Intégrations & API
Intégrations
Intégrer et automatiser
Integrate and automate
Ostorlab integrates with 10 CI/CD tools (plus App Center, which Microsoft retired), three ticketing systems, Slack, Vanta and four SAML identity providers. It also offers a GraphQL API, an MCP server and a command line for your own automation.
The MCP server and every CI guide except App Center need an Ostorlab API key. The GraphQL API accepts an API key or a user token. App Center uses an App Center API token instead. See API keys and GraphQL API .
CI/CD
To learn how a CI scan works, see Scan in your CI/CD pipeline . For the command options, see CI scan options .
Tool
How you connect
Page
GitHub
The Ostorlab GitHub Action. An optional GitHub App comments on pull requests.
GitHub
GitLab
The ostorlab/gitlab-ci image, configured with environment variables.
GitLab
Jenkins
The Ostorlab plugin, as a freestyle build step or a pipeline step.
Jenkins
Azure DevOps
The Ostorlab extension from the Azure DevOps Marketplace.
Azure DevOps
CircleCI
The Ostorlab orb.
CircleCI
Bitbucket
A script step that installs and runs the CLI.
Bitbucket
GoCD
A command line task that runs the CLI.
GoCD
TeamCity
A command line step that runs the CLI in the ostorlab/oxo:latest container.
TeamCity
Bitrise
A script step that installs and runs the CLI.
Bitrise
Harness
A run step that installs and runs the CLI.
Harness
App Center (retired by Microsoft)
A webhook, set up from a configuration you create in Ostorlab. It needs no pipeline script.
App Center
Microsoft retired Visual Studio App Center on 31 March 2025. See the Microsoft retirement notice . The App Center guide stays for existing configurations.
Source code providers
Tool
Use it to
Page
GitHub, GitLab, Bitbucket, Azure DevOps, Self-Hosted Git
Connect your source code provider so that your repositories are available when you create a source code scan.
Source Code Scanning
Ticketing
The Jira and Linear pages state that the organisation must have an enterprise subscription.
Tool
Use it to
Page
Jira
Manage vulnerabilities with Ostorlab tickets and sync them with Jira, one way or two ways.
Jira
Linear
Manage vulnerabilities with Ostorlab tickets and sync them with Linear, one way or two ways.
Linear
ServiceNow
Configure authentication and ticket synchronization between Ostorlab and ServiceNow.
ServiceNow
Chat and compliance
Tool
Use it to
Page
Slack
Send Ostorlab notifications to your Slack workspace.
Slack
Vanta
Push vulnerability findings from Ostorlab to Vanta's vulnerability tracking system.
Vanta
Single sign-on
Tool
Use it to
Page
SAML 2.0
Enable centralized single sign-on, so members of your organisation sign in with their work email.
Single sign-on (SAML)
Azure Active Directory
Configure Azure Active Directory as a SAML SSO identity provider for Ostorlab.
SAML with Azure Active Directory
Google Workspace
Configure Google Workspace as a SAML SSO identity provider for Ostorlab.
SAML with Google Workspace
Okta
Configure Okta as a SAML SSO identity provider for Ostorlab.
SAML with Okta
OneLogin
Configure OneLogin as a SAML SSO identity provider for Ostorlab.
SAML with OneLogin
API and MCP
Tool
Use it to
Page
GraphQL API
Create scans, follow their progress and list vulnerabilities from scripts or the GraphiQL sandbox.
GraphQL API
MCP server
Let AI assistants and agent frameworks work with your scans, vulnerabilities, tickets and assets directly.
MCP server
API keys
Create and manage the keys that the API, the MCP server and every CI guide except App Center use to authenticate.
API keys
Command line
Choose by situation
I want to
Open
Fail a build when the scan risk rating is above a threshold
The guide for your CI tool, such as GitHub or GitLab , and CI scan options
Open tickets in Jira or Linear
Jira or Linear
Get scan comments on a pull request
GitHub , section on the Ostorlab Security Scanner GitHub App
Send notifications to a Slack channel
Slack
Let members sign in with their work email
Single sign-on (SAML)
Create scans from a script
GraphQL API
Ask an AI assistant about my scans
MCP server