Integrate and automate
Ostorlab integrates with 10 CI/CD tools (plus App Center, which Microsoft retired), three ticketing systems, Slack, Vanta and four SAML identity providers. It also offers a GraphQL API, an MCP server and a command line for your own automation.
The MCP server and every CI guide except App Center need an Ostorlab API key. The GraphQL API accepts an API key or a user token. App Center uses an App Center API token instead. See API keys and GraphQL API.
CI/CD
To learn how a CI scan works, see Scan in your CI/CD pipeline. For the command options, see CI scan options.
| Tool |
How you connect |
Page |
| GitHub |
The Ostorlab GitHub Action. An optional GitHub App comments on pull requests. |
GitHub |
| GitLab |
The ostorlab/gitlab-ci image, configured with environment variables. |
GitLab |
| Jenkins |
The Ostorlab plugin, as a freestyle build step or a pipeline step. |
Jenkins |
| Azure DevOps |
The Ostorlab extension from the Azure DevOps Marketplace. |
Azure DevOps |
| CircleCI |
The Ostorlab orb. |
CircleCI |
| Bitbucket |
A script step that installs and runs the CLI. |
Bitbucket |
| GoCD |
A command line task that runs the CLI. |
GoCD |
| TeamCity |
A command line step that runs the CLI in the ostorlab/oxo:latest container. |
TeamCity |
| Bitrise |
A script step that installs and runs the CLI. |
Bitrise |
| Harness |
A run step that installs and runs the CLI. |
Harness |
| App Center (retired by Microsoft) |
A webhook, set up from a configuration you create in Ostorlab. It needs no pipeline script. |
App Center |
Microsoft retired Visual Studio App Center on 31 March 2025. See the Microsoft retirement notice. The App Center guide stays for existing configurations.
Source code providers
| Tool |
Use it to |
Page |
| GitHub, GitLab, Bitbucket, Azure DevOps, Self-Hosted Git |
Connect your source code provider so that your repositories are available when you create a source code scan. |
Source Code Scanning |
Ticketing
The Jira and Linear pages state that the organisation must have an enterprise subscription.
| Tool |
Use it to |
Page |
| Jira |
Manage vulnerabilities with Ostorlab tickets and sync them with Jira, one way or two ways. |
Jira |
| Linear |
Manage vulnerabilities with Ostorlab tickets and sync them with Linear, one way or two ways. |
Linear |
| ServiceNow |
Configure authentication and ticket synchronization between Ostorlab and ServiceNow. |
ServiceNow |
Chat and compliance
| Tool |
Use it to |
Page |
| Slack |
Send Ostorlab notifications to your Slack workspace. |
Slack |
| Vanta |
Push vulnerability findings from Ostorlab to Vanta's vulnerability tracking system. |
Vanta |
Single sign-on
| Tool |
Use it to |
Page |
| SAML 2.0 |
Enable centralized single sign-on, so members of your organisation sign in with their work email. |
Single sign-on (SAML) |
| Azure Active Directory |
Configure Azure Active Directory as a SAML SSO identity provider for Ostorlab. |
SAML with Azure Active Directory |
| Google Workspace |
Configure Google Workspace as a SAML SSO identity provider for Ostorlab. |
SAML with Google Workspace |
| Okta |
Configure Okta as a SAML SSO identity provider for Ostorlab. |
SAML with Okta |
| OneLogin |
Configure OneLogin as a SAML SSO identity provider for Ostorlab. |
SAML with OneLogin |
API and MCP
| Tool |
Use it to |
Page |
| GraphQL API |
Create scans, follow their progress and list vulnerabilities from scripts or the GraphiQL sandbox. |
GraphQL API |
| MCP server |
Let AI assistants and agent frameworks work with your scans, vulnerabilities, tickets and assets directly. |
MCP server |
| API keys |
Create and manage the keys that the API, the MCP server and every CI guide except App Center use to authenticate. |
API keys |
Command line
Choose by situation
| I want to |
Open |
| Fail a build when the scan risk rating is above a threshold |
The guide for your CI tool, such as GitHub or GitLab, and CI scan options |
| Open tickets in Jira or Linear |
Jira or Linear |
| Get scan comments on a pull request |
GitHub, section on the Ostorlab Security Scanner GitHub App |
| Send notifications to a Slack channel |
Slack |
| Let members sign in with their work email |
Single sign-on (SAML) |
| Create scans from a script |
GraphQL API |
| Ask an AI assistant about my scans |
MCP server |