n4. Click 'Grant admin consent'\n5. Go to Certificates & secrets → New client secret, copy the value (only shown once)\n6. From the app Overview page, copy the Tenant ID and Application (Client) ID\n7. Paste the Tenant ID, Application ID, and Client Secret below\n\nNote: Access Reviews require Microsoft Entra ID P2 (or Microsoft Entra ID Governance) licensing.", "credentialFields": [ { "label": "Tenant ID", diff --git a/integrations-catalog/integrations/eset-protect.json b/integrations-catalog/integrations/eset-protect.json index 3bbc89ebc4..d91f23af8d 100644 --- a/integrations-catalog/integrations/eset-protect.json +++ b/integrations-catalog/integrations/eset-protect.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to ESET Protect Cloud console\n2. Go to More > Users > API Users\n3. Create a new API user with Device Management read permissions\n4. Note your region from the console URL (eu, de, us, jpn, or ca)\n5. Enter the API username, password, and region prefix", + "setupInstructions": "1. Create the API user in your ESET account portal — ESET Business Account (https://eba.eset.com), or ESET PROTECT Hub if your company has been migrated (the steps are the same; the menu is \"Users\" and the section is \"Permissions\"). Sign in as a Root/Superuser. Do NOT create it in the ESET PROTECT web console (e.g. us02.protect.eset.com): the \"New Mapped Account\" option there (More → Access Rights → Users) only creates a console sign-in for a person and does NOT grant API access.\n2. Open User management and click New User (in ESET PROTECT Hub: open Users and add a user). Create a separate, dedicated user — the API access right cannot be granted to the Root/Superuser's own account.\n3. Enter the user's details with a valid email address, and grant Read access to ESET PROTECT so device and policy data is visible.\n4. Under Access Rights (ESET PROTECT Hub: Permissions), enable the \"Integrations\" toggle — this is what grants ESET Connect (API) access. Only a Root/Superuser can enable it. Without it the connection signs in but every check is denied.\n5. Click Create. The user receives an invitation email — accept it, set the password, and sign in once so the account is activated.\n6. Find your region prefix in your console URL: use the letters before the number, e.g. us02.protect.eset.com is \"us\". Valid values: eu, de, us, jpn, ca.\n7. Return here and enter the user's login email as API Username, its password as API Password, and the region prefix.", "credentialFields": [ { "label": "API Username", diff --git a/integrations-catalog/integrations/figma.json b/integrations-catalog/integrations/figma.json index 3e97fd0182..840d5b74b4 100644 --- a/integrations-catalog/integrations/figma.json +++ b/integrations-catalog/integrations/figma.json @@ -7,7 +7,9 @@ "baseUrl": "https://api.figma.com/", "authConfig": { "type": "api_key", - "config": {} + "config": { + "setupInstructions": "Steps to generate a Figma personal access token:\n1. In Figma, click your avatar (top-right) → Settings → Account → Personal access tokens\n2. Click 'Generate new token', name it (e.g. 'Comp AI compliance check'), set expiration as desired\n3. Copy the token and paste it into the API Key field below\n\nFor each Figma check you enable, you will also be asked for a Team ID. Find it in the team URL: figma.com/files/team/{team_id}/...\n\nImportant notes:\n - The token inherits the permissions of the user who creates it. Make sure that user is a member of every team you want to monitor — otherwise the team check will fail with 403.\n - Figma's REST API does NOT expose a full team-member list for personal access tokens. The 'Employee Access' check verifies the token can see the team's projects as a proxy for membership. A full team-member audit requires Figma Enterprise + SCIM, or OAuth with admin scopes." + } }, "capabilities": [ "checks" diff --git a/integrations-catalog/integrations/fireworks-ai.json b/integrations-catalog/integrations/fireworks-ai.json index bf858d61dc..701f0fe279 100644 --- a/integrations-catalog/integrations/fireworks-ai.json +++ b/integrations-catalog/integrations/fireworks-ai.json @@ -6,9 +6,16 @@ "docsUrl": "https://docs.fireworks.ai/", "baseUrl": "https://api.fireworks.ai", "authConfig": { - "type": "api_key", + "type": "custom", "config": { - "setupInstructions": "1. Go to the Fireworks AI dashboard at https://app.fireworks.ai\n2. Navigate to Settings > API Keys\n3. Generate an API key\n4. Enter it below" + "setupInstructions": "1. Go to the Fireworks AI dashboard at https://app.fireworks.ai\n2. Navigate to Settings > API Keys\n3. Create a new API key (an account-admin scoped key is required for the Employee Access check)\n4. Copy the key and enter it above", + "credentialFields": [ + { + "label": "API Key", + "type": "password", + "required": true + } + ] } }, "capabilities": [ diff --git a/integrations-catalog/integrations/flutterflow.json b/integrations-catalog/integrations/flutterflow.json new file mode 100644 index 0000000000..cdf515dd0d --- /dev/null +++ b/integrations-catalog/integrations/flutterflow.json @@ -0,0 +1,38 @@ +{ + "slug": "flutterflow", + "name": "FlutterFlow", + "description": "Track code-change activity across FlutterFlow projects (update counts, branches, collaborators) via the FlutterFlow Project API.", + "category": "Development", + "docsUrl": null, + "baseUrl": "https://api.flutterflow.io", + "authConfig": { + "type": "custom", + "config": { + "setupInstructions": "1. Sign in to FlutterFlow and open your account page: https://app.flutterflow.io/account\n2. In the API section, generate an API token. (API access requires an active paid FlutterFlow subscription.)\n3. Copy the token and paste it below.", + "credentialFields": [ + { + "label": "API Token", + "type": "password", + "required": true, + "helpText": "From https://app.flutterflow.io/account (Account > API). Requires an active paid FlutterFlow subscription." + } + ] + } + }, + "capabilities": [ + "checks" + ], + "supportsMultipleConnections": false, + "syncSupported": false, + "checks": [ + { + "slug": "flutterflow_code_changes", + "name": "Code Changes", + "description": "Verifies FlutterFlow project changes are tracked/version-controlled (update counts, branches, last-modified, collaborator access) via the Project API.", + "defaultSeverity": "medium", + "enabled": true + } + ], + "checkCount": 1, + "isActive": true +} diff --git a/integrations-catalog/integrations/freshteam.json b/integrations-catalog/integrations/freshteam.json index 8161ec43fe..2f519c2dc4 100644 --- a/integrations-catalog/integrations/freshteam.json +++ b/integrations-catalog/integrations/freshteam.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to your Freshteam account\n2. Click your profile icon in the top right\n3. Select 'API Settings'\n4. Copy the API key displayed under 'Your API Key'\n5. Enter your subdomain (the part before .freshteam.com in your URL)\n6. Paste the API key below\n\nNote: Only HR Partner, Admin, and Account Admin roles can use the API.", + "setupInstructions": "⚠️ DEPRECATED: Freshteam was sunset by Freshworks in March 2024. New connections will likely fail because the upstream API and product are no longer available. This integration is preserved only for any remaining legacy tenants.\n\n1. Log in to your Freshteam account (if it still exists)\n2. Click your profile icon in the top right\n3. Select 'API Settings'\n4. Copy the API key displayed under 'Your API Key'\n5. Enter your subdomain (the part before .freshteam.com in your URL)\n6. Paste the API key below\n\nNote: Only HR Partner, Admin, and Account Admin roles can use the API.", "credentialFields": [ { "label": "Freshteam Subdomain", diff --git a/integrations-catalog/integrations/frontegg.json b/integrations-catalog/integrations/frontegg.json index 9010aac5ea..4a0f870075 100644 --- a/integrations-catalog/integrations/frontegg.json +++ b/integrations-catalog/integrations/frontegg.json @@ -4,17 +4,29 @@ "description": "Monitor Frontegg authentication platform for user management and access control compliance", "category": "Identity & Access", "docsUrl": "https://docs.frontegg.com/reference/overview", - "baseUrl": "https://api.frontegg.com/", + "baseUrl": "https://api.frontegg.com", "authConfig": { - "type": "api_key", + "type": "custom", "config": { - "setupInstructions": "1. Log in to Frontegg at https://portal.frontegg.com\n2. Go to Environments → [your env] → Settings → API Tokens\n3. Generate an API token\n4. Enter it below", + "setupInstructions": "1. Log in to Frontegg portal (https://portal.frontegg.com)\n2. Select the Environment to monitor\n3. Open Settings → API Tokens\n4. Copy the Client ID and Secret (Api-Key)\n5. Choose the matching region (US or EU)", "credentialFields": [ { - "label": "API Token", + "label": "Client ID", + "type": "text", + "required": true, + "helpText": "Frontegg Portal → [your environment] → Settings → API Tokens → Client ID" + }, + { + "label": "Secret", "type": "password", "required": true, - "helpText": "Found in Frontegg Portal → Environments → Settings → API Tokens" + "helpText": "Frontegg Portal → [your environment] → Settings → API Tokens → Secret (Api-Key)" + }, + { + "label": "Region", + "type": "select", + "required": true, + "helpText": "Select your Frontegg region." } ] } diff --git a/integrations-catalog/integrations/fusionauth.json b/integrations-catalog/integrations/fusionauth.json index c0e352a0db..22c7923dd6 100644 --- a/integrations-catalog/integrations/fusionauth.json +++ b/integrations-catalog/integrations/fusionauth.json @@ -55,7 +55,7 @@ { "slug": "fusionauth_access_review_log", "name": "Access Review Log", - "description": "Verifies that audit logging is active in FusionAuth by checking for recent audit log entries.", + "description": "Performs an access review of FusionAuth users and their assigned roles.", "defaultSeverity": "medium", "enabled": true } diff --git a/integrations-catalog/integrations/gitbook.json b/integrations-catalog/integrations/gitbook.json index 9cd674682e..0a3fdb8f4a 100644 --- a/integrations-catalog/integrations/gitbook.json +++ b/integrations-catalog/integrations/gitbook.json @@ -7,7 +7,17 @@ "baseUrl": "https://api.gitbook.com/", "authConfig": { "type": "api_key", - "config": {} + "config": { + "setupInstructions": "1. Sign in to GitBook at app.gitbook.com\n2. Open User Settings (top-left avatar) > Developer settings > API tokens\n3. Create a new API token with read access to your organization\n4. Copy the token and paste it below\n5. Find your Organization ID in the GitBook URL after signing in (the segment after /o/)", + "credentialFields": [ + { + "label": "GitBook API Token", + "type": "password", + "required": true, + "helpText": "Your GitBook API token. Create one at app.gitbook.com > User Settings > Developer settings > API tokens." + } + ] + } }, "capabilities": [ "checks" diff --git a/integrations-catalog/integrations/gitguardian.json b/integrations-catalog/integrations/gitguardian.json index 3e09f3de77..af01750bf3 100644 --- a/integrations-catalog/integrations/gitguardian.json +++ b/integrations-catalog/integrations/gitguardian.json @@ -17,15 +17,15 @@ "checks": [ { "slug": "gitguardian_secure_code", - "name": "Secure Code", - "description": "Checks GitGuardian for open incidents of exposed secrets in code", + "name": "Open Secret Incidents", + "description": "Lists open (TRIGGERED/ASSIGNED) GitGuardian secret incidents. Fails if any are open; passes when none remain.", "defaultSeverity": "critical", "enabled": true }, { "slug": "gitguardian_secure_secrets", - "name": "Secure Secrets", - "description": "Reviews GitGuardian monitored sources for secret scanning coverage", + "name": "Monitored Sources", + "description": "Verifies at least one source (GitHub/GitLab/Bitbucket/Azure DevOps repository) is connected to GitGuardian for secret scanning.", "defaultSeverity": "high", "enabled": true } diff --git a/integrations-catalog/integrations/github-copilot.json b/integrations-catalog/integrations/github-copilot.json index a8a77f1545..8172885b43 100644 --- a/integrations-catalog/integrations/github-copilot.json +++ b/integrations-catalog/integrations/github-copilot.json @@ -8,7 +8,7 @@ "authConfig": { "type": "oauth2", "config": { - "setupInstructions": "1. Go to GitHub > Settings > Developer settings > OAuth Apps > New OAuth App\n2. Set Redirect URI to: https://api.trycomp.ai/v1/integrations/oauth/callback\n3. Request scopes: read:org, manage_billing:copilot\n4. Copy Client ID and Secret to Comp AI admin panel\n5. After connecting, enter your GitHub organization name", + "setupInstructions": "1. Go to GitHub > Settings > Developer settings > OAuth Apps > New OAuth App\n2. Set Redirect URI to: https://api.trycomp.ai/v1/integrations/oauth/callback\n3. Request scopes: read:org, manage_billing:copilot\n4. Copy Client ID and Secret to Comp AI admin panel\n5. After connecting, enter your GitHub organization name\n\nImportant: The user who connects this integration MUST be an organization owner, billing manager, or Copilot admin in GitHub. Other roles will receive HTTP 404 even with all required scopes granted.\n\nOrganization name: enter the bare GitHub org name (e.g. \"acme-corp\"), not the full URL.", "scopes": [ "read:org", "manage_billing:copilot" diff --git a/integrations-catalog/integrations/go1.json b/integrations-catalog/integrations/go1.json index 177fd1ae9b..1bfbda0dfb 100644 --- a/integrations-catalog/integrations/go1.json +++ b/integrations-catalog/integrations/go1.json @@ -4,7 +4,7 @@ "description": "Go1 is a learning content aggregator and training platform used for compliance training, L&D, and security awareness. Connect Go1 to verify employee access and training enrollment status.", "category": "Security", "docsUrl": "https://www.go1.com/developers", - "baseUrl": "https://gateway.go1.com", + "baseUrl": "https://api.go1.com/v2", "authConfig": { "type": "oauth2", "config": { diff --git a/integrations-catalog/integrations/hackerone.json b/integrations-catalog/integrations/hackerone.json index 80ca024171..c1ae016db1 100644 --- a/integrations-catalog/integrations/hackerone.json +++ b/integrations-catalog/integrations/hackerone.json @@ -8,13 +8,19 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to HackerOne at https://hackerone.com\n2. Go to Settings → API Token\n3. Create a new token with a name (identifier) and token value\n4. Base64 encode 'identifier:api_token' and enter below", + "setupInstructions": "1. Log in to HackerOne at https://hackerone.com\n2. Go to your organization → Settings → API Tokens (org-admin required)\n3. Click 'Create API Token', enter an identifier name, copy the generated token value (shown once)\n4. Paste the identifier and token below — Comp will base64-encode them for HTTP Basic auth", "credentialFields": [ { - "label": "Encoded API Credentials", + "label": "API Identifier", + "type": "text", + "required": true, + "helpText": "The API identifier (username) of an API token created in HackerOne. Create at https://hackerone.com/organizations//api_tokens." + }, + { + "label": "API Token", "type": "password", "required": true, - "helpText": "Base64 encode 'identifier:api_token'. Create API credentials in HackerOne → Settings → API Token. Command: echo -n 'identifier:token' | base64" + "helpText": "The API token value generated alongside the identifier. HackerOne shows it only once at creation." } ] } diff --git a/integrations-catalog/integrations/hetzner.json b/integrations-catalog/integrations/hetzner.json index 4489ba4e31..f6974ed1fb 100644 --- a/integrations-catalog/integrations/hetzner.json +++ b/integrations-catalog/integrations/hetzner.json @@ -4,7 +4,7 @@ "description": "Monitor Hetzner Cloud servers and firewall configuration for EU infrastructure compliance", "category": "Cloud", "docsUrl": "https://docs.hetzner.cloud/", - "baseUrl": "https://api.hetzner.cloud/", + "baseUrl": "https://api.hetzner.cloud/v1", "authConfig": { "type": "api_key", "config": { diff --git a/integrations-catalog/integrations/hibob.json b/integrations-catalog/integrations/hibob.json index 69148676f8..21f344cf8e 100644 --- a/integrations-catalog/integrations/hibob.json +++ b/integrations-catalog/integrations/hibob.json @@ -4,19 +4,27 @@ "description": "Monitor HiBob employee records and job descriptions for HR compliance and employee data completeness", "category": "HR & People", "docsUrl": "https://apidocs.hibob.com/reference", - "baseUrl": "https://api.hibob.com/", + "baseUrl": "https://api.hibob.com", "authConfig": { - "type": "custom", + "type": "basic", "config": { - "setupInstructions": "1. Log in to HiBob Admin\n2. Go to Settings > Integrations > Service Users\n3. Create a new service user with People read permissions\n4. Copy and paste the generated token below", + "setupInstructions": "1. Log in to HiBob as an admin\n2. Go to Settings -> Integrations -> Service Users\n3. Create a new Service User and grant read access to People\n4. Copy BOTH the Service User ID and the Service User Token (the token is shown only once)\n5. Paste Service User ID and Service User Token below - Comp AI authenticates to HiBob using HTTP Basic Auth (ID as username, token as password).", "credentialFields": [ + { + "label": "Service User ID", + "type": "text", + "required": true, + "helpText": "The Service User ID generated by HiBob (looks like \"SERVICE-12345\")." + }, { "label": "Service User Token", "type": "password", "required": true, - "helpText": "Create a Service User in HiBob > Settings > Integrations > Service Users" + "helpText": "The token shown when you create the Service User. HiBob shows the token only once - copy it immediately." } - ] + ], + "usernameField": "username", + "passwordField": "password" } }, "capabilities": [ @@ -26,15 +34,15 @@ "syncSupported": false, "checks": [ { - "slug": "employee_access", - "name": "Employee Access", + "slug": "hibob_employee_access", + "name": "HiBob Employee Access", "description": "Reviews HiBob employee records for access management", "defaultSeverity": "medium", "enabled": true }, { - "slug": "employee_descriptions", - "name": "Employee Descriptions", + "slug": "hibob_employee_descriptions", + "name": "HiBob Employee Descriptions", "description": "Verifies that HiBob employees have job titles set for employee descriptions", "defaultSeverity": "low", "enabled": true diff --git a/integrations-catalog/integrations/highlight-io.json b/integrations-catalog/integrations/highlight-io.json index 1a939e25dc..4e313fd3bb 100644 --- a/integrations-catalog/integrations/highlight-io.json +++ b/integrations-catalog/integrations/highlight-io.json @@ -4,10 +4,19 @@ "description": "Full-stack observability platform with session replay and error monitoring.", "category": "Monitoring", "docsUrl": "https://www.highlight.io/docs", - "baseUrl": "https://pri.highlight.io", + "baseUrl": "https://pri.highlight.run", "authConfig": { - "type": "api_key", - "config": {} + "type": "custom", + "config": { + "setupInstructions": "1. Sign in to https://app.highlight.io as a workspace admin/owner.\n2. Open Workspace Settings > API Tokens.\n3. Create a new API token (or reuse one) that has admin / owner privileges on the workspace you want audited.\n4. Copy the token and paste it above.\n\nNote: Highlight's public API surface for workspace data is limited. The employee-access check uses the private GraphQL endpoint (pri.highlight.run/graphql). If Highlight rejects the workspace_admins query for your token, the check will surface that explicitly so you can either upgrade the token's scope or upload the admin list as manual evidence.", + "credentialFields": [ + { + "label": "Highlight API Token", + "type": "password", + "required": true + } + ] + } }, "capabilities": [ "checks" diff --git a/integrations-catalog/integrations/honeybadger.json b/integrations-catalog/integrations/honeybadger.json index 60d9900b4b..1b8378fa0b 100644 --- a/integrations-catalog/integrations/honeybadger.json +++ b/integrations-catalog/integrations/honeybadger.json @@ -8,13 +8,13 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Honeybadger at https://app.honeybadger.io\n2. Go to Profile → Authentication Tokens\n3. Copy your API key\n4. Base64 encode 'api_key:' (with colon, empty password)\n5. Enter the encoded value below", + "setupInstructions": "1. Log in to Honeybadger at https://app.honeybadger.io\n2. Click your profile (top right) > \"Authentication\".\n3. Copy your \"Personal Auth Token\" (NOT a project API key).\n4. Paste it below — Comp will use it with HTTP Basic auth (token as username).", "credentialFields": [ { - "label": "Encoded API Key", + "label": "Personal Auth Token", "type": "password", "required": true, - "helpText": "Base64 encode 'api_key:' (your API key with a colon and empty password). Command: echo -n 'your_api_key:' | base64" + "helpText": "Your Honeybadger Personal Auth Token (from Profile > Authentication). Used as the HTTP Basic auth username; Comp adds the empty password automatically." } ] } @@ -28,14 +28,14 @@ { "slug": "honeybadger_monitoring", "name": "Monitoring & Alerting", - "description": "Verifies Honeybadger projects are configured for error monitoring", + "description": "Verifies Honeybadger projects exist and are actively monitoring application errors.", "defaultSeverity": "medium", "enabled": true }, { "slug": "honeybadger_incident_response", "name": "Incident Response", - "description": "Verifies Honeybadger uptime checks are configured for availability monitoring", + "description": "Verifies Honeybadger faults (incidents) are being tracked per project and surfaces unresolved faults for triage.", "defaultSeverity": "medium", "enabled": true } diff --git a/integrations-catalog/integrations/hubspot.json b/integrations-catalog/integrations/hubspot.json index a3dadb1cc7..4cdc48e207 100644 --- a/integrations-catalog/integrations/hubspot.json +++ b/integrations-catalog/integrations/hubspot.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to HubSpot as a Super Admin\n2. Go to Development (left sidebar)\n3. Click Keys > Service keys\n4. Click \"Create service key\" in the top right\n5. Name your key (e.g. \"CompAI\")\n6. Click \"Add new scope\" and select: settings.users.read, crm.objects.owners.read\n7. Click Update, then Create\n8. Copy the service key and paste it below\n\nNote: If you still see Private Apps instead of Service Keys, go to Development > Legacy apps and create a legacy private app with the same scopes.", + "setupInstructions": "Step 1 — Create a HubSpot Private App\n1. In HubSpot, go to Settings > Integrations > Private Apps (https://app.hubspot.com/private-apps)\n2. Click Create a private app\n3. Name it (e.g. \"Comp AI\")\n4. Under Scopes, add:\n - account-info.security.read (account info check)\n - settings.users.read (employee access check)\n - crm.objects.owners.read (contact information check)\n5. Click Create app and copy the access token\n\nToken format: starts with \"pat-\" followed by your data-center region (e.g. pat-na1-..., pat-eu1-..., pat-na2-...)\n\nStep 2 — Paste the access token below\n\nNote: HubSpot updates scopes on the existing token when you change them — no need to regenerate the token after adding scopes (as of 2024 docs).", "credentialFields": [ { "label": "Service Key", diff --git a/integrations-catalog/integrations/humaans.json b/integrations-catalog/integrations/humaans.json index f609b17fe4..d39b2f159e 100644 --- a/integrations-catalog/integrations/humaans.json +++ b/integrations-catalog/integrations/humaans.json @@ -25,6 +25,13 @@ "supportsMultipleConnections": false, "syncSupported": false, "checks": [ + { + "slug": "humaans_app_availability", + "name": "Humaans App Availability", + "description": "Verifies the Humaans API is reachable with the supplied token.", + "defaultSeverity": "high", + "enabled": true + }, { "slug": "humaans_employee_access", "name": "Employee Access", @@ -33,6 +40,6 @@ "enabled": true } ], - "checkCount": 1, + "checkCount": 2, "isActive": true } diff --git a/integrations-catalog/integrations/infisical.json b/integrations-catalog/integrations/infisical.json index 90cddab85e..61359bb1d2 100644 --- a/integrations-catalog/integrations/infisical.json +++ b/integrations-catalog/integrations/infisical.json @@ -8,7 +8,7 @@ "authConfig": { "type": "api_key", "config": { - "setupInstructions": "1. Create a Machine Identity in Infisical (Org Settings > Access Control > Identities)\n2. Assign the 'Member' role (or a custom role with project read access)\n3. Configure authentication - choose ONE:\n\n Option A (Token Auth - simplest):\n - On the identity page, switch auth to Token Auth\n - Create an access token directly in the UI\n - Copy and paste it below\n\n Option B (Universal Auth):\n - Configure Universal Auth on the identity\n - Note the Client ID and Client Secret\n - Exchange them for an access token: POST https://app.infisical.com/api/v1/auth/universal-auth/login\n - Paste the access token below\n\nIMPORTANT: Service tokens will NOT work. You must use a Machine Identity.\nNote: Access tokens expire (default 30 days). You may need to refresh periodically." + "setupInstructions": "1. Pick your Infisical region first - the US (app.infisical.com / us.infisical.com) and EU (eu.infisical.com) platforms are separate. Do every step below on the SAME host your organization lives on: a token created in one region is rejected by the other (\"invalid signature\"). No region selection is needed in Comp AI - the region is detected automatically from your token.\n2. Create a Machine Identity in Infisical (Org Settings > Access Control > Identities)\n3. Assign the 'Member' role (or a custom role with project read access)\n4. Configure authentication - choose ONE:\n\n Option A (Token Auth - simplest):\n - On the identity page, switch auth to Token Auth\n - Create an access token directly in the UI\n - Copy and paste it below\n\n Option B (Universal Auth):\n - Configure Universal Auth on the identity\n - Note the Client ID and Client Secret\n - Exchange them for an access token on YOUR region's host:\n US: POST https://app.infisical.com/api/v1/auth/universal-auth/login\n EU: POST https://eu.infisical.com/api/v1/auth/universal-auth/login\n - Paste the access token below\n\nIMPORTANT: Service tokens will NOT work. You must use a Machine Identity.\nNote: Access tokens expire (default 30 days). You may need to refresh periodically.\nSelf-hosted Infisical is not supported by this integration - contact support if you run your own instance." } }, "capabilities": [ diff --git a/integrations-catalog/integrations/inngest.json b/integrations-catalog/integrations/inngest.json index bbb2715ac2..f41de095b2 100644 --- a/integrations-catalog/integrations/inngest.json +++ b/integrations-catalog/integrations/inngest.json @@ -6,9 +6,16 @@ "docsUrl": "https://www.inngest.com/docs/reference/", "baseUrl": "https://api.inngest.com", "authConfig": { - "type": "api_key", + "type": "custom", "config": { - "setupInstructions": "1. Log in to your Inngest Cloud dashboard\n2. Go to Profile menu (bottom left) > API Keys\n3. Create a new API key (or use your environment signing key)\n4. Enter it below" + "setupInstructions": "1. Log in to Inngest Cloud (https://app.inngest.com).\n2. Select the environment you want to monitor (Production or a branch env).\n3. Go to Manage > Signing Key and copy the value (starts with \"signkey-\").\n4. Paste the signing key above and save.\nNote: Inngest does not provide a public REST endpoint for listing team members, so the employee-access check is informational only and asks you to perform a manual review in the Inngest dashboard.", + "credentialFields": [ + { + "label": "Signing Key", + "type": "password", + "required": true + } + ] } }, "capabilities": [ diff --git a/integrations-catalog/integrations/intune.json b/integrations-catalog/integrations/intune.json index f018d94362..1efd0540b3 100644 --- a/integrations-catalog/integrations/intune.json +++ b/integrations-catalog/integrations/intune.json @@ -23,7 +23,8 @@ } }, "capabilities": [ - "checks" + "checks", + "device_sync" ], "supportsMultipleConnections": false, "syncSupported": false, diff --git a/integrations-catalog/integrations/jenkins.json b/integrations-catalog/integrations/jenkins.json index d4127cbbe0..a2195841d7 100644 --- a/integrations-catalog/integrations/jenkins.json +++ b/integrations-catalog/integrations/jenkins.json @@ -6,15 +6,27 @@ "docsUrl": "https://www.jenkins.io/doc/book/using/remote-access-api/", "baseUrl": "https://jenkins.example.com", "authConfig": { - "type": "basic", + "type": "custom", "config": { - "setupInstructions": "1. Log in to your Jenkins server\n2. Click your username (top-right) → Configure\n3. Under API Token, click Add new Token → Generate\n4. Copy the token\n5. Enter your Jenkins URL below\n6. Use your Jenkins username and the API token as the password", + "setupInstructions": "1. Log in to your Jenkins server.\n2. Click your username (top-right) > Configure.\n3. Under \"API Token\", click \"Add new Token\" > \"Generate\".\n4. Copy the generated token (shown once).\n5. Enter your Jenkins URL, username, and the API token below.\n\nNote: Jenkins is usually self-hosted. The instance must be reachable from CompAI (publicly, via a reverse proxy, or via an allow-listed proxy) for checks to run. The integration user needs at least Overall/Read and Job/Read.", "credentialFields": [ { "label": "Jenkins URL", "type": "text", "required": true, - "helpText": "Your Jenkins server URL (e.g. https://jenkins.yourcompany.com). No trailing slash." + "helpText": "Your Jenkins server URL (e.g. https://jenkins.yourcompany.com). No trailing slash. The instance must be reachable from CompAI." + }, + { + "label": "Jenkins Username", + "type": "text", + "required": true, + "helpText": "The Jenkins username that owns the API token." + }, + { + "label": "API Token", + "type": "password", + "required": true, + "helpText": "Jenkins API token. Profile > Configure > API Token > Add new Token > Generate. Treat it like a password." } ] } diff --git a/integrations-catalog/integrations/jumpcloud.json b/integrations-catalog/integrations/jumpcloud.json index fb86e320d4..3453c1d9fd 100644 --- a/integrations-catalog/integrations/jumpcloud.json +++ b/integrations-catalog/integrations/jumpcloud.json @@ -21,7 +21,8 @@ }, "capabilities": [ "checks", - "sync" + "sync", + "device_sync" ], "supportsMultipleConnections": false, "syncSupported": true, diff --git a/integrations-catalog/integrations/juro.json b/integrations-catalog/integrations/juro.json index c026762ed8..1429c374d4 100644 --- a/integrations-catalog/integrations/juro.json +++ b/integrations-catalog/integrations/juro.json @@ -4,7 +4,7 @@ "description": "Juro contract management and automation platform", "category": "Productivity", "docsUrl": "https://juro.com/integrations", - "baseUrl": "https://app.juro.com/api/v1", + "baseUrl": "https://api.juro.com/v1", "authConfig": { "type": "custom", "config": { diff --git a/integrations-catalog/integrations/kandji.json b/integrations-catalog/integrations/kandji.json index 550c698cbb..0270dd1988 100644 --- a/integrations-catalog/integrations/kandji.json +++ b/integrations-catalog/integrations/kandji.json @@ -8,11 +8,12 @@ "authConfig": { "type": "api_key", "config": { - "setupInstructions": "## Setup Iru (formerly Kandji) Integration\n\n1. Sign in to your Iru (formerly Kandji) admin console\n2. Go to **Settings** then **Access** then **API Token**\n3. Click **Add token** and give it a name like \"CompAI Integration\"\n4. Grant the token the **Device List** permission\n5. Copy the API token (it is only shown once)\n6. Note your Iru (formerly Kandji) subdomain from your URL (e.g. \"mycompany\" from mycompany.clients.us-1.kandji.io)\n7. Paste the API token and subdomain into CompAI" + "setupInstructions": "## Setup Iru (formerly Kandji) Integration\n\n1. Sign in to your Iru admin console\n2. Go to **Settings** -> **Access** -> **API Token**\n3. Click **Add Token**, give it a name like \"CompAI Integration\"\n4. Grant the token the **Device List** permission (read-only)\n5. Copy the API token (it is only shown once)\n6. Find your Iru API subdomain — it is the prefix in your API URL: `mycompany.api.kandji.io` -> subdomain is `mycompany`\n7. Paste the API token and the subdomain into CompAI" } }, "capabilities": [ - "checks" + "checks", + "device_sync" ], "supportsMultipleConnections": false, "syncSupported": false, diff --git a/integrations-catalog/integrations/kolide.json b/integrations-catalog/integrations/kolide.json index 09b83abc23..83cf52bb7a 100644 --- a/integrations-catalog/integrations/kolide.json +++ b/integrations-catalog/integrations/kolide.json @@ -27,15 +27,15 @@ "checks": [ { "slug": "kolide_secure_devices", - "name": "Secure Devices", - "description": "Reviews Kolide device compliance status", - "defaultSeverity": "medium", + "name": "All Kolide-managed devices pass security checks", + "description": "Verifies that every device enrolled in Kolide has zero unresolved security issues (disk encryption, screen lock, OS updates, MDM, etc.).", + "defaultSeverity": "high", "enabled": true }, { "slug": "kolide_employee_access", - "name": "Employee Access", - "description": "Lists Kolide users", + "name": "No Kolide users have open security issues", + "description": "Verifies that every enrolled Kolide user has zero unresolved Kolide issues. Fails if any user has open issues.", "defaultSeverity": "medium", "enabled": true } diff --git a/integrations-catalog/integrations/kong.json b/integrations-catalog/integrations/kong.json index 6eca9cdf96..9f3a70a84f 100644 --- a/integrations-catalog/integrations/kong.json +++ b/integrations-catalog/integrations/kong.json @@ -4,17 +4,23 @@ "description": "Monitor Kong API gateway for team access and role-based API management compliance", "category": "Infrastructure", "docsUrl": "https://docs.konghq.com/konnect/api/", - "baseUrl": "https://global.api.konghq.com/", + "baseUrl": "https://us.api.konghq.com", "authConfig": { - "type": "api_key", + "type": "custom", "config": { - "setupInstructions": "1. Log in to Kong Konnect at https://cloud.konghq.com\n2. Go to Personal Access Tokens\n3. Generate a new token\n4. Copy and enter it below", + "setupInstructions": "1. Log in to Kong Konnect at https://cloud.konghq.com (or eu.cloud / au.cloud for those regions)\n2. Click your profile > Personal Access Tokens\n3. Click \"Generate Token\", name it (e.g. \"Comp AI\"), and copy the token (starts with kpat_)\n4. Paste the token below and select the region matching your Konnect tenant\n\nThe token inherits the permissions of the user that generated it; an Organization Admin or read-only auditor role is sufficient.", "credentialFields": [ { "label": "Personal Access Token", "type": "password", "required": true, - "helpText": "Found in Kong Konnect → Personal Access Tokens" + "helpText": "Generate at Kong Konnect > Personal Access Tokens (starts with kpat_...)." + }, + { + "label": "Region", + "type": "select", + "required": true, + "helpText": "Pick the region shown in your Konnect URL (e.g. cloud.konghq.com vs eu.cloud.konghq.com)." } ] } diff --git a/integrations-catalog/integrations/lacework.json b/integrations-catalog/integrations/lacework.json index 4c23cb1006..b416a7f9f9 100644 --- a/integrations-catalog/integrations/lacework.json +++ b/integrations-catalog/integrations/lacework.json @@ -4,7 +4,7 @@ "description": "Monitor Lacework cloud security platform for threat detection and compliance posture", "category": "Security", "docsUrl": "https://docs.lacework.net/api/v2/docs/", - "baseUrl": "https://api.lacework.net/", + "baseUrl": "", "authConfig": { "type": "custom", "config": { diff --git a/integrations-catalog/integrations/microsoft-365.json b/integrations-catalog/integrations/microsoft-365.json index 171cd33b3d..cd674c47ac 100644 --- a/integrations-catalog/integrations/microsoft-365.json +++ b/integrations-catalog/integrations/microsoft-365.json @@ -45,7 +45,7 @@ { "slug": "m365_access_review_log", "name": "Access Review Log", - "description": "Verifies that Microsoft 365 directory audit logs are active and contain recent events", + "description": "Performs an access review of Microsoft 365 users and privileged directory roles.", "defaultSeverity": "high", "enabled": true } diff --git a/integrations-catalog/integrations/microsoft-defender.json b/integrations-catalog/integrations/microsoft-defender.json index 62cfa3e909..b1b5f65243 100644 --- a/integrations-catalog/integrations/microsoft-defender.json +++ b/integrations-catalog/integrations/microsoft-defender.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Go to Azure Portal → Microsoft Entra ID → App registrations\n2. Click 'New registration', name it (e.g. 'CompAI Defender'), register\n3. Note the Application (client) ID and Directory (tenant) ID\n4. Go to 'Certificates & secrets' → 'New client secret', copy the value\n5. Go to 'API permissions' → 'Add a permission' → 'APIs my organization uses'\n6. Search for 'Microsoft Threat Protection' (or 'WindowsDefenderATP')\n7. Select 'Application permissions' and add: Machine.Read.All, Alert.Read.All, Vulnerability.Read.All\n8. Click 'Grant admin consent' for your organization\n9. Paste the Tenant ID, Client ID, and Client Secret below", + "setupInstructions": "1. Go to Azure Portal → Microsoft Entra ID → App registrations → New registration (e.g. 'CompAI Defender')\n2. From the Overview page, copy the Application (client) ID and Directory (tenant) ID\n3. Go to Certificates & secrets → New client secret, copy the value (only shown once)\n4. Go to API permissions → Add a permission → APIs my organization uses\n IMPORTANT: pick \"APIs my organization uses\", NOT \"Microsoft Graph\".\n5. Search for and select WindowsDefenderATP (the Microsoft Defender for Endpoint API)\n6. Choose Application permissions and add:\n - Machine.Read.All\n - Alert.Read.All\n - Vulnerability.Read.All\n7. Click 'Grant admin consent' for your organization\n8. Paste the Tenant ID, Client ID, and Client Secret below\n\nNotes:\n - The API is registered in Azure AD under the name 'WindowsDefenderATP' even though Microsoft brands the product as Microsoft Defender for Endpoint.\n - The OAuth resource/scope is https://api.securitycenter.microsoft.com/.default — Microsoft has consolidated the API URL to api.security.microsoft.com but the token resource remains the legacy URL.", "credentialFields": [ { "label": "Tenant ID", @@ -56,7 +56,7 @@ "name": "Vulnerability Scanning", "description": "Retrieves vulnerabilities detected by Microsoft Defender for Endpoint and reports critical and high severity findings.", "defaultSeverity": "high", - "enabled": true + "enabled": false } ], "checkCount": 3, diff --git a/integrations-catalog/integrations/mongodb-atlas.json b/integrations-catalog/integrations/mongodb-atlas.json index 0cf786f501..d4d5419c9d 100644 --- a/integrations-catalog/integrations/mongodb-atlas.json +++ b/integrations-catalog/integrations/mongodb-atlas.json @@ -8,24 +8,25 @@ "authConfig": { "type": "custom", "config": { + "setupInstructions": "1. In MongoDB Atlas, go to Organization > Access Manager > Applications.\n2. Click 'Add Service Account', name it (e.g. 'Comp AI'), choose a secret expiry, and grant it the 'Organization Read Only' role.\n3. Click Create, then copy the Client ID and the Client Secret (the secret is shown only once).\n4. Find your Organization ID under Organization Settings (or the cloud.mongodb.com URL after /org/).\n5. Enter the Client ID, Client Secret, and Organization ID below.", "credentialFields": [ { - "label": "Public API Key", + "label": "Service Account Client ID", "type": "text", "required": true, - "helpText": "Your MongoDB Atlas programmatic API public key. Create one at Organization > Access Manager > API Keys." + "helpText": "From Organization > Access Manager > Applications > your Service Account. Looks like mdb_sa_id_..." }, { - "label": "Private API Key", + "label": "Service Account Client Secret", "type": "password", "required": true, - "helpText": "Your MongoDB Atlas programmatic API private key. Shown only once at creation time." + "helpText": "Shown only once when the Service Account is created. Looks like mdb_sa_sk_..." }, { "label": "Organization ID", "type": "text", "required": true, - "helpText": "Your MongoDB Atlas Organization ID. Found at Organization Settings > General." + "helpText": "Your MongoDB Atlas Organization ID (Organization Settings, or the 24-character hex in the cloud.mongodb.com URL)." } ] } diff --git a/integrations-catalog/integrations/mosyle.json b/integrations-catalog/integrations/mosyle.json index 129fccb0da..33fae5083f 100644 --- a/integrations-catalog/integrations/mosyle.json +++ b/integrations-catalog/integrations/mosyle.json @@ -8,31 +8,31 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to your Mosyle admin console\n2. Go to Organization > API Integration\n3. Enable the API and generate an Access Token\n4. Copy the Access Token\n5. Enter the token along with your admin email and password", + "setupInstructions": "Mosyle has two products with separate APIs; pick the one that matches your subscription:\n - Mosyle Business (Enterprise) — for businesses, uses businessapi.mosyle.com/v1\n - Mosyle Manager (Education) — for schools, uses managerapi.mosyle.com/v2\nSelecting the wrong environment will always fail — Mosyle treats them as separate APIs.\n\nSteps:\n1. Sign in to your Mosyle admin console (mybusiness.mosyle.com or myschool.mosyle.com).\n2. Go to Organization → API Integration.\n3. Enable the API Integration if it is not already enabled.\n4. Generate a new Access Token (or copy an existing one).\n5. Below, fill in: the Mosyle Environment that matches your product, the Access Token, and the Admin Email and Password of a Mosyle administrator user. Mosyle Business requires the admin email/password — the Access Token alone is not sufficient because Mosyle exchanges them for a session token on every connection.\n\nNotes:\n - If you regenerate the Access Token, paste the new value here and re-run the check.\n - The Admin Email and Password are the same credentials you use to log into the Mosyle web console.", "credentialFields": [ { "label": "Mosyle Environment", "type": "select", "required": true, - "helpText": "Select your Mosyle product type" + "helpText": "Select your Mosyle product. Business = businessapi.mosyle.com/v1; Manager = managerapi.mosyle.com/v2." }, { "label": "Access Token", "type": "password", "required": true, - "helpText": "API access token from Organization > API Integration" + "helpText": "Generated in your Mosyle admin console: Organization → API Integration." }, { "label": "Admin Email", "type": "text", "required": true, - "helpText": "Email address of an admin user for API authentication" + "helpText": "Email of a Mosyle administrator user. Mosyle Business exchanges this with your password (plus the Access Token) for a session token on every connection." }, { "label": "Admin Password", "type": "password", "required": true, - "helpText": "Password for the admin user account" + "helpText": "Password of the Mosyle administrator user above." } ] } diff --git a/integrations-catalog/integrations/motherduck.json b/integrations-catalog/integrations/motherduck.json index c0243be093..f86b9d1e32 100644 --- a/integrations-catalog/integrations/motherduck.json +++ b/integrations-catalog/integrations/motherduck.json @@ -20,7 +20,7 @@ "name": "MotherDuck App Availability", "description": "Checks that the MotherDuck API is accessible.", "defaultSeverity": "medium", - "enabled": true + "enabled": false }, { "slug": "motherduck_employee_access", diff --git a/integrations-catalog/integrations/new-relic.json b/integrations-catalog/integrations/new-relic.json index f8d153a4df..bdf00b5823 100644 --- a/integrations-catalog/integrations/new-relic.json +++ b/integrations-catalog/integrations/new-relic.json @@ -8,13 +8,19 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to New Relic One (one.newrelic.com)\n2. Click your user icon > API keys\n3. Click 'Create a key' and select type 'User'\n4. Copy and paste the key below", + "setupInstructions": "1. Sign in to New Relic (one.newrelic.com, or one.eu.newrelic.com for EU accounts).\n2. Open the user menu (bottom left) > API keys.\n3. Click 'Create a key', choose key type 'User', name it (e.g. 'Comp AI'), and create it.\n4. Copy the key (it starts with NRAK-) and paste it below.\n5. Set Region to EU if you sign in at one.eu.newrelic.com; otherwise leave it as US. The wrong region causes authentication failures.", "credentialFields": [ { "label": "API Key", "type": "password", "required": true, "helpText": "Create a User API Key under your New Relic profile > API keys" + }, + { + "label": "Data center region", + "type": "select", + "required": false, + "helpText": "Select EU if your New Relic account is hosted in the EU (you sign in at one.eu.newrelic.com); otherwise select US. Choosing the wrong region causes authentication (HTTP 403) errors." } ] } @@ -42,7 +48,7 @@ { "slug": "alert_channels", "name": "Incident Response", - "description": "Verifies that New Relic alert channels are configured for incident notifications", + "description": "Verify New Relic has notification destinations configured (email, Slack, PagerDuty, etc.) via NerdGraph so alert workflows can deliver incidents.", "defaultSeverity": "high", "enabled": true } diff --git a/integrations-catalog/integrations/ninjio.json b/integrations-catalog/integrations/ninjio.json new file mode 100644 index 0000000000..bb7f3e1b69 --- /dev/null +++ b/integrations-catalog/integrations/ninjio.json @@ -0,0 +1,38 @@ +{ + "slug": "ninjio", + "name": "NINJIO", + "description": "Security awareness training evidence from NINJIO: year-to-date training episodes released and per-employee completion status.", + "category": "Security", + "docsUrl": null, + "baseUrl": "https://apigw.goninjio.com/api/api_gateway", + "authConfig": { + "type": "custom", + "config": { + "setupInstructions": "1. Sign in to the NINJIO Admin Center at admin.goninjio.com as an administrator.\n2. Go to Integration > API Keys and click 'New API Key'.\n3. Give it read access (e.g. name it 'Comp AI') and create it.\n4. Copy the API key and paste it below. Comp AI uses it read-only to report year-to-date training episodes released and employee completion status.", + "credentialFields": [ + { + "label": "API Key", + "type": "password", + "required": true, + "helpText": "Create a read API key in the NINJIO Admin Center (admin.goninjio.com > Integration > API Keys > New API Key)." + } + ] + } + }, + "capabilities": [ + "checks" + ], + "supportsMultipleConnections": false, + "syncSupported": false, + "checks": [ + { + "slug": "ninjio_security_awareness_training", + "name": "Security Awareness Training", + "description": "Reports year-to-date security awareness training from NINJIO: which training episodes were released and when, and which employees have completed vs are still working on their assigned training.", + "defaultSeverity": "high", + "enabled": true + } + ], + "checkCount": 1, + "isActive": true +} diff --git a/integrations-catalog/integrations/odoo.json b/integrations-catalog/integrations/odoo.json new file mode 100644 index 0000000000..f9b9b1bb9d --- /dev/null +++ b/integrations-catalog/integrations/odoo.json @@ -0,0 +1,63 @@ +{ + "slug": "odoo", + "name": "Odoo", + "description": "Audit Odoo ERP for application availability and employee access via the External JSON-RPC API.", + "category": "HR & People", + "docsUrl": "https://www.odoo.com/documentation/master/developer/reference/external_api.html", + "baseUrl": "https://www.odoo.com/", + "authConfig": { + "type": "custom", + "config": { + "setupInstructions": "Odoo exposes a JSON-RPC API at /jsonrpc that accepts a database name + username + API key. To connect:\n\nStep 1 — Generate an API key\n1. In Odoo, click your avatar (top-right) and choose Preferences (older versions: My Profile)\n2. Open the Account Security tab\n3. Click New API Key, give it a name (e.g. \"Comp AI\"), and copy the key — it is only shown once\n\nNote: Odoo Online accounts must have a local password set on the user before API keys can be generated (avatar > Preferences > Account Security > Change Password). On Odoo 19+ API keys have a maximum duration of three months and must be rotated.\n\nStep 2 — Find your database name\n - Odoo Online: it's your company subdomain (e.g. \"acme\" for acme.odoo.com)\n - Self-hosted: it's the database name configured in odoo.conf, or visible in the login screen URL as `?db=...`\n\nStep 3 — Paste all four values below\n - Instance URL (with https://, no trailing slash needed — we normalize it)\n - Database name\n - Your administrator email / login\n - The API key from step 1\n\nThe connecting user needs read access to res.users and (for the Employee Access check) read access to hr.employee. If the HR module is not installed, the Employee Access check automatically falls back to listing internal users from res.users.", + "credentialFields": [ + { + "label": "Odoo Instance URL", + "type": "text", + "required": true, + "helpText": "Your Odoo instance URL — for Odoo Online it looks like https://yourcompany.odoo.com, for self-hosted it's your installation's domain." + }, + { + "label": "Database Name", + "type": "text", + "required": true, + "helpText": "The Odoo database name. For Odoo Online it's usually your company subdomain (e.g. \"yourcompany\"). You can confirm it in the Odoo login screen URL parameter `?db=...`." + }, + { + "label": "Username (Email)", + "type": "text", + "required": true, + "helpText": "The Odoo login (usually an email) of an administrator account." + }, + { + "label": "API Key", + "type": "password", + "required": true, + "helpText": "Generate at Odoo > Settings > Users > Account Security > Developer API Keys > New API Key. Do not paste your master password — use a scoped API key." + } + ] + } + }, + "capabilities": [ + "checks" + ], + "supportsMultipleConnections": false, + "syncSupported": false, + "checks": [ + { + "slug": "odoo_app_availability", + "name": "Odoo App Availability", + "description": "Verifies the Odoo instance is reachable, the database accepts the credentials, and a basic query returns successfully.", + "defaultSeverity": "medium", + "enabled": true + }, + { + "slug": "odoo_employee_access", + "name": "Odoo Employee Access", + "description": "Lists employees (or internal users) so you can review who has access to the Odoo platform.", + "defaultSeverity": "medium", + "enabled": true + } + ], + "checkCount": 2, + "isActive": true +} diff --git a/integrations-catalog/integrations/openai.json b/integrations-catalog/integrations/openai.json index 62b7b187cc..967b7630e7 100644 --- a/integrations-catalog/integrations/openai.json +++ b/integrations-catalog/integrations/openai.json @@ -8,13 +8,13 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to platform.openai.com\n2. Go to API Keys\n3. Create a new secret key\n4. Paste it below", + "setupInstructions": "The OpenAI integration requires an Admin API Key (not a regular API key) to read organization users, projects, and audit data.\n\nStep 1 — Create an Admin API Key\n1. Sign in to https://platform.openai.com as an Organization Owner\n2. Go to Settings > Organization > Admin keys (https://platform.openai.com/settings/organization/admin-keys)\n3. Click Create new key\n4. Name it (e.g. \"Comp AI\") and grant these scopes:\n - api.management.read (required for user/project listings)\n - api.model.read (required for model availability checks)\n5. Copy the key (starts with \"sk-admin-\") — it's shown only once\n\nImportant: Regular API keys (sk-..., sk-proj-...) cannot list organization users and will return HTTP 401/403 with \"Missing scopes\" errors.\n\nStep 2 — Paste the Admin key in the integration settings below", "credentialFields": [ { "label": "API Key", "type": "password", "required": true, - "helpText": "OpenAI → Platform → API Keys → Create new secret key" + "helpText": "Admin API key (starts with sk-admin-) from Settings > Organization > Admin keys" } ] } diff --git a/integrations-catalog/integrations/openstack.json b/integrations-catalog/integrations/openstack.json new file mode 100644 index 0000000000..93f56ebbaf --- /dev/null +++ b/integrations-catalog/integrations/openstack.json @@ -0,0 +1,75 @@ +{ + "slug": "openstack", + "name": "OpenStack", + "description": "Open-source private cloud platform. Comp AI connects to the Keystone v3 Identity service to verify availability and list users for access review.", + "category": "Cloud", + "docsUrl": "https://docs.openstack.org/api-ref/identity/v3/index.html", + "baseUrl": "https://www.openstack.org", + "authConfig": { + "type": "custom", + "config": { + "setupInstructions": "OpenStack is a self-hosted private cloud platform. To connect Comp AI, the Keystone v3 endpoint must be reachable from the public internet (or from Comp AI egress IPs if you allowlist them).\n\n1. In your OpenStack deployment, create a dedicated read-only user account for Comp AI (or reuse an existing one).\n2. Assign the user the 'reader' role at the **domain** (or system) level so it can list users in /v3/users — a project-level reader role is not sufficient. Via CLI:\n `openstack role add --user --user-domain --domain reader`\n To list users across all domains, use system scope instead:\n `openstack role add --user --user-domain --system all reader`\n (The 'reader' role is provided out-of-the-box on OpenStack Rocky [2018] and newer.)\n3. Find the Keystone v3 endpoint URL — usually shown in Horizon: Identity → Endpoints, or via CLI: `openstack endpoint list --service identity`. The full URL ends in /v3 (e.g. https://openstack.example.com:5000/v3 or https://openstack.example.com/identity/v3).\n4. Paste the Auth URL, username, password, project name (used to scope the auth token), user domain name, and project domain name below. The domain names are usually 'Default' unless your deployment uses LDAP-backed or multi-domain identity.\n\nNote: Comp AI only calls the Keystone Identity service for user/auth data. Nova, Neutron, and other OpenStack services are not used.", + "credentialFields": [ + { + "label": "Keystone Auth URL", + "type": "text", + "required": true, + "helpText": "Full Keystone v3 URL. Example: https://openstack.example.com:5000/v3" + }, + { + "label": "Username", + "type": "text", + "required": true, + "helpText": "Username of the Comp AI service account in OpenStack." + }, + { + "label": "Password", + "type": "password", + "required": true, + "helpText": "Password for the Comp AI service account." + }, + { + "label": "Project Name", + "type": "text", + "required": true, + "helpText": "OpenStack project (tenant) to scope the auth token to." + }, + { + "label": "User Domain Name", + "type": "text", + "required": false, + "helpText": "Domain where the user lives. Usually 'Default'." + }, + { + "label": "Project Domain Name", + "type": "text", + "required": false, + "helpText": "Domain where the project lives. Usually 'Default'." + } + ] + } + }, + "capabilities": [ + "checks" + ], + "supportsMultipleConnections": false, + "syncSupported": false, + "checks": [ + { + "slug": "openstack_app_availability", + "name": "OpenStack App Availability", + "description": "Verifies that the Keystone v3 endpoint is reachable and the configured credentials can obtain a project-scoped token.", + "defaultSeverity": "medium", + "enabled": true + }, + { + "slug": "openstack_employee_access", + "name": "OpenStack Employee Access", + "description": "Lists Keystone users for periodic access review. Returns total users, enabled vs. disabled counts, and a sample of user records.", + "defaultSeverity": "medium", + "enabled": true + } + ], + "checkCount": 2, + "isActive": true +} diff --git a/integrations-catalog/integrations/pagerduty.json b/integrations-catalog/integrations/pagerduty.json index adfc1e963c..fc2a06426c 100644 --- a/integrations-catalog/integrations/pagerduty.json +++ b/integrations-catalog/integrations/pagerduty.json @@ -8,13 +8,13 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to PagerDuty.\n2. Go to Integrations > API Access Keys.\n3. Click 'Create New API Key', give it a description (e.g. 'Comp AI'), select Read-Only.\n4. Copy the API key and paste it below.", + "setupInstructions": "1. Log in to PagerDuty as an Admin or Account Owner.\n2. In the web app, navigate to Integrations > Developer Tools > API Access Keys.\n3. Click 'Create New API Key'.\n4. Enter a Description (e.g. 'Comp AI'), check 'Read-only API Key', then click 'Create Key'.\n5. Copy the API key (shown only once) and paste it below.", "credentialFields": [ { "label": "API Key", "type": "password", "required": true, - "helpText": "Found in PagerDuty > Integrations > API Access Keys. Create a General Access Key with Read-Only access." + "helpText": "Found in PagerDuty > Integrations > Developer Tools > API Access Keys. Create a General Access REST API Key with 'Read-only API Key' checked." } ] } diff --git a/integrations-catalog/integrations/pendo.json b/integrations-catalog/integrations/pendo.json index fea0596704..67adba9428 100644 --- a/integrations-catalog/integrations/pendo.json +++ b/integrations-catalog/integrations/pendo.json @@ -7,7 +7,23 @@ "baseUrl": "https://app.pendo.io/", "authConfig": { "type": "api_key", - "config": {} + "config": { + "setupInstructions": "1. Log in to Pendo\n2. Settings > Integrations > Integration Keys\n3. Create or copy an integration key\n4. Paste below and select your data region", + "credentialFields": [ + { + "label": "Integration Key", + "type": "password", + "required": true, + "helpText": "From Pendo Settings > Integrations > Integration Keys." + }, + { + "label": "Data Region", + "type": "select", + "required": false, + "helpText": "Select EU if your Pendo subscription is hosted in the EU data center." + } + ] + } }, "capabilities": [ "checks" diff --git a/integrations-catalog/integrations/power-bi.json b/integrations-catalog/integrations/power-bi.json index 4090ef36d5..b8690bb7f4 100644 --- a/integrations-catalog/integrations/power-bi.json +++ b/integrations-catalog/integrations/power-bi.json @@ -42,7 +42,7 @@ "name": "Employee Access", "description": "Lists all users across Power BI workspaces with their access roles. Retrieves workspaces (groups) with expanded user membership to identify who has access and at what permission level (Admin, Member, Contributor, Viewer).", "defaultSeverity": "medium", - "enabled": true + "enabled": false }, { "slug": "power_bi_app_availability", diff --git a/integrations-catalog/integrations/ramp.json b/integrations-catalog/integrations/ramp.json index dc10ee619f..71006f8b9f 100644 --- a/integrations-catalog/integrations/ramp.json +++ b/integrations-catalog/integrations/ramp.json @@ -12,7 +12,7 @@ "scopes": [ "users:read" ], - "clientAuthMethod": "body", + "clientAuthMethod": "header", "supportsRefreshToken": true } }, diff --git a/integrations-catalog/integrations/remote.json b/integrations-catalog/integrations/remote.json index 599286fe1d..0c3c43c1e7 100644 --- a/integrations-catalog/integrations/remote.json +++ b/integrations-catalog/integrations/remote.json @@ -3,12 +3,12 @@ "name": "Remote", "description": "Global HR platform for distributed teams. Monitor employee records.", "category": "HR & People", - "docsUrl": "https://gateway.remote.com/v1/docs", + "docsUrl": "https://developer.remote.com/docs", "baseUrl": "https://gateway.remote.com", "authConfig": { "type": "api_key", "config": { - "setupInstructions": "1. Log in to Remote at https://remote.com\n2. Go to Company Settings → Integrations & APIs → Integrations\n3. Click on the Remote API card\n4. Click Generate API token\n5. Copy the token (starts with ra_live_) and paste it below" + "setupInstructions": "You must be a company admin or company owner in Remote to generate API tokens.\n\n1. Log in to Remote at https://remote.com\n2. Navigate to: Company > Company Settings > Integrations & APIs > Integrations\n3. Find the Remote API card and click it\n4. Click Generate API token (or Create new token)\n5. Under Endpoint collections, select \"Read only\"\n (\"Read only\" is sufficient — Comp AI does not modify your Remote data)\n6. Click Generate, then copy the token (it starts with ra_live_)\n7. Paste the token below" } }, "capabilities": [ @@ -20,14 +20,14 @@ { "slug": "remote_app_availability", "name": "Remote App Availability", - "description": "Checks Remote app availability.", + "description": "Verifies that the Remote API is accessible and the API token is valid by listing company managers.", "defaultSeverity": "medium", "enabled": true }, { "slug": "remote_employee_access", "name": "Remote Employee Access", - "description": "Checks Remote employee access.", + "description": "Verifies that Remote has active company managers with admin access configured for proper employee management oversight.", "defaultSeverity": "medium", "enabled": true } diff --git a/integrations-catalog/integrations/roboflow.json b/integrations-catalog/integrations/roboflow.json index 4a7d7ddd55..aea369ae01 100644 --- a/integrations-catalog/integrations/roboflow.json +++ b/integrations-catalog/integrations/roboflow.json @@ -8,7 +8,7 @@ "authConfig": { "type": "api_key", "config": { - "setupInstructions": "1. Log in to Roboflow at https://app.roboflow.com\n2. Go to Settings → API Keys (or Workspace Settings → Roboflow API)\n3. Copy your API key\n4. Paste it below" + "setupInstructions": "1. Log in to Roboflow at https://app.roboflow.com\n2. Go to Settings -> Roboflow API (or Workspace Settings)\n3. Copy your workspace API key\n4. Paste it below" } }, "capabilities": [ diff --git a/integrations-catalog/integrations/roboform.json b/integrations-catalog/integrations/roboform.json new file mode 100644 index 0000000000..be36e75d0f --- /dev/null +++ b/integrations-catalog/integrations/roboform.json @@ -0,0 +1,51 @@ +{ + "slug": "roboform", + "name": "RoboForm", + "description": "Audit RoboForm for Business user provisioning and employee access via SCIM 2.0.", + "category": "Security", + "docsUrl": "https://help.roboform.com/hc/en-us/articles/19684686751373-SCIM-provisioning-integration-with-Azure-Entra-AD", + "baseUrl": "https://scim.roboform.com/", + "authConfig": { + "type": "custom", + "config": { + "setupInstructions": "RoboForm exposes user provisioning data through its SCIM 2.0 endpoint. To connect:\n\nStep 1 — Open the RoboForm Admin Console\n1. Sign in as an administrator at https://www.roboform.com/business\n2. Open the admin console (Manage)\n\nStep 2 — Generate SCIM credentials\n1. Go to Company Settings > SCIM Provisioning\n2. Copy the SCIM Server URL\n3. Click Generate New Token and copy the token (shown only once)\n\nStep 3 — Paste both values below\n - SCIM Server URL: the URL from step 2 (must end with a trailing slash)\n - SCIM Bearer Token: the token from step 2\n\nNote: this integration is read-only — it only inspects the user list exposed via SCIM, it never writes back.", + "credentialFields": [ + { + "label": "SCIM Server URL", + "type": "text", + "required": true, + "helpText": "Found in RoboForm Admin Console > Company Settings > SCIM Provisioning. Looks like https://scim.roboform.com/scim/v2/.../" + }, + { + "label": "SCIM Bearer Token", + "type": "password", + "required": true, + "helpText": "Generated alongside the SCIM URL in the RoboForm Admin Console > Company Settings > SCIM Provisioning section." + } + ] + } + }, + "capabilities": [ + "checks" + ], + "supportsMultipleConnections": false, + "syncSupported": false, + "checks": [ + { + "slug": "roboform_app_availability", + "name": "RoboForm App Availability", + "description": "Verifies the RoboForm SCIM endpoint is reachable and the bearer token is accepted.", + "defaultSeverity": "medium", + "enabled": true + }, + { + "slug": "roboform_employee_access", + "name": "RoboForm Employee Access", + "description": "Lists users provisioned in RoboForm for Business so you can review who has access to the password vault.", + "defaultSeverity": "medium", + "enabled": true + } + ], + "checkCount": 2, + "isActive": true +} diff --git a/integrations-catalog/integrations/salesforce.json b/integrations-catalog/integrations/salesforce.json index 24fe4f99c9..99abc9eb8e 100644 --- a/integrations-catalog/integrations/salesforce.json +++ b/integrations-catalog/integrations/salesforce.json @@ -8,7 +8,7 @@ "authConfig": { "type": "oauth2", "config": { - "setupInstructions": "1. Go to Salesforce > Setup > App Manager > New Connected App\n2. Enable OAuth Settings\n3. Set callback URL to: https://api.trycomp.ai/v1/integrations/oauth/callback\n4. Add scopes: Access (api), ID (id), Offline (offline_access)\n5. Copy Consumer Key (Client ID) and Secret\n6. After connecting, enter your Salesforce instance URL (e.g. https://yourorg.my.salesforce.com)", + "setupInstructions": "1. In Salesforce: Setup → App Manager → New Connected App.\n2. Enable OAuth Settings.\n3. Set the Callback URL to: https://api.trycomp.ai/v1/integrations/oauth/callback\n4. Add OAuth scopes: Access the identity URL service (id), Manage user data via APIs (api), Perform requests at any time (refresh_token, offline_access).\n5. Save the Connected App. Copy the Consumer Key (Client ID) and Consumer Secret.\n6. Wait a few minutes for the Connected App to propagate, then click Connect in Comp AI and sign in to your Salesforce org.\n\nNotes:\n - This integration currently supports Salesforce Production orgs (login.salesforce.com). Sandbox (test.salesforce.com) is not yet supported.\n - The Salesforce instance URL is discovered automatically after connection — no manual entry needed.", "scopes": [ "id", "api", @@ -29,7 +29,7 @@ "name": "Employee Access", "description": "Reviews Salesforce users and verifies only active users have access", "defaultSeverity": "medium", - "enabled": true + "enabled": false }, { "slug": "salesforce_contact_information", diff --git a/integrations-catalog/integrations/secureframe.json b/integrations-catalog/integrations/secureframe.json index 471412bf17..844d8dc641 100644 --- a/integrations-catalog/integrations/secureframe.json +++ b/integrations-catalog/integrations/secureframe.json @@ -6,9 +6,23 @@ "docsUrl": "https://developers.secureframe.com/", "baseUrl": "https://api.secureframe.com", "authConfig": { - "type": "api_key", + "type": "custom", "config": { - "setupInstructions": "1. Log in to Secureframe at https://app.secureframe.com\n2. Go to Settings > API Keys\n3. Generate a new API key with read access\n4. Copy the API key and paste it below" + "setupInstructions": "1. Log in to Secureframe at https://app.secureframe.com\n2. Go to Settings > API Keys\n3. Generate a new API key pair (Access Key ID + Secret)\n4. Paste both fields below", + "credentialFields": [ + { + "label": "Access Key ID", + "type": "text", + "required": true, + "helpText": "From Secureframe Settings > API Keys" + }, + { + "label": "Secret Access Key", + "type": "password", + "required": true, + "helpText": "From Secureframe Settings > API Keys" + } + ] } }, "capabilities": [ diff --git a/integrations-catalog/integrations/sentry.json b/integrations-catalog/integrations/sentry.json index c4f7301686..dca7b666fd 100644 --- a/integrations-catalog/integrations/sentry.json +++ b/integrations-catalog/integrations/sentry.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Log in to Sentry\n2. Go to Settings > Developer Settings > Internal Integrations\n3. Create a new internal integration\n4. Set permissions: Organization: Read, Project: Read, and Alert Rule: Read\n5. Click Save, then copy the generated token", + "setupInstructions": "Step 1 — Create a Sentry Auth Token\n1. In Sentry, go to Settings > Auth Tokens (https://sentry.io/settings/account/api/auth-tokens/) — or for organizations: Settings > Developer Settings > User Auth Tokens\n2. Click Create New Token\n3. Add these scopes (read-only):\n - org:read (list organizations)\n - project:read (list projects)\n - alerts:read (read alert rules + monitoring config)\n - member:read (optional: read org members)\n4. Copy the token (starts with \"sntryu_\" for user tokens, \"sntrys_\" for org internal-integration tokens)\n\nStep 2 — Paste the token + your organization slug below\n\nSentry Region: This integration currently uses https://sentry.io (US). If you're on Sentry EU (de.sentry.io) or self-hosted Sentry, contact support — multi-region support is planned.", "credentialFields": [ { "label": "Auth Token", diff --git a/integrations-catalog/integrations/smartsheet.json b/integrations-catalog/integrations/smartsheet.json index 03f69d4984..45765ac7f8 100644 --- a/integrations-catalog/integrations/smartsheet.json +++ b/integrations-catalog/integrations/smartsheet.json @@ -7,7 +7,9 @@ "baseUrl": "https://api.smartsheet.com/", "authConfig": { "type": "api_key", - "config": {} + "config": { + "setupInstructions": "Plan tier requirement:\nThe Smartsheet API is restricted to Business and Enterprise plans. Free and Pro accounts cannot use this integration — calls will fail with errorCode 1013 ('operation not supported by your plan').\n\nSteps to generate a Smartsheet API access token:\n1. In Smartsheet, click your Account icon (top-right) → Personal Settings → API Access\n2. Click 'Generate new access token', name it (e.g. 'Comp AI compliance check'), and copy the value\n3. Paste the token into the API Key field below\n\nPermission requirements:\n - For the Employee Access check (lists users): the token must belong to a System Admin user with the ADMIN_USERS scope.\n - Tokens generated by non-admin users will fail with 403 even on Business/Enterprise plans.\n - If you regenerate the token in Smartsheet, paste the new value here — the old one is invalidated." + } }, "capabilities": [ "checks" diff --git a/integrations-catalog/integrations/snowflake.json b/integrations-catalog/integrations/snowflake.json index 5955079ece..642445d508 100644 --- a/integrations-catalog/integrations/snowflake.json +++ b/integrations-catalog/integrations/snowflake.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Find your Account Identifier from your Snowflake URL:\n https://.snowflakecomputing.com\n Example: 'myorg-myaccount'\n\n2. Set up a Network Policy:\n Snowflake requires a network policy to use Programmatic Access Tokens.\n In your Snowflake account, create a network policy that includes CompAI's IP address: 54.159.77.69\n Then assign that network policy to the user who will generate the token.\n\n3. Generate a Programmatic Access Token (PAT):\n Option A - In Snowsight, go to Admin > Users & Roles > select your user > Generate Token\n Option B - Use SQL to create a token for your user\n\n Note: The user's authentication policy must allow PATs. If you're having trouble generating a token, check your authentication policy settings.\n\n4. Copy the token and paste both values below.", + "setupInstructions": "1. Find your Account Identifier — the part before \".snowflakecomputing.com\" in your Snowflake URL, in the form \"myorg-myaccount\" (e.g. from https://myorg-myaccount.snowflakecomputing.com).\n\n2. Allow CompAI's IP (required to use the token):\n Snowflake requires the token's user to be covered by a network policy to generate and use a Programmatic Access Token. Create or update a network policy that allows CompAI's IP address 54.159.77.69, and assign it to that user.\n (Alternatively, choose \"Bypass requirement for network policy\" in the token dialog when generating.)\n\n3. Generate a Programmatic Access Token (PAT) in Snowsight:\n Generate it for a user with the SECURITYADMIN role (or ACCOUNTADMIN) — listing users requires the MANAGE GRANTS privilege that these roles have, which also lets the integration see your databases.\n In the left nav, open \"Users & roles\" (under \"Governance & security\", or under \"Admin\" in some accounts) → select that user → under \"Programmatic access tokens\" click \"Generate new token\". Name it, set an expiration, and if you set a role restriction (\"One specific role\") choose SECURITYADMIN. Click Generate and copy the token (it is shown only once).\n\n4. Paste your Account Identifier and the token below.\n\nComp AI uses this token read-only and never makes changes to your Snowflake account.", "credentialFields": [ { "label": "Account Identifier", @@ -20,7 +20,7 @@ "label": "Programmatic Access Token (PAT)", "type": "password", "required": true, - "helpText": "Generate via Snowsight: Admin → Users → select user → Generate Token. Or SQL: ALTER USER ADD PROGRAMMATIC ACCESS TOKEN DAYS_TO_EXPIRY = 30." + "helpText": "Generate in Snowsight: open \"Users & roles\" (under \"Governance & security\", or \"Admin\" in some accounts) → select a user with the SECURITYADMIN or ACCOUNTADMIN role → Programmatic access tokens → Generate new token. The user must be covered by a network policy that allows CompAI's IP (54.159.77.69), or choose \"Bypass requirement for network policy\" when generating." } ] } diff --git a/integrations-catalog/integrations/sonarqube-cloud.json b/integrations-catalog/integrations/sonarqube-cloud.json index 73c2e1c0ea..15e4328685 100644 --- a/integrations-catalog/integrations/sonarqube-cloud.json +++ b/integrations-catalog/integrations/sonarqube-cloud.json @@ -6,8 +6,18 @@ "docsUrl": "https://sonarcloud.io/web_api", "baseUrl": "https://sonarcloud.io", "authConfig": { - "type": "api_key", - "config": {} + "type": "custom", + "config": { + "setupInstructions": "1. Log in to SonarQube Cloud (sonarcloud.io)\n2. Go to My Account > Security\n3. Generate a new token\n4. Base64-encode it as token:\n5. Paste the encoded string below", + "credentialFields": [ + { + "label": "Base64 Encoded Token", + "type": "password", + "required": true, + "helpText": "Base64-encode 'your_token:' (with trailing colon). Create a token in SonarQube Cloud > My Account > Security." + } + ] + } }, "capabilities": [ "checks" diff --git a/integrations-catalog/integrations/trello.json b/integrations-catalog/integrations/trello.json index 3ad41dcf09..a54aa59c79 100644 --- a/integrations-catalog/integrations/trello.json +++ b/integrations-catalog/integrations/trello.json @@ -8,7 +8,7 @@ "authConfig": { "type": "custom", "config": { - "setupInstructions": "1. Go to https://trello.com/power-ups/admin\n2. Create a new Power-Up (or select an existing one)\n3. Click on your Power-Up → go to the API Key tab\n4. Copy your API Key\n5. Click the Token link next to your key → click Allow to authorize\n6. Copy the generated token\n7. Enter your API Key and Token below", + "setupInstructions": "1. Go to https://trello.com/power-ups/admin and create a new Power-Up (or open an existing one) for your workspace.\n2. Open your Power-Up > API Key tab. If no key exists yet, click 'Generate a new API Key'.\n3. Copy the API Key shown at the top — this is the long key, NOT the Secret listed next to it. (You do NOT need to set an 'Allowed Origin' for this connection.)\n4. Generate a read-only token that never expires: open the URL below in your browser, replacing YOUR_API_KEY with the key from step 3, then click 'Allow' and copy the token shown.\n https://trello.com/1/authorize?expiration=never&scope=read&response_type=token&name=Comp%20AI&key=YOUR_API_KEY\n5. Enter the API Key (step 3) and the Token (step 4) below. Both must belong to the same Power-Up.\nTip: the simple 'Token' link on the API Key page issues a token that expires in 30 days; using the URL above keeps the connection from breaking later.", "credentialFields": [ { "label": "API Key", diff --git a/integrations-catalog/integrations/unifi.json b/integrations-catalog/integrations/unifi.json index 8f061af927..c92f98eb5e 100644 --- a/integrations-catalog/integrations/unifi.json +++ b/integrations-catalog/integrations/unifi.json @@ -4,7 +4,7 @@ "description": "Ubiquiti UniFi network management platform. Monitors hosts, sites, devices, firewall policies, and ISP connectivity through the official UniFi Site Manager and Network APIs.", "category": "Infrastructure", "docsUrl": "https://developer.ui.com/site-manager/v1.0.0/gettingstarted", - "baseUrl": null, + "baseUrl": "https://api.ui.com", "authConfig": { "type": "custom", "config": { diff --git a/integrations-catalog/integrations/uptime-robot.json b/integrations-catalog/integrations/uptime-robot.json index 1762a72c0c..ea58c595d4 100644 --- a/integrations-catalog/integrations/uptime-robot.json +++ b/integrations-catalog/integrations/uptime-robot.json @@ -4,7 +4,7 @@ "description": "Monitor Uptime Robot uptime monitors and account accessibility for availability compliance", "category": "Monitoring", "docsUrl": "https://uptimerobot.com/api/v3/", - "baseUrl": "https://api.uptimerobot.com/v3", + "baseUrl": "https://api.uptimerobot.com/v2", "authConfig": { "type": "api_key", "config": { diff --git a/integrations-catalog/integrations/webflow.json b/integrations-catalog/integrations/webflow.json index 8525a5e265..5341fe1f66 100644 --- a/integrations-catalog/integrations/webflow.json +++ b/integrations-catalog/integrations/webflow.json @@ -8,7 +8,7 @@ "authConfig": { "type": "api_key", "config": { - "setupInstructions": "1. Log in to webflow.com\n2. Go to Account Settings > Integrations > API Access\n3. Generate an API token with sites:read scope\n4. Copy the token and paste it below" + "setupInstructions": "Step 1 — Log in to webflow.com\nStep 2 — Go to: Account Settings > Workspace Settings > Integrations > API Access\nStep 3 — Click \"Generate API token\" and give it a name (e.g. \"Comp AI\")\n\nStep 4 — CRITICAL: Select scopes\n In the scope selector, check the box: \"Sites > Read\"\n (By default NO scopes are selected. Without this checkbox, the integration will fail with \"OAuthForbidden: missing sites:read\".)\n \nStep 5 — Click \"Generate token\" and copy the token (starts with \"wf-\")\n\nStep 6 — Paste the token below\n\nCommon mistake: clicking Generate without scrolling down to check the Sites > Read box. If your integration fails with a 403 \"missing sites:read\" error, regenerate the token with that scope enabled." } }, "capabilities": [ diff --git a/integrations-catalog/integrations/xano.json b/integrations-catalog/integrations/xano.json new file mode 100644 index 0000000000..04564f26a1 --- /dev/null +++ b/integrations-catalog/integrations/xano.json @@ -0,0 +1,50 @@ +{ + "slug": "xano", + "name": "Xano", + "description": "Monitor Xano backend activity — verifies API request logging and audit events via the Metadata API.", + "category": "Development", + "docsUrl": null, + "baseUrl": "https://app.xano.com", + "authConfig": { + "type": "custom", + "config": { + "setupInstructions": "1. Find your Xano instance base URL — the domain of your Xano instance, e.g. https://x8ki-letl-twmt.n7.xano.io (paste the domain only, no extra path). It's visible in your browser while working in Xano.\n2. Create a Metadata API access token: in Xano go to Account Settings > Metadata API > Manage Access Tokens > Generate New Access Token. Grant it at least the \"Request History\" (read) scope (add \"Audit Logs\" for change-event evidence). Copy the token — it is shown only once.\n3. (Optional) Workspace ID — leave blank to auto-detect your workspaces, or enter a specific numeric workspace ID (visible in your Xano workspace URL).\n4. Enter the instance URL and access token below.", + "credentialFields": [ + { + "label": "Instance Base URL", + "type": "text", + "required": true, + "helpText": "Your Xano instance domain, e.g. https://x8ki-letl-twmt.n7.xano.io (domain only, no path)." + }, + { + "label": "Metadata API Access Token", + "type": "password", + "required": true, + "helpText": "Account Settings > Metadata API > Manage Access Tokens. Needs the \"Request History\" (read) scope." + }, + { + "label": "Workspace ID (optional)", + "type": "text", + "required": false, + "helpText": "Leave blank to auto-detect all workspaces, or enter a specific numeric workspace ID." + } + ] + } + }, + "capabilities": [ + "checks" + ], + "supportsMultipleConnections": false, + "syncSupported": false, + "checks": [ + { + "slug": "xano_monitoring_alerting", + "name": "Monitoring & Alerting", + "description": "Verifies Xano is logging API request activity (and audit events) via the Metadata API request history.", + "defaultSeverity": "medium", + "enabled": true + } + ], + "checkCount": 1, + "isActive": true +}