Skip to main content

Snyk

Integrate Snyk with Cloudaware to inventory organizations, projects, and application security findings for AppSec reporting.

info
  • Audience: Cloudaware administrators, AppSec teams, vulnerability management teams, and cloud operations teams
  • Outcome: Snyk organizations and projects are available in CMDB for application security visibility, vulnerability context, and reporting

Capabilities

The integration supports:

  • Read-only discovery of Snyk organizations and projects
  • AppSec context in CMDB for Snyk-managed projects and related findings
  • Reporting for application security posture across Snyk organizations and projects
  • Search and reporting for Snyk objects using CMDB Navigator, CMDB list views, and reports

Prerequisites

Before you begin, make sure you have:

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
  • Snyk Enterprise plan.
  • Snyk API key with read access to organizations, projects, and issues.

Add a Snyk Account to Cloudaware

  1. In Cloudaware, go to Admin.
  2. Find Snyk, then click + ADD.
  3. Enter the following values:
    • Name: A display name for the Snyk integration.
    • API Token: The Snyk API token with read access.
  4. Click Save.
  5. Confirm that the integration status indicator is green.
tip

Allow the initial discovery cycle to complete after enabling the integration.

View Snyk Data in CMDB

  1. In Cloudaware, open CMDB Navigator.
  2. In the left pane, select SNYK.
  3. Open an object list, e.g., Snyk Organizations or Snyk Projects, to view discovered records.

Supported Objects

Cloudaware ingests the following Snyk objects:

Snyk ObjectCMDB Object API Name
Snyk AccountCA10SK__CaSnykAccount__c
Snyk OrganizationCA10SK__CaSnykOrganization__c
Snyk ProjectCA10SK__CaSnykProject__c

Troubleshooting

note

Initial data collection may take time to complete.

Authentication Fails or Integration Shows Red Status

  • Verify that the Snyk API token is correct and active.
  • Confirm that the API token belongs to a Snyk user or service account with read access to the expected organizations.
  • Re-enter the API token by editing the integration in Cloudaware.

No Snyk Data Appears in CMDB

  • Allow the initial discovery cycle to complete.
  • Confirm that the Snyk API token can access the organizations and projects expected to appear in Cloudaware.
  • In CMDB Navigator, verify that you are viewing the SNYK section and related resources.

Some Projects or Findings Are Missing

  • Confirm that the projects are visible to the Snyk API token.
  • Check whether the projects belong to organizations outside the API token scope.
  • Review recent changes after the next discovery cycle completes.

Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.

Reconfigure or Remove the Integration

warning

To rotate the Snyk API token, edit the existing integration instead of deleting and re-creating it.

Update the Integration Details

  1. Go to Admin.
  2. Select Snyk.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Edit.
  5. Update the required fields.
  6. Click Save.

Remove the Integration from Cloudaware

  1. Go to Admin.
  2. Select Snyk.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Delete.
  5. Confirm the deletion if prompted.

Security Notes

  • Use a dedicated Snyk API token for Cloudaware discovery where possible.
  • Grant the API token only the read access required for organizations, projects, and issues that Cloudaware must discover.
  • Do not reuse personal administrator tokens for production integrations.
  • Rotate the Snyk API token according to your organization's credential management policy.
  • Review Snyk project and issue visibility with your AppSec team, because project names, repository references, and vulnerability context may contain sensitive application details.
  • Remove or revoke unused API tokens when the integration is retired.