Connect Snyk
Use this guide to import Snyk application-security findings into Cracken.
Prerequisites
- Permission to create a Snyk organization service account
- Access to every Snyk organization and project that Cracken should read
- A Cracken realm where you can configure data integrations
Prepare the credential and URL
Create an organization service account and select:
- Org Admin role
- API Key (no expiry) authentication
The current connector requires this legacy credential even though Cracken only reads findings. The key does not expire automatically and its Org Admin access is broader than the action Cracken exposes. Use a dedicated service account, limit it to the intended organization and projects, rotate the key on your organization's credential schedule, and revoke it immediately when you disconnect the integration or suspect exposure. Do not reuse a personal account or key. If your security policy does not permit a non-expiring administrator key, do not connect Snyk until a bounded authentication method is available.
Enter the API key as API Token. Leave Base URL empty for the default US service. For US-2
or EU, enter the regional application URL, such as https://app.us.snyk.io or
https://app.eu.snyk.io.
Connect Snyk
- Open Integration Center → Data Integrations.
- On the Snyk card, click Install.
- Enter the API Token and, when required, the Base URL.
- Click Test Connection, then Save & Connect.
Cracken can list Snyk findings and filter them by severity and state.
Sources
Next steps
- Data Integrations — Review how connected security data flows into Cracken.
- Cybergraph — See how Cracken uses imported application data.