# Aikido Docs Overview

### Getting Started <a href="#getting-started" id="getting-started"></a>

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="https://help.aikido.dev/getting-started/setting-up-your-account"><strong>Account Creation &#x26; User Management</strong></a></td><td>Set up your account, user, team and application management</td><td></td><td><a href="/pages/Gb7eg7fqpUA7qY9gpn1q">/pages/Gb7eg7fqpUA7qY9gpn1q</a></td></tr><tr><td><a href="/pages/g15AXRqR7ftFVZ86FBmU"><strong>Manage Findings</strong></a></td><td>Manage and triage your security findings</td><td></td><td><a href="/pages/g15AXRqR7ftFVZ86FBmU">/pages/g15AXRqR7ftFVZ86FBmU</a></td></tr><tr><td><a href="/pages/TIU1O3nlC2dIgJ4aRUdq"><strong>Task Management Tools</strong></a></td><td>Learn how to integrate your task management tool</td><td></td><td><a href="/pages/TIU1O3nlC2dIgJ4aRUdq">/pages/TIU1O3nlC2dIgJ4aRUdq</a></td></tr><tr><td><a href="/pages/PsRIWr0geeS4NbCiivmm"><strong>Chat &#x26; Alerts</strong></a></td><td>Connect your Slack or MS Teams for instant alerts</td><td></td><td><a href="/pages/PsRIWr0geeS4NbCiivmm">/pages/PsRIWr0geeS4NbCiivmm</a></td></tr></tbody></table>

### Scanning Capabilities <a href="#getting-started" id="getting-started"></a>

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/nZXi5tgsAMpaccG0uZp8"><strong>Code Scanning</strong></a></td><td>Learn how to connect your source code &#x26; scanning best practices.</td><td></td><td><a href="/pages/nZXi5tgsAMpaccG0uZp8">/pages/nZXi5tgsAMpaccG0uZp8</a></td></tr><tr><td><a href="/pages/67pDJzI7D0ak7pklPyOf"><strong>Cloud Scanning</strong></a></td><td>Connect your cloud to scan for misconfigurations and security risks.</td><td></td><td><a href="/pages/67pDJzI7D0ak7pklPyOf">/pages/67pDJzI7D0ak7pklPyOf</a></td></tr><tr><td><a href="/pages/ntCfpWnqFGT0BuD94Eob"><strong>Container Image Scanning</strong></a></td><td>Learn how to connect &#x26; configure your Container Registries.</td><td></td><td><a href="/pages/ntCfpWnqFGT0BuD94Eob">/pages/ntCfpWnqFGT0BuD94Eob</a></td></tr><tr><td><a href="/pages/EDIqXkgmKzg936l1mnPB"><strong>Virtual Machine Scanning</strong></a></td><td>Learn how to connect your Virtual Machines for scanning.</td><td></td><td><a href="/pages/EDIqXkgmKzg936l1mnPB">/pages/EDIqXkgmKzg936l1mnPB</a></td></tr><tr><td><a href="/pages/bjqSXrNOK0lM2UYsX1JG"><strong>Surface Monitoring</strong></a></td><td>Learn how to connect your Domain, API &#x26; Web App for scanning</td><td></td><td><a href="/pages/bjqSXrNOK0lM2UYsX1JG">/pages/bjqSXrNOK0lM2UYsX1JG</a></td></tr><tr><td><a href="/pages/BirkjcYrkwVsAK0cD3VW"><strong>Pentests</strong></a></td><td>Learn how to setup continuous, automated penetration testing</td><td></td><td></td></tr></tbody></table>

### Developer Integrations <a href="#getting-started" id="getting-started"></a>

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/ws69BODt75XfH7PjsLlF"><strong>PR &#x26; Release Gating</strong></a></td><td>Learn how to set up pull request &#x26; feature branch scanning.</td><td></td><td><a href="/pages/ws69BODt75XfH7PjsLlF">/pages/ws69BODt75XfH7PjsLlF</a></td></tr><tr><td><a href="/pages/sDg9tHlqk1pddw2iDl1U"><strong>Aikido AutoFix</strong></a></td><td>Learn how to create PRs that fix vulnerabilities with one click.</td><td></td><td><a href="/pages/sDg9tHlqk1pddw2iDl1U">/pages/sDg9tHlqk1pddw2iDl1U</a></td></tr><tr><td><a href="/pages/Na2kqayLA9FrP32sxw7L"><strong>AI &#x26; Dev Tools</strong></a></td><td>Use our plugins to scan and auto-remediate vulnerabilities while coding.</td><td></td><td><a href="/pages/TtCgRvpjJR8sPsXdszal">/pages/TtCgRvpjJR8sPsXdszal</a></td></tr><tr><td><a href="/pages/rNt5HIvN1L8hhNGkOUWA"><strong>Code Quality</strong></a></td><td>Learn how to maintain high standards across your codebase</td><td></td><td></td></tr></tbody></table>

### Device and Runtime Protection

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/KCwAzA4Nn1WCONWjhlRY"><strong>Zen Firewall</strong></a></td><td>Your in-app firewall for peace of mind–at runtime</td><td></td><td><a href="/pages/KCwAzA4Nn1WCONWjhlRY">/pages/KCwAzA4Nn1WCONWjhlRY</a></td></tr><tr><td><a href="/pages/TjYafodozYrDquTxY6Hb"><strong>Device Protection</strong></a></td><td>Block malware from your company devices plus manage package and extension policies.</td><td></td><td></td></tr></tbody></table>

### Compliance & Governance

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/eSFSsN8E544KltOI07va"><strong>ISO 27001 &#x26; SOC 2 Compliance</strong></a></td><td>Learn how to connect Aikido Security with your compliance software.</td><td></td><td><a href="/pages/eSFSsN8E544KltOI07va">/pages/eSFSsN8E544KltOI07va</a></td></tr></tbody></table>


# Setting Up Your Account


# Aikido Never Stores Your Code

{% hint style="success" %}
In short: Aikido does not store your code after analysis has taken place. Some of the analysis jobs such as SAST or Secrets Detection require a git clone operation. Below we talk about the technical measures we take to ensure your code is protected:
{% endhint %}

* We perform different actions such as git clones in a fresh docker container for each repository. After analysis, the data is wiped and the docker container is terminated.
* For GitHub, no refresh or access tokens are ever stored in our database. We use the new GitHub Apps which do not require this. Even a database breach of Aikido itself would not result in your GitHub code being downloadable.
* By default, our integrations require a very minimal read-only scope. Only if you enable special features such as Autofix Pull Requests, Aikido will request write accesses.
* If you want to keep your code completely on-premise, without ever leaving your environment, you can use our [Local Scanner](https://help.aikido.dev/category/aikido-local-scan-setup/sg4xF4OsJciW). The results will seamlessly populate on the Aikido platform.
* Aikido has SOC2 Type 2 & ISO27001:2022 certification. A report is available [upon request](http://trustcenter.aikido.dev/). That means we adhere to several organizational and technical policies by default.
* Aikido's servers are located in AWS, with data stored in-region for EU, US, AU and ME. Meaning customer data is stored for [app.aikido.dev](http://app.aikido.dev) in the EU region, for [app.us.aikido.dev](http://app.us.aikido.dev) in the US region, for [app.me.aikido.dev](http://app.me.aikido.dev) in the ME region and for [app.au.aikido.dev](http://app.au.aikido.dev) in the AU region.

The process we use to ensure code security:

![Secure repository scanning workflow: select, clone, scan, encrypt findings, destroy containers.](/files/5UmpQF2rNPVmNmnSUxfo)

**Disclaimer.**

Aikido has some features where certain parts of your code are stored. This is in the case for the following functionalities:

* AutoFix: Aikido stores the diffs (original and AutoFixed code) - only files that are part of the AutoFix
* Aikido stores the calltree for each AutoTriaged SAST finding for up to 2 weeks

All code that is stored is ran through Gitleaks. If there are any obvious secrets in the code, we make sure to definitely not store these.


# Connect Your Repositories

## Introduction <a href="#introduction" id="introduction"></a>

Welcome to Aikido, where we prioritize the security of your software without compromising on your data's privacy. At Aikido, we stand firm on our commitment: **we never store your code**.

As soon as you have done account setup and connected repositories, Aikido will instantly start a scan. Results will start coming in **within 1 minute. By connecting your repositories, you will already be benefiting from six different security scans** (SCA, SAST, Secrets, Licenses, IaC, Malware)**.**

You can set up an Aikido account through your version control system, whether you use GitHub, GitLab, Bitbucket, Azure DevOps, or an on-premise solution.

## Detailed Integration Guides <a href="#detailed-integration-guides" id="detailed-integration-guides"></a>

For more specific instructions for account setup, please check out the dedicated articles below:

* [Connect your GitHub Account to Aikido](/code-scanning/connect-your-source-code/connect-github-account-to-aikido)
* [Connect your Bitbucket Account to Aikido](/code-scanning/connect-your-source-code/connect-bitbucket-account-to-aikido)
* [Connect your GitLab Account to Aikido](/code-scanning/connect-your-source-code/connect-gitlab-account-to-aikido)
* [Connect your Azure Devops Account to Aikido](/code-scanning/connect-your-source-code/connect-azure-devops-projects-to-aikido)
* [Connect your Azure Devops Self-Managed Server to Aikido](/code-scanning/connect-your-source-code/connect-azure-devops-self-managed-server)
* [Connect your GitLab Self-Managed Server to Aikido](/code-scanning/connect-your-source-code/connect-gitlab-self-managed-server-to-aikido)
* [Setup Local Scanner Account if you don't want code to leave your premise](/code-scanning/local-code-scanning/account-creation-for-local-scanning-on-aikido)

These guides provide detailed steps and considerations for a smooth and secure integration process tailored to your needs.


# Account Setup with Multiple Gits

If you have repositories with multiple Git Providers (such as GitHub and GitLab) and you want to quickly access them, this is possible by setting up multiple workspaces that are connected to those specific Gits.

## Step-by-Step Guide <a href="#step-by-step-guide" id="step-by-step-guide"></a>

**Step 1:** Add a new workspace by clicking your profile icon in the top right corner.

![](/files/d1xH51UFEmTYiy0tS71Y)

**Step 2:** Click "Logout" on the top right if you need to connect to a different Git provider. If it is the same Git provider, continue by selecting "Add a New Workspace."

![](/files/QUHrjcFFZJLKiK5HbZlf)

> This screen can look slightly different when you are connected via Azure, GitLab Self Managed or Local Scanner.

**Step 3:** Choose the preferred Git Provider on the login screen.

![Login options for GitHub, Bitbucket, and GitLab displayed as prominent buttons.](/files/FpJvZdp8Op6tpPQwh9DK)

**Step 4:** After setting up the new account, merge both accounts. [Click here for more information](/getting-started/setting-up-your-account/link-and-merge-multiple-login-types-github-gitlab-etc) on how to set this up.

**Step 5:** Switch between different Git accounts using the workspace switcher located in the top left corner.

![GitHub dashboard showing repository selection and vulnerability summary chart.](/files/KUmuItI3qm223yaOqhhI)


# Merge Multiple Login Types

### Introduction <a href="#introduction" id="introduction"></a>

If you have multiple organizations across different source code managers (e.g. GitHub and GitLab), you can link these different login types which allows for easily swapping between organizations using the org-switcher at the **top left of the screen**. This allows you to not always having to go through the login hassle when you are changing login types.

{% hint style="info" %}
**Note.** this will not result in having all issues in 1 feed. All issues across workspaces is currently not supported
{% endhint %}

## How to Link Accounts <a href="#how-to-link-accounts" id="how-to-link-accounts"></a>

**Prerequisite:**

* Functionality needs to be enabled. ​**To enable, please contact our support over chat or via** [**support@aikido.dev**](mailto:support@aikido.dev)**.**
* Email needs to be the same across accounts

**Steps to link**

1. Open your [personal profile ](https://app.aikido.dev/my-profile)via the top right corner and select 'Link A Secondary User' in the Personal Profile Section.
2. Select your accounts to link (add links for account 1 and account 2). Make sure these accounts use the same email address. If you are using Azure DevOps, select Microsoft or Google Login (depending on the account you have used).

   ![Link two accounts for seamless integration and easy switching between platforms.](/files/pxSh0xxIsedlReb6BlQO)
3. Click 'Link Accounts'.\
   ​

   ![Link GitHub and GitLab accounts for seamless integration and easy switching.](/files/e5CENo9YlYWYf0RY9k10)
4. Log in with any of the linked accounts and you'll find the organizations of both users in the organization dropdown.\
   ​

   ![Workspace menu for Aikido Security with options to manage team and settings.](/files/Pu7gsvKqUCdMCCX5Bu16)

### How to link 3 or more accounts <a href="#how-to-link-3-or-more-accounts" id="how-to-link-3-or-more-accounts"></a>

It is possible to link more than 2 accounts, which is a bit more complex to set up. All workspaces will need to be linked to each other, in order to have all workspaces in the sidebar visible at all times.

**Example.**

If you have already linked a GitLab and a Bitbucket workspace, and you want to add a third GitHub workspace you will need to

* Link the GitLab and GitHub workspaces
* Link the Bitbucket and GitHub workspaces

In order to link these, visit the merge logins screen directly via [this link](https://app.aikido.dev/merge-logins).


# Change Email for Notifications

## Introduction <a href="#introduction" id="introduction"></a>

You can change your email address for receiving notifications (e.g., new issues and weekly digest). This change does not impact your authentication method.

## How To Change Your Email <a href="#how-to-change-your-email" id="how-to-change-your-email"></a>

**Step 1:** Navigate to [**Your Profile**](https://app.aikido.dev/my-profile) via the top right corner of the Aikido interface.

![User profile dropdown menu with options to view profile, add workspace, or log out.](/files/l1TtKIPIS1weTIoDBd0x)

**Step 2:** In the **email notification settings**, click the **edit icon** (next to the email).

![Notification email settings displaying the registered email address for alerts.](/files/kreoOV9JGElLIQJKRgQb)

**Step 3:** **Enter your new email address** in the provided field within the modal.

![Edit notification email address for receiving Aikido security alerts.](/files/vgqVBrthhbLHaUHOGBv0)

**Step 4:** After entering your new email, **a verification email will be sent** to the new address. Follow the instructions within this email to confirm the change.

![Email verification prompt for notification updates on the Aikido platform.](/files/T85AbHfMdbKdc3xpAszN)


# Running a Successful Pilot with Aikido

A pilot should answer two questions fast:

1. Does Aikido fit your environment and workflows?
2. Does Aikido improve signal, coverage, and speed for your team?

Most pilots run for 1 to 2 weeks. The goal is not to configure everything. The goal is to validate the parts that matter for your team.

### Suggested pilot plan

1. **Align on scope and success criteria.** Decide which teams, assets, and workflows you want to evaluate. Pick a clear owner for the pilot and a short list of must-have outcomes.
2. **Create your workspace and connect your first repositories.** Start by [creating your workspace](https://app.aikido.dev/login). Then follow [Connect Your Repositories](/getting-started/setting-up-your-account/create-account-and-connect-your-repositories). If data handling is part of your review, also read [Aikido Never Stores Your Code](/getting-started/setting-up-your-account/aikido-never-stores-your-code).
3. **Validate the core product coverage.** Cover the main scanners and workflows you expect to use in production. Start with the core checklist below.
4. **Invite the right stakeholders.** Add security, platform, and developer leads early. Use [User Management](/getting-started/automated-user-management) to get the right people into the workspace.
5. **Review results against your buying criteria.** Measure setup time, issue quality, workflow fit, and expected ROI. Use the evaluation section below as a starting point.

{% hint style="info" %}
Need more time before the pilot starts? Your workspace can fall back to the free plan until you are ready. Your setup stays in place.
{% endhint %}

### Core coverage to validate

These are the most common areas to validate during a pilot:

1. **Code scanning.** Start with [Code Scanning Overview](/code-scanning/code-scanning-overview) and connect your main repositories first.
2. **Cloud scanning.** Review [Cloud Scanning Overview](/cloud-scanning/cloud-scanning-overview) if cloud posture management is in scope.
3. **Containers and virtual machines.** Validate [Container Image Scanning Overview](/container-image-scanning/container-image-scanning-overview) and/or [VM Scanning Overview](/virtual-machine-scanning/virtual-machines-overview) based on your runtime footprint.
4. **DAST and attack surface.** Review [DAST Overview](/dast-surface-monitoring/dast-surface-monitoring-overview) if you want live validation on apps or APIs.
5. **Task tracking and ownership.** Connect your workflows through [Task Management Tools](/getting-started/task-management-systems).
6. **Team access.** Make sure findings reach the right teams through [Inviting Users to Aikido](/getting-started/automated-user-management/inviting-users-to-aikido).

### Optional pilot tracks

If you want broader validation, add one or more of these tracks:

1. **Attack visibility and exploit paths.** Review [Reachability Analysis](/getting-started/reachability-analysis/introduction-to-reachability-analysis), [Attack Surface Monitoring](/dast-surface-monitoring/attack-surface-scanning), and [Threat Model](/pentests/coverage-and-findings/threat-model).
2. **Developer workflow coverage.** Test [IDE Plugins](/ai-and-dev-tools/ide-plugins-overview), [AI Coding Assistants (MCP)](/ai-and-dev-tools/aikido-mcp), and [PR Gating](/pr-and-release-gating/aikido-ci-gating-functionality).
3. **Malware and package protection.** Evaluate [Safe Chain](/code-scanning/aikido-malware-scanning), [Malware Detection in Open-Source Dependencies and Containers](/code-scanning/scanning-practices/malware-detection-in-open-source-dependencies), and [Aikido Device Protection](/aikido-device-protection/endpoint-protection).
4. **Advanced validation.** Run [Code Audit](/ai-code-analysis/ai-code-audit-overview) if you want deeper code-level reasoning. Run [Aikido Pentest](/pentests/aikido-pentest) if you want live target testing.
5. **Private and self-hosted environments.** If you scan internal apps or self-managed systems, review [Aikido Broker for Internal Applications](/miscellaneous-info/aikido-broker-for-internal-applications).
6. **Credit-based features.** If you plan to test credit-backed workflows, review [Wallet & Credits](/miscellaneous-info/wallet-and-credits) before you start.

### Suggested evaluation criteria

Use these questions to structure your pilot review:

#### Time to value

* How long did first setup take?
* How quickly did useful findings appear?
* Did onboarding feel clear for admins and developers?

#### Signal quality

* Did the findings feel relevant?
* Did noise reduction improve focus compared to other tools?
* Did prioritization help the team decide what to fix first?

#### Workflow fit

* Does Aikido fit your Git, CI, ticketing, and chat workflows?
* Can the right teams see and act on findings?
* Do the integrations support how your teams already work?

#### Breadth and depth

* Does Aikido cover the assets you care about most?
* Are the product areas deep enough for your requirements?
* Do advanced workflows like IDE scanning, PR gating, Code Audit, or Pentest add value for your team?

#### Buying confidence

* Does the product replace enough tools or manual work to justify the spend?
* Can you show expected ROI through better coverage, faster remediation, or less noise?
* Does the support model give your team confidence?

### Getting help during the pilot

You can work with the Aikido team in three ways:

1. **In-app chat.** Best for fast setup and troubleshooting questions.
2. **Slack or Microsoft Teams.** Good for shared pilot communication with your team.
3. **Documentation.** Use the docs to go deeper on setup, product behavior, and troubleshooting.


# Limit Aikido Access to Specific IPs

IP restrictions let you limit access to your Aikido workspace so only users connecting from trusted IP addresses can use the dashboard. This adds a network-level control on top of your existing login method.

## Why use IP restrictions?

* ✨ Reduce risk from stolen credentials: leaked passwords or tokens are useless if the attacker can't connect from an approved network
* 🛡️ Enforce access from known locations such as your office network or VPN egress
* 🚦 Meet compliance requirements that call for IP-based access controls

## Who can configure IP restrictions?

Only **workspace admins** can view and manage IP restrictions. Non-admin users are blocked from the settings page and API.

## Set up IP restrictions

{% stepper %}
{% step %}

### Open IP restrictions

Go to [**IP Restrictions**](https://app.aikido.dev/settings/advanced/ip-locks) in your workspace settings. Use direct link to access.
{% endstep %}

{% step %}

### Add trusted IP addresses

Click **"Add IP restriction"** and enter one or more IPv4 addresses or CIDR ranges.

* Use a single IP (for example, `203.0.113.45`) for individual machines or VPN egress points
* Use a CIDR range (for example, `203.0.113.0/24`) to allow an entire subnet; netmasks must be between `/24` and `/32`

Click **"Save"** to apply the allowlist.
{% endstep %}

{% step %}

### Verify your current IP is included

Aikido automatically adds your current IP address when you save. This prevents you from locking yourself out of the workspace.

Your current IP is shown with a **"Current IP"** badge in the list. You can't remove your own IP while you're logged in.
{% endstep %}
{% endstepper %}

## How it works

When at least one IP address is on the allowlist, Aikido enables IP restrictions for your workspace. Any user connecting from an IP that isn't on the list sees a **403 Forbidden** error: *"Your IP is not allowed to access this workspace."*

**Disabling IP restrictions:** Remove all IP addresses from the allowlist. When you remove the last entry, IP restrictions are turned off automatically and all users can access the workspace again (subject to their normal login permissions).

**CIDR ranges:** When you add a CIDR range, Aikido expands it into individual IPv4 addresses behind the scenes. For example, `10.0.0.0/24` adds all 256 addresses in that subnet.

## What stays accessible

IP restrictions apply to workspace access through the Aikido dashboard and authenticated API calls. Aikido keeps the following integrations working so your scans, CI checks, and alerts aren't disrupted:

* CI/CD webhooks and check integrations (GitHub, GitLab, Bitbucket, Azure DevOps)
* Jira and Microsoft Teams integrations
* Aikido's background scanning and data-fetch services
* Zen Firewall runtime public API

Aikido Support can still access your workspace when providing support via impersonation.

## Supported formats

| Format       | Example         | Notes                               |
| ------------ | --------------- | ----------------------------------- |
| IPv4 address | `192.168.1.100` | Single trusted IP                   |
| CIDR range   | `10.0.0.0/24`   | Netmask must be `/24` through `/32` |
| IPv6         | Not applicable  | Not supported                       |

## Tips

{% hint style="warning" %}
Before enabling IP restrictions, make sure every team member can reach Aikido from an allowed network. Users on home networks or traveling without VPN access will be blocked.
{% endhint %}

{% hint style="info" %}
IP restrictions for Aikido are separate from IP allowlisting on your Git provider. If you also restrict access to GitHub, GitLab, or another SCM, see [IP Allowlisting for Your Git Provider](/miscellaneous-info/ip-allowlisting-for-your-git-provider).
{% endhint %}


# User Management


# Inviting Users to Aikido

Aikido offers two primary methods for inviting users to your workspace: inviting users who are part of your Github organization/ Gitlab group/ Bitbucket workspace and inviting users who do not have access to an organizational Git account.

![Login option menu: Only organizational GitHub login is currently selected.](/files/i19foOQEM8z74Guxt3PP)

### Option 1. Inviting Users That Are Part of Your Organization / Group <a href="#inviting-users-that-are-part-of-your-organization" id="inviting-users-that-are-part-of-your-organization"></a>

{% hint style="success" %}
This functionality is recommended as this allows for hassle-free automatic on- and offboarding of all your users.
{% endhint %}

By connecting to your organization’s Git provider (GitHub, GitLab, Bitbucket), Aikido ensures a streamlined on- and off-boarding process. This integration simplifies the management of user access and roles, ensuring that as users join or leave your Git organization, their access to Aikido is automatically adjusted.

{% hint style="info" %}
**Note.** For GitHub these are members part of the **organisation**. For Gitlab these are members of a **group**. For Bitbucket, these are members of a **workspace**.
{% endhint %}

**Choose the below login method in Aikido 👇**

![](/files/2kfaFeL2ayVan43DVv6H)

***

### Option 2. Inviting Users That Do Not Have Access to an Organization Git Account <a href="#inviting-users-that-do-not-have-access-to-an-organization-git-account" id="inviting-users-that-do-not-have-access-to-an-organization-git-account"></a>

{% hint style="info" %}
Automated off-boarding is **not available** for this option. You need to manually manage your users and deactivate them once access should be revoked.
{% endhint %}

This is especially useful for adding billing personnel, users with personal GitHub accounts, freelancers, and auditors requiring temporary access. Read the full article on how to [Invite Users to Aikido Without a Git Account](/getting-started/automated-user-management/invite-users-to-aikido-without-a-git-account).

**Choose the below login method in Aikido 👇**

![](/files/xTya0R7YzqFGDOirvvTW)

***

### More info on authentication & automated user management <a href="#more-info-on-authentication--automated-user-management" id="more-info-on-authentication--automated-user-management"></a>

* [GitHub Integration](/getting-started/automated-user-management/automated-user-management/github-integration-for-authentication-and-user-management)
* [GitLab Cloud Integration](/getting-started/automated-user-management/automated-user-management/gitlab-integration-for-authentication-and-user-management)
* [GitLab Self-Managed Integration](/getting-started/automated-user-management/automated-user-management/gitlab-self-managed-integration-for-authentication-and-user-management)
* [BitBucket Cloud Integration](/getting-started/automated-user-management/automated-user-management/bitbucket-cloud-integration-for-authentication-and-user-management)


# Invite Users to Aikido Without a Git Account

Aikido provides flexible options for inviting users who do not have a GitHub/BitBucket/GitLab account or prefer using alternative login methods such as Google, Microsoft, or a personal GitHub/BitBucket/GitLab account.

## Use Cases <a href="#use-cases" id="use-cases"></a>

* **Billing Personnel**: Users responsible for billing who do not have a Git account.
* **Personal GitHub Account Users**: Users with a personal GitHub account not affiliated with the organization.
* **Freelancers**: Contractors needing partial or temporary access.
* **Auditors**: External auditors requiring temporary access.
* **BitBucket users with limited-access to repos:** Users that only have limited access to a certain repos in BitBucket.
* **Multiple Git systems:** when users need to be invited to multiple workspaces of different Git systems (combo Github and Gitlab).

## Steps to Invite Users <a href="#steps-to-invite-users" id="steps-to-invite-users"></a>

**Step 1**: Navigate to the [Users Section](https://app.aikido.dev/settings/users) in Settings. Click **'Add'** to open the user invite dialogue

**Step 2**: Enter one or multiple **email address**. The email needs to be a company email.

![](/files/SjB0md8sEk1IDg9lX9P7)

**Step 3.** Choose the **second Login Method** - Users can log in via GitHub/Bitbucket/GitLab, Google or Microsoft.

![](/files/dKCgz7wsEJLKeLTgzudN)

**Step 4.** Ensure that the invited user clicks the button in the email redirecting to Aikido and then using its email that was used during invite for Google/Microsoft.

### Important Notes <a href="#important-notes" id="important-notes"></a>

* **Manual Offboarding**: Users invited via these methods **will not** be automatically offboarded. It is important to manually remove users who no longer require access to the Aikido platform to maintain security and manage access appropriately.


# Setting Roles and Permissions

## Roles and Permissions Logic <a href="#roles-and-permissions-logic" id="roles-and-permissions-logic"></a>

Aikido offers three distinct user roles (**admins**, **default** and **team-only** users) to manage access and permissions effectively. Default and team-only users can have **standard editing rights** or can be **read-only**.

| Role                | Access Level                                                 |
| ------------------- | ------------------------------------------------------------ |
| **Admins**          | Full access                                                  |
| **Default Users**   | <p>Global / All Teams</p><p>Standard rights or read-only</p> |
| **Team-Only Users** | <p>Team-specific</p><p>Standard rights or read-only</p>      |

### Default Users vs Team-Only Users <a href="#default-users-vs-team-only-users" id="default-users-vs-team-only-users"></a>

The main difference between the two is that team-only users only have access to those issues for the teams they belong to. They still are able to mostly manage issues.

| Permission                                                                           | Default Users | Team-Only Users                                       |
| ------------------------------------------------------------------------------------ | ------------- | ----------------------------------------------------- |
| <p><strong>Issue Actions</strong></p><p>Snooze, ignore, severity change, autofix</p> | ✅             | ✅                                                     |
| **Create Tasks**                                                                     | ✅             | ✅                                                     |
| **Add Repos**                                                                        | ✅             | ❌                                                     |
| **Add Container Registries**                                                         | ✅             | ❌                                                     |
| **Add Domains**                                                                      | ✅             | Connected to repos only. No standalone.               |
| **Export Issues**                                                                    | ✅             | ❌                                                     |
| **Pentests**                                                                         | ✅             | ❌                                                     |
| **Code Quality**                                                                     | ✅             | ❌                                                     |
| **Zen Firewall**                                                                     | ✅             | ❌                                                     |
| **Acces to Settings**                                                                | All settings  | General Settings **Only**                             |
| **Acces to Reports**                                                                 | All Reports   | Trends Over Time, Licenses & SBOM and Malware Monitor |

### Advanced Rights for Users with Standard Rights <a href="#advanced-rights-for-users-with-standard-rights" id="advanced-rights-for-users-with-standard-rights"></a>

Aikido has an extra layer of permissions that can be enabled or disabled (both for default and team-only users). This is helpful in case you still want users to be able to execute certain actions. **Read-only rights block all possible actions.**

**Configurable for Default and Team-Only**

* **Snooze/Ignore Issues**: Ability to temporarily or permanently dismiss issues. When [ignore requests are enabled](/getting-started/core-functionalities/approval-inbox-for-ignored-issues#enabling-ignore-requests), users without ignore permissions can request to ignore individual issues via the [approval inbox](/getting-started/core-functionalities/approval-inbox-for-ignored-issues). Snooze is not affected.
* **Change Issue Severity**: Ability to modify the severity level of issues.
* **Can export data:** Ability to export csv reports of vulnerability issues.

**Limited to Default Users**

* **Manage Teams**: Ability to manage team settings and membership.
* **Manage Repositories:** Ability to change branch, set multi-branch scanning and manage custom SAST rules.
* **Manage Clouds:** Ability to add and configure clouds
* **Manage Containers:** Ability to add and configure containers
* **Manage Domains:** Ability to add and configure domains
* **Manage Pentests:** Ability to run and configure pentests
* **Manage Code Quality Rules:** Ability to add and configure Code Quality Rules & manage code context
* **Manage Device Protection:** Ability to add devies and configure rules

## How to change roles and permissions <a href="#how-to-change-roles-and-permissions" id="how-to-change-roles-and-permissions"></a>

**Step 1.** Go to the user overview in your settings

**Step 2.** Click the triple dots to open up the role and permissions modal for a specific user

<div data-with-frame="true"><img src="/files/xAIrtytTcFhfJO0Yrkxc" alt="" width="375"></div>

**Step 3.** Set the preferred user role and permissions

<div data-full-width="false" data-with-frame="true"><figure><img src="/files/w4SKjPgaZSfC88JM0W9b" alt="" width="375"><figcaption></figcaption></figure></div>

## FAQ

Why am I seeing the error "You cannot change the role of a more senior admin"?

* This means the admin you're trying to modify joined the Aikido workspace before you and has a higher privilege level. To change their role, contact Aikido Support via the in-app chat to request an elevation of your admin permissions.


# Automated User Management


# Configure Team Sync Settings

Team sync controls how Aikido imports teams and members from your source control manager (GitHub, Bitbucket, or Azure DevOps), and whether repositories are automatically linked to those teams.

{% hint style="info" %}
This is an admin-only setting. Only workspace **admins** can change the team sync mode.
{% endhint %}

### **Different Sync Settings**

#### **Full team sync (default)**

Teams and members are imported from your SCM and kept up to date. Repositories are automatically linked to teams based on your SCM's team-to-repo mapping, so ownership and coverage mirror your SCM structure exactly.

**When to use:** Use this when you want your SCM to drive both group membership and repository ownership. This is the lowest-maintenance option.

#### **Team sync without automatic repo linking**

Teams and members are still imported and kept in sync from your SCM. Repositories are not linked automatically. You manage repo-team assignments directly in Aikido.

**When to use:** Use this when you want accurate team membership in Aikido but need to control repo-team assignments manually, for example when your SCM team structure does not reflect how you assign code ownership.

#### **Team sync off**

No teams are imported from your SCM going forward. Existing SCM-imported teams will be removed when you turn this off.

**When to use**: use this when you are not using SCM teams in Aikido at all, or when you are migrating to a different team management approach.

{% hint style="warning" %}
Turning off team sync removes teams that were created and maintained by the import process. Teams created manually in Aikido are not affected.
{% endhint %}

#### How to configure sync settings

**Step 1.** Go to [**settings > Teams**](https://app.test.aikido.dev/settings/teams) and click **Settings** in the Action menu

<figure><img src="/files/e9KagKBmKLM3XbsosQAk" alt=""><figcaption></figcaption></figure>

**Step 2.** Choose the preferred sync configuration and press save.

<figure><img src="/files/QlI1qrL6Hq3lXRVqtoOj" alt=""><figcaption></figcaption></figure>


# GitHub Integration: Authentication and User Management

## Introduction <a href="#introduction" id="introduction"></a>

Aikido ensures a one-to-one mapping with your GitHub organizations, including repositories, and teams. This streamlines the onboarding and offboarding processes within Aikido.

## Understanding Aikido's GitHub Integration <a href="#understanding-aikidos-github-integration" id="understanding-aikidos-github-integration"></a>

* **Automatic Onboarding**: Thanks to the one-to-one mapping with GitHub organizations, all GitHub org members can easily onboard themselves to Aikido workspaces. This eliminates the need for manual email invitations. As soon as a user is part of the GitHub org, they will be able to access the workspace directly.
* **Effortless Offboarding**: When a member is removed from your GitHub organization, they automatically lose access to the Aikido workspace.
* **Synchronization of Teams and Repositories**: Aikido replicates your GitHub team structure and repository access controls. If your GitHub setup involves managing repository access through team memberships, Aikido will automatically and instantly mirror this structure, ensuring access levels remain consistent across both platforms.
* **Instant Syncing**: Instant syncing for adding & removing members, changing teams, changing repos on a team. All changes done in GitHub will instantly be reflected in Aikido.
* **Limitations for Outside Collaborators**: It's important to note that only full members of your GitHub organization can join the Aikido workspace. This means outside collaborators, even though they may have access to your GitHub repositories, will not be granted access to Aikido, ensuring workspace access is limited to your core team. If you want to add these users, you can also invite them via Google/Microsoft (see below).

### Inviting users to Aikido without an organisational GitHub account <a href="#inviting-users-to-aikido-without-an-organisational-github-account" id="inviting-users-to-aikido-without-an-organisational-github-account"></a>

You can invite users via Gmail, Microsoft or using a personal GitHub Account. More information can be [found here.](/getting-started/automated-user-management/invite-users-to-aikido-without-a-git-account)


# Azure DevOps: Authentication and User Management

If your organization uses Azure DevOps, users can login with Google and Microsoft accounts. To allow auto-onboarding of users in your workspace: configure **Trusted Domains (see below for instructions)**

### Understanding Aikido's Azure DevOps Integration <a href="#understanding-aikidos-azure-devops-integration" id="understanding-aikidos-azure-devops-integration"></a>

* **Manual Onboarding:** invite users manually via email
* **Auto-onboard via Trusted Domains**: Users can automatically join the Azure DevOps workspace if their login email is part of a trusted domain that you can specify on workspace level. Aikido will verify this user has access to your Azure Devops organization. **Note:** the user needs to be a member on the organisation level in Azure, otherwise they will not be recognised during team sync.
* **Synchronization of Teams and Repositories:** Aikido replicates your Azure DevOps team and project structure. All users will have access to their repos, in line with the permissions set in Azure DevOps. By default, all users will have the **Team Only** role.

{% hint style="info" %}
If users, roles, or repository access change in Azure DevOps, Aikido syncs those updates automatically. Changes are synced nightly, or you can trigger a manual sync via the Teams page in settings.
{% endhint %}

### Onboarding of Users with Trusted Domains <a href="#onboarding-of-users-with-trusted-domains" id="onboarding-of-users-with-trusted-domains"></a>

{% hint style="info" %}
If you have multiple workspaces, you need to setup Trusted Domains in each workspace.
{% endhint %}

1. Go to [General Settings](https://app.aikido.dev/settings/account) in your workspace
2. In workspace info, click 'Add Trusted Domain'

   ![Azure DevOps Server: Update token and add trusted domains for security.](/files/5KvTbByiKDnPhlCpFTjm)
3. Fill in the trusted domain in the modal

   ![Add a trusted domain for Azure DevOps user auto-enrollment and verification.](/files/EEP9pDLtFbYbMyzT4obD)

{% hint style="info" %}
For security reasons, Aikido only allows you to add trusted domains that are the same as the current logged in user. This means that <user@aikido.dev> can only add [aikido.dev](http://aikido.dev) as trusted domain.
{% endhint %}

### Manually Inviting Users <a href="#manually-inviting-users" id="manually-inviting-users"></a>

**Manually invite via email**: You can invite users via the Aikido platform on the specified email, and the user will be able to access Aikido directly.


# Bitbucket Cloud Integration: Authentication and User Management

### Introduction <a href="#introduction" id="introduction"></a>

Aikido ensures a one-to-one mapping with this Bitbucket Workspace, including repositories and teams. This streamlines the onboarding and offboarding processes within Aikido.

If you have multiple Bitbucket workspaces, you can connect these by setting up multiple Aikido workspaces.

{% hint style="warning" %}
For automatic onboarding to work, developers need to have **access to all repos**. If you want to give access to a developer with limited access to repos in Bitbucket, we suggest inviting them [via Google/Microsoft](/getting-started/automated-user-management/invite-users-to-aikido-without-a-git-account).
{% endhint %}

### Benefits <a href="#benefits" id="benefits"></a>

* **Automatic Onboarding:** After initial connection with Bitbucket, all Bitbucket members of this group will be able to onboard Aikido automatically, on the condition they have access to **all repositories** in this Bitbucket workspace.
* **Effortless Offboarding:** Aikido will sync access every night and auto-offboard members that are no longer active in your Bitbucket Workspace. This means that when a member is removed from the Bitbucket Workspace, they automatically lose access to the Aikido Workspace too.
* **Synchronization of Teams:** Aikido replicates your Bitbucket team structure (i.e. User Groups in Bitbucket). Groups need to have access to repositories in order to connect responsibilities of repositories to the teams in Aikido.
* **Daily Syncing**: Currently, Aikido updates the team structures, repositories and access permissions on a daily basis.

### Inviting users to Aikido without an organisational Bitbucket account <a href="#inviting-users-to-aikido-without-an-organisational-bitbucket-account" id="inviting-users-to-aikido-without-an-organisational-bitbucket-account"></a>

You can invite users via Gmail, Microsoft or using a personal Bitbucket Account. This can be helpful when a developer only has limited access in Bitbucket. More information can be [found here.](/getting-started/automated-user-management/invite-users-to-aikido-without-a-git-account)


# GitLab Integration: Authentication and User Management

### Introduction <a href="#introduction" id="introduction"></a>

When you create an Aikido workspace based on GitLab Cloud version, you select a GitLab Group. The Aikido workspace will consist of the main group and all its subgroups and underlying repositories.

### Benefits <a href="#benefits" id="benefits"></a>

* **Automatic Onboarding:** From that point on, other GitLab members of this group will be able to onboard Aikido automatically. Note: this only on the condition that they have at the least 'reporter', 'developer', 'maintainer' or 'owner' level of access to this group. 'Guests' will not be able to get in.
* **Effortless Offboarding:** When a member is removed from your GitLab Instance, they automatically lose access to the Aikido workspace. Aikido will sync access every night and auto-offboard members that are no longer active in your GitLab instance.

### Adding multiple GitLab Groups in a single Aikido Workspace <a href="#adding-multiple-gitlab-groups-in-a-single-aikido-workspace" id="adding-multiple-gitlab-groups-in-a-single-aikido-workspace"></a>

By default, a new workspace will be created for every GitLab group. If you want to have multiple GitLab groups inside 1 Aikido workspace, you need to create a root-level group in GitLab that contains all the subgroups.

### Inviting users to Aikido without an organisational GitLab account <a href="#inviting-users-to-aikido-without-an-organisational-gitlab-account" id="inviting-users-to-aikido-without-an-organisational-gitlab-account"></a>

You can invite users via Google, Microsoft or using a personal GitLab Account. More information can be [found here.](/getting-started/automated-user-management/invite-users-to-aikido-without-a-git-account)


# GitLab Self-Managed Integration: Authentication and User Management

### Introduction <a href="#introduction" id="introduction"></a>

If your organization uses GitLab self-managed, it's not possible to authenticate via the Git provider. In those cases, we allow Gmail and Office365 logins.

### Onboarding of Users <a href="#onboarding-of-users" id="onboarding-of-users"></a>

**Manually invite via email (default)**: You can invite users via the Aikido platform on the specified email, and the user will be able to access Aikido directly.

***

**Auto-onboarding**: Aikido can check whether the email that is being used for login is available in the GitLab instance. This is based on adding trusted domains. **Contact us** to help in setting this up or go to your Workspace settings and click 'Add Trusted Domain'.

![](/files/LYkDrTGKrn89UJPRd6KT)

{% hint style="info" %}
**​Important notes on auto-onboarding**

* All users will need to have their 'public email' field exposed. Currently, GitLab does not allow yet to force this upon all users ([more info](https://gitlab.com/gitlab-org/gitlab/-/issues/9828)).
* The email used for login and the email in the 'public email' field need to be exactly the same. Aliases are currently not supported.
  {% endhint %}


# SAML Login


# SAML User Rights: Access Profiles (Recommended)

SAML Access Profiles allow you to define user access rights based on SAML attributes. You can manage these profiles in the app under:

**Settings > General > SAML Setup > Add SAML Profile**<https://app.aikido.dev/settings/account>

## Configuring SAML Access Profiles <a href="#configuring-saml-access-profiles" id="configuring-saml-access-profiles"></a>

When adding a new SAML Profile, you can define the following settings:

### 1. Profile Name <a href="#id-1-profile-name" id="id-1-profile-name"></a>

* The name that should be passed as the `aikido_access_profile` SAML claim.

### 2. Role <a href="#id-2-role" id="id-2-role"></a>

* Defines the user's role:
  * **Admin**
  * **Default**
  * **Team Only**

### 3. Edit Rights <a href="#id-3-edit-rights" id="id-3-edit-rights"></a>

* Determines the user's edit capabilities:
  * **Standard**
  * **Read Only**

### 4. Can Ignore <a href="#id-4-can-ignore" id="id-4-can-ignore"></a>

* Specifies whether the user can ignore issues:
  * **Yes**
  * **No**

### 5. Can Snooze <a href="#id-5-can-snooze" id="id-5-can-snooze"></a>

* Specifies whether the user can snooze issues:
  * **Yes**
  * **No**

### 6. Can Change Severity <a href="#id-6-can-change-severity" id="id-6-can-change-severity"></a>

* Defines if the user can change the severity of issues:
  * **Yes**
  * **No**

### 7. Can Export Data <a href="#id-7-can-manage-teams" id="id-7-can-manage-teams"></a>

* Defines if the user can export data:
  * **Yes**
  * **No**

### 8. Can Manage Teams <a href="#id-7-can-manage-teams" id="id-7-can-manage-teams"></a>

* Defines if the user can manage teams:
  * **Yes**
  * **No**

### 9. Can Manage Clouds <a href="#id-7-can-manage-teams" id="id-7-can-manage-teams"></a>

* Defines if the user can manage clouds:
  * **Yes**
  * **No**

### 9. Can Manage Containers <a href="#id-7-can-manage-teams" id="id-7-can-manage-teams"></a>

* Defines if the user can manage containers:
  * **Yes**
  * **No**

### 10. Can Manage Domains <a href="#id-7-can-manage-teams" id="id-7-can-manage-teams"></a>

* Defines if the user can manage domains:
  * **Yes**
  * **No**

### 11. Can Manage Pentests <a href="#id-7-can-manage-teams" id="id-7-can-manage-teams"></a>

* Defines if the user can manage pentests:
  * **Yes**
  * **No**

### 12. Can Manage Code Quality Rules <a href="#id-7-can-manage-teams" id="id-7-can-manage-teams"></a>

* Defines if the user can manage code quality rules:
  * **Yes**
  * **No**

### 13. Member of Teams <a href="#id-8-member-of-teams" id="id-8-member-of-teams"></a>

* A comma-separated list of team names the user belongs to.
* Matches the existing `aikido_teams` [SAML claim](/getting-started/automated-user-management/saml-login/saml-user-rights-using-custom-attributes-advanced).

### 14. Workspace IDs <a href="#id-9-workspace-ids" id="id-9-workspace-ids"></a>

* A comma-separated list of workspace IDs where the user has access.
* Matches the existing `aikido_workspace_ids` [SAML claim](/getting-started/automated-user-management/saml-login/saml-user-rights-using-custom-attributes-advanced).
* If left empty, the profile grants access to all workspaces linked to the SAML client.

## Using SAML Access Profiles <a href="#using-saml-access-profiles" id="using-saml-access-profiles"></a>

Once a profile is created, you can set up a custom SAML claim `aikido_access_profile` with the profile name as value. **If set**, users who authenticate via SAML will receive access based on the profile associated with this claim. Ensure that the correct claims are configured in your Identity Provider (IdP) to match the assigned profiles.

> **Note**
>
> When using the `aikido_access_profile` in combination with other [custom SAML claims](/getting-started/automated-user-management/saml-login/saml-user-rights-using-custom-attributes-advanced), those other claims will take precedence.


# SAML User Rights: Custom Attributes (Advanced)

> These are the advanced way of setting up user rights. We recommend using [SAML Access Profiles](/getting-started/automated-user-management/saml-login/saml-user-rights-access-profiles-recommended)
>
> [https://help.aikido.dev/doc/saml-user-rights-access-profiles-recommended/docVaVb0VPy1](/getting-started/automated-user-management/saml-login/saml-user-rights-access-profiles-recommended)

This guide provides detailed instructions on how to configure and manage user rights within Aikido using SAML custom attributes. By leveraging attributes such as `aikido_role`, `aikido_data_edit_rights`, `aikido_can_ignore`, `aikido_can_snooze`, `aikido_can_change_severity`, `aikido_can_manage_teams`, and `aikido_teams`, you can control user permissions and roles from within your identity provider. This approach ensures that users have the same access in Aikido as set up in your identity provider.

* **aikido\_access\_profile:** [**More info**](/getting-started/automated-user-management/saml-login/saml-user-rights-access-profiles-recommended)\
  When setting up SAML Access Profiles, this is the claim to use.

  ```xml
  <saml:Attribute Name="aikido_access_profile">
      <saml:AttributeValue xsi:type="xs:anyType">My Access Profile</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_username:** You can define the name of the user in Aikido

  ```xml
  <saml:Attribute Name="aikido_username">
      <saml:AttributeValue xsi:type="xs:anyType">John Doe</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_role:** `admin`, `default`, `team_only`

  ```xml
  <saml:Attribute Name="aikido_role">
      <saml:AttributeValue xsi:type="xs:anyType">default</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_data\_edit\_rights:** `standard`, `read_only`

  ```xml
  <saml:Attribute Name="aikido_data_edit_rights">
      <saml:AttributeValue xsi:type="xs:anyType">standard</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_can\_ignore:** `true`, `false`

  ```xml
  <saml:Attribute Name="aikido_can_ignore">
      <saml:AttributeValue xsi:type="xs:anyType">true</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_can\_snooze:** `true`, `false`

  ```xml
  <saml:Attribute Name="aikido_can_snooze">
      <saml:AttributeValue xsi:type="xs:anyType">true</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_can\_change\_severity:** `true`, `false`

  ```xml
  <saml:Attribute Name="aikido_can_change_severity">
      <saml:AttributeValue xsi:type="xs:anyType">true</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_can\_manage\_teams:** `true`, `false`

  ```xml
  <saml:Attribute Name="aikido_can_manage_teams">
      <saml:AttributeValue xsi:type="xs:anyType">true</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_can\_export\_data:** `true`, `false`

  ```xml
  <saml:Attribute Name="aikido_can_export_data">
      <saml:AttributeValue xsi:type="xs:anyType">true</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_can\_manage\_clouds:** `true`, `false`

  ```xml
  <saml:Attribute Name="aikido_can_manage_clouds">
      <saml:AttributeValue xsi:type="xs:anyType">true</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_can\_manage\_containers:** `true`, `false`

  ```xml
  <saml:Attribute Name="aikido_can_manage_containers">
      <saml:AttributeValue xsi:type="xs:anyType">true</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_can\_manage\_domains:** `true`, `false`

  ```xml
  <saml:Attribute Name="aikido_can_manage_domains">
      <saml:AttributeValue xsi:type="xs:anyType">true</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_can\_manage\_pentests:** `true`, `false`

  ```xml
  <saml:Attribute Name="aikido_can_manage_pentests">
      <saml:AttributeValue xsi:type="xs:anyType">true</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_can\_manage\_code\_quality:** `true`, `false`

  <pre class="language-xml"><code class="lang-xml">&#x3C;saml:Attribute Name="aikido_can_manage_code_quality">
  <strong>    &#x3C;saml:AttributeValue xsi:type="xs:anyType">true&#x3C;/saml:AttributeValue>
  </strong>&#x3C;/saml:Attribute>
  </code></pre>
* **aikido\_can\_manage\_repos:** `true`, `false`

  <pre class="language-xml"><code class="lang-xml">&#x3C;saml:Attribute Name="aikido_can_manage_repos">
  <strong>    &#x3C;saml:AttributeValue xsi:type="xs:anyType">true&#x3C;/saml:AttributeValue>
  </strong>&#x3C;/saml:Attribute>
  </code></pre>
* **aikido\_teams:** You can define the different teams where the user is a part of here. If the team(s) do not exist in Aikido, it will be created. The user will auto-join these given teams. The user will be removed from all other teams if this is set up.

  ```xml
  <saml:Attribute Name="aikido_teams">
      <saml:AttributeValue xsi:type="xs:anyType">team1</saml:AttributeValue>
      <saml:AttributeValue xsi:type="xs:anyType">team2</saml:AttributeValue>
  </saml:Attribute>
  ```
* **aikido\_workspace\_ids:** You can define the different Aikido workspaces where the user is a part of here. The user will auto-join these given workspaces. The user will be removed from all other workspaces if this field is set up.

  ```xml
  <saml:Attribute Name="aikido_workspace_ids">
      <saml:AttributeValue xsi:type="xs:anyType">1233</saml:AttributeValue>
      <saml:AttributeValue xsi:type="xs:anyType">2511</saml:AttributeValue>
  </saml:Attribute>
  ```
* **github\_samlidentity\_nameid:** (github specific) Team member sync based on SAML users currently only works if users also log into GitHub via SAML. By sending the `github_samlidentity_nameid` SAML claim containing the user’s email address, triggering team-sync will also sync the SAML team members.

  ```xml
  <saml:Attribute Name="github_samlidentity_nameid">
      <saml:AttributeValue xsi:type="xs:anyType">example@email.com</saml:AttributeValue>
  </saml:Attribute>
  ```
* **github\_user\_slug:** (github specific) Team member sync based on SAML users currently only works if users also log into GitHub via SAML. By sending the `github_user_slug` SAML claim containing the user’s github slug, triggering team-sync will also sync the SAML team members.

  ```xml
  <saml:Attribute Name="github_user_slug">
      <saml:AttributeValue xsi:type="xs:anyType"johndoe</saml:AttributeValue>
  </saml:Attribute>
  ```


# Okta: Login with SAML

{% hint style="info" %}
This feature is only available on a **paying** plan and is not enabled by default. If you’d like to enable this feature, please reach out via the chat in the bottom right corner within Aikido.
{% endhint %}

> If you switch to SAML Login instead of auto-onboarding via your Git provider, team import from GitHub, Bitbucket, or Azure DevOps will no longer work. You will need to manage your teams manually moving forward, either through the Aikido UI or [Access Profiles.](/getting-started/automated-user-management/saml-login/saml-user-rights-access-profiles-recommended)

## Setting up SAML in your account <a href="#setting-up-saml-in-your-account" id="setting-up-saml-in-your-account"></a>

**Step 1.** Go to [**General Settings**](https://app.aikido.dev/settings/account) and click '**Enable SAML Authentication'**

![Workspace info page showing option to enable SAML authentication for a GitHub account.](/files/aOiM25kER30KfCFw8LIE)

**Step 2.** Copy **all details** to your identity provider. See steps below.

![SAML Authentication setup screen with required URLs and Name ID format for configuration.](/files/RADWmUqgwIOaGrq8KiKA)

### Continue in Okta <a href="#continue-in-okta" id="continue-in-okta"></a>

**Step 1.** Go to **Applications** > **Applications** in the Admin Console.

**Step 2.** Click **Create App Integration**, select **SAML 2.0** and click **Next**.

**Step 3.** Choose an **App name** and click **Next**.

**Step 4.** Fill the fields **Single sign-on URL**, **Audience URI** and **Name ID format** with the fields visible in Aikido (see above) and click **Next**.

**Step 5.** Now you should be on the tab **Sign On** and you should see **Metadata details**. Click **More details**.

### Go back to Aikido <a href="#go-back-to-aikido" id="go-back-to-aikido"></a>

* Fill in the **Entity ID / Issuer**, **Single Sign-On URL** and **X.509 Certificate** as shown in Okta.
* Also fill out the **Company Domain** to make sure people can log in without the need of a Single Sign-On URL.

![Form for entering SAML authentication details for secure single sign-on setup.](/files/MmfaM4FoxViIVFil4Vf9)

> Success! People having access to your Okta SAML app will now be able to auto-onboard to your Aikido workspace.

### 2 options for users to login using your SAML client <a href="#id-2-options-for-users-to-login-using-your-saml-client" id="id-2-options-for-users-to-login-using-your-saml-client"></a>

**Option 1. Using SSO Link Directly**

Copy the Login Link and share this internally with other users.

![SAML Authentication settings with options to manage or copy the login link.](/files/xyz04nKTOkjhYRoEY2JV)

**Option 2.** Going to the Aikido login screen, selecting **Login Via SSO** and filling in the email address **Important**: the email needs to contain the company domain that has been set up.

![One-click free login and sign-up with Google, Microsoft, or SSO, with no card required.](/files/l4LiZQEdG4K8nwx4sY9F)

![Login screen with Google, Microsoft, and email authentication options.](/files/SJnoFWTkYSeLzTeyyO1F)


# JumpCloud: Login with SAML

{% hint style="info" %}
This feature is only available on a **paying** plan and is not enabled by default. If you’d like to enable this feature, please reach out via the chat in the bottom right corner within Aikido.
{% endhint %}

> If you switch to SAML Login instead of auto-onboarding via your Git provider, team import from GitHub, Bitbucket, or Azure DevOps will no longer work. You will need to manage your teams manually moving forward, either through the Aikido UI or [Access Profiles.](/getting-started/automated-user-management/saml-login/saml-user-rights-access-profiles-recommended)

## Setting up SAML in your account <a href="#setting-up-saml-in-your-account" id="setting-up-saml-in-your-account"></a>

**Step 1.** Go to [**General Settings**](https://app.aikido.dev/settings/account) and click '**Enable SAML Authentication'**

![Workspace info page with option to enable SAML authentication.](/files/aOiM25kER30KfCFw8LIE)

**Step 2.** Copy **all details** to your identity provider. See steps below.

![SAML authentication setup screen with required URLs and Name ID format.](/files/fFEyJIfsFEkVeMLbAZmi)

### Continue in JumpCloud <a href="#continue-in-jumpcloud" id="continue-in-jumpcloud"></a>

**Step 1.** Go to **User Authentication** > **SSO Applications** in the JumpCloud Admin Portal navigation.

**Step 2.** Click the **Add New Application** and search for **SAML 2.0**. Click **Next**.

**Step 3.** Choose a **Display Label** and click **Save Application**.

**Step 4.** Click **Configure Application**.

**Step 5.** Click on the **SSO** tab and fill following fields:

* **Idp Entity ID:** `https://console.jumpcloud.com/<appname>`
* **SP Entity ID:** `https://app.aikido.dev/saml`
* **ACS URLs** - **Default URL:** `https://app.aikido.dev/api/saml/saml_auth?samlClientId=...` (As shown in Aikido)
* **SAMLSubject NameID:** `email`
* **SAMLSubject NameID Format:** `urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress`
* **Signature Algorithm:** `RSA-SHA256`
* **Default RelayState:** You can leave this empty

![SAML 2.0 single sign-on configuration settings for secure identity management integration.](/files/g0lkKpR9O2Hvxmbp560z)

**Step 6.** We'll continue in Aikido, but you might as well click **Save** and come back to this screen.

### Go back to Aikido <a href="#go-back-to-aikido" id="go-back-to-aikido"></a>

* Fill in the:
  * **Entity ID / Issuer:** `https://console.jumpcloud.com/<appname>` (Make sure this matches what you've entered as **Idp Entity ID** in JumpCloud. If you're having issues with this, see the Troubleshooting section at the bottom)
  * **Single Sign-On URL:** as shown in JumpCloud under **IDP URL**. (looks like `https://sso.jumpcloud.com/saml2/<appname>`)
  * **X.509 Certificate**: This can be fetched in different ways. One way is to click **Export Metadata** in JumpCloud the config and open the downloaded xml. You'll find your certificate between the `ds:X509Certificate` tags.
* Also fill out the **Company Domain** to make sure people can log in without the need of a Single Sign-On URL.

![SAML Authentication setup form for configuring identity provider details.](/files/MmfaM4FoxViIVFil4Vf9)

> Success! People having access to your JumpCloud SAML app will now be able to auto-onboard to your Aikido workspace.

### 2 options for users to login using your SAML client <a href="#id-2-options-for-users-to-login-using-your-saml-client" id="id-2-options-for-users-to-login-using-your-saml-client"></a>

**Option 1. Using SSO Link Directly**

Copy the Login Link and share this internally with other users.

![SAML Authentication settings with options to manage or copy the login link.](/files/xyz04nKTOkjhYRoEY2JV)

**Option 2.** Going to the Aikido login screen, selecting **Login Via SSO** and filling in the email address **Important**: the email needs to contain the company domain that has been set up.

![One-click login and sign-up with Google, Microsoft, or SSO, with no credit card needed.](/files/l4LiZQEdG4K8nwx4sY9F)

![Login screen with Google, Microsoft, and email login options.](/files/SJnoFWTkYSeLzTeyyO1F)

### Troubleshooting <a href="#troubleshooting" id="troubleshooting"></a>

**Error**

![SAML client already exists error; prompts user to contact support for linking organization.](/files/2y9egRcKKLQSDMAswwV3)

**Solution**

Make sure the **Idp Entity ID** is unique. Perhaps you could change it to `https://console.jumpcloud.com/<samlClientId>`. Note that you'll also need to change it in Aikido in **Entity ID / Issuer** as these should match.


# Google Workspaces: Login with SAML

{% hint style="info" %}
This feature is only available on a **paying** plan and is not enabled by default. If you’d like to enable this feature, please reach out via the chat in the bottom right corner within Aikido.
{% endhint %}

> If you switch to SAML Login instead of auto-onboarding via your Git provider, team import from GitHub, Bitbucket, or Azure DevOps will no longer work. You will need to manage your teams manually moving forward, either through the Aikido UI or [Access Profiles.](/getting-started/automated-user-management/saml-login/saml-user-rights-access-profiles-recommended)

### Setting up SAML in your account <a href="#setting-up-saml-in-your-account" id="setting-up-saml-in-your-account"></a>

**Step 1.** Go to [**General Settings**](https://app.aikido.dev/settings/account) and click '**Enable SAML Authentication'**

![Workspace info page showing option to enable SAML authentication.](/files/aOiM25kER30KfCFw8LIE)

**Step 2.** Copy **all details** to your identity provider. See steps below.

![SAML Authentication setup screen with required URLs and Name ID format fields.](/files/fFEyJIfsFEkVeMLbAZmi)

### Continue in Google <a href="#continue-in-google" id="continue-in-google"></a>

**Step 1.** Go to **Apps** > **Web and mobile apps** in the Google Admin Console.

**Step 2.** Click the **Add app** dropdown and select **Add custom SAML app**.

**Step 3.** Choose an **App name** and click **Continue**.

**Step 4.** Ignore the metadata page for now, we'll get this information later on. Click **Continue**.

**Step 5.** Fill the fields **ACS URL**, **Entity ID** and **Name ID format** with the fields visible in Aikido (see above) and click **Continue** and click **Finish**.

**Step 6.** Now you should be on the detail page of your newly created app. Click **Download Metadata**.

### Go back to Aikido <a href="#go-back-to-aikido" id="go-back-to-aikido"></a>

* Fill in the **Entity ID / Issuer**, **Single Sign-On URL** and **X.509 Certificate** as shown in the modal in Google.
* Also fill out the **Company Domain** to make sure people can log in without the need of a Single Sign-On URL.

![SAML authentication setup form requiring identity provider and company domain details.](/files/MmfaM4FoxViIVFil4Vf9)

> Success! People having access to your Google SAML app will now be able to auto-onboard to your Aikido workspace.

### 2 options for users to login using your SAML client <a href="#id-2-options-for-users-to-login-using-your-saml-client" id="id-2-options-for-users-to-login-using-your-saml-client"></a>

**Option 1. Using SSO Link Directly**

Copy the Login Link and share this internally with other users.

![SAML Authentication settings with options to manage or copy the login link.](/files/xyz04nKTOkjhYRoEY2JV)

**Option 2.** Going to the Aikido login screen, selecting **Login Via SSO** and filling in the email address **Important**: the email needs to contain the company domain that has been set up.

![One-click login and sign-up with Google, Microsoft, or SSO, with no credit card needed.](/files/l4LiZQEdG4K8nwx4sY9F)

![Login options: Google, Microsoft, or email for account access.](/files/SJnoFWTkYSeLzTeyyO1F)


# Microsoft Azure: Login with SAML/ Entra ID

{% hint style="info" %}
This feature is only available on a **paying** plan and is not enabled by default. If you’d like to enable this feature, please reach out via the chat in the bottom right corner within Aikido.
{% endhint %}

> If you switch to SAML Login instead of auto-onboarding via your Git provider, team import from GitHub, Bitbucket, or Azure DevOps will no longer work. You will need to manage your teams manually moving forward, either through the Aikido UI or [Access Profiles.](/getting-started/automated-user-management/saml-login/saml-user-rights-access-profiles-recommended)

## Setting up SAML in your account <a href="#setting-up-saml-in-your-account" id="setting-up-saml-in-your-account"></a>

**Step 1.** Go to [**General Settings**](https://app.aikido.dev/settings/account) and click '**Enable SAML Authentication'**

![Workspace info screen with option to enable SAML authentication for GitHub account.](/files/aOiM25kER30KfCFw8LIE)

**Step 2.** Copy **all details** to your identity provider. See steps below.

![SAML Authentication setup screen showing required URLs and Name ID format for configuration.](/files/fFEyJIfsFEkVeMLbAZmi)

### Continue in Azure <a href="#continue-in-azure" id="continue-in-azure"></a>

**Step 1.** Go to **Microsoft Entra ID**.

**Step 2.** Click the **Add** dropdown and select **Enterprise application**.

![Adding a new enterprise application in Microsoft Azure Active Directory.](/files/BWtmvVYBJvvOKhySjNH5)

**Step 3.** Click **Create your own application**, choose a name for your app and select 'Non-gallery'.

![Creating a custom non-gallery application named "Aikido-SSO" for integration purposes.](/files/czSYhc2ZtKbE7MQgtS2m)

**Step 4.** Select **Set up single sign on**.

![Aikido-SSO application setup: Assign users and configure single sign-on in Microsoft Entra.](/files/9CzflR5V3JYv3RipfjD5)

**Step 5.** Click the **SAML** option.

![Enable SAML single sign-on for secure application authentication in Aikido-SSO.](/files/YNwdSsJxQ7LEdLzaCQPk)

**Step 6.** On **step 1**, click **Edit.**

![Basic SAML Configuration: Edit required Identifier and Reply URL fields.](/files/LznVLZwAf7mx0AEIsuwv)

**Step 7.** Fill in the **Entity ID** and **ACS URL** as shown in Aikido.

![Configuration screen for SAML SSO with Entity ID and Reply URL fields specified.](/files/P8HanoJmIxEjarvxEF9Z)

**Step 8.** At **step 2**, click **Edit.**

![User attributes and claims mapping with editable options highlighted.](/files/DWsWMe1uzAdDyg5e838y)

**Step 9.** Click the **Unique User Identifier (Name ID)**.\
Optional: clicking 'Add new claim' at the top of this page allows you to add [custom attributes](/getting-started/automated-user-management/saml-login/saml-user-rights-using-custom-attributes-advanced) to SAML. More info [here](https://help.aikido.dev/doc/microsoft-azure-custom-attributes-with-saml--entra-id/docFaysVwVZy).

![Highlighted SAML claim: Unique User Identifier (Name ID) for user identification.](/files/jey09FVr8MJgLGhDt4tN)

**Step 10.** Make sure to set **Source attribute** to `user.mail` here.

![Configuring a SAML claim for user email as the name identifier in Azure AD.](/files/HpcG4ZGUcJveZjAqgSss)

**Step 11.** At step 3 you can download the **Certificate (Base64)** & at step 4 you'll see the **Login URL** and **Mircosoft Entra Identifier**. These should be copy and pasted to Aikido.

### Go back to Aikido <a href="#go-back-to-aikido" id="go-back-to-aikido"></a>

* Fill in the **Entity ID / Issuer**, **Single Sign-On URL** and **X.509 Certificate** as shown in Azure.
* Also fill out the **Company Domain** to make sure people can log in without the need of a Single Sign-On URL.

![SAML Authentication setup form for configuring Single Sign-On (SSO) credentials.](/files/MmfaM4FoxViIVFil4Vf9)

> Success! People having access to your Azure SAML app will now be able to auto-onboard to your Aikido workspace.

### 2 options for users to login using your SAML client <a href="#id-2-options-for-users-to-login-using-your-saml-client" id="id-2-options-for-users-to-login-using-your-saml-client"></a>

**Option 1. Using SSO Link Directly**

Copy the Login Link and share this internally with other users.

![SAML Authentication settings with options to manage or copy the login link.](/files/xyz04nKTOkjhYRoEY2JV)

**Option 2.** Going to the Aikido login screen, selecting **Login Via SSO** and filling in the email address **Important**: the email needs to contain the company domain that has been set up.

![One-click login and sign-up with Google, Microsoft, or SSO; no credit card needed.](/files/l4LiZQEdG4K8nwx4sY9F)

![Login screen offering Google, Microsoft, or email sign-in options.](/files/SJnoFWTkYSeLzTeyyO1F)


# Microsoft Azure: Custom Attributes with SAML /Entra ID

First, make sure you have SAML login working using following guide:

[https://help.aikido.dev/doc/microsoft-azure-login-with-saml--entra-id/doc74BfKR60Z](/getting-started/automated-user-management/saml-login/microsoft-azure-login-with-saml-entra-id)

### Setting up Azure Group based SAML custom attributes <a href="#setting-up-azure-group-based-saml-custom-attributes" id="setting-up-azure-group-based-saml-custom-attributes"></a>

1. Go to the application registration

   ![Azure portal view for managing Aikido-SSO enterprise application properties and settings.](/files/oLgbDIr4AHurwdeTJi8I)
2. Create an app role.**value** here should be the value of the claim. In this example, we're setting up for `aikido_role`, so valid values for this are `admin`, `default`, `team_only`.

   ![Creating a new app role "Aikido Admin" in Microsoft Azure for Aikido-SSO.](/files/nsRfUHnJTamTtUswDeeQ)
3. After saving, go back to the app settings, and add a group to 'Users and Groups'

   ![Azure portal: Assign users or groups to the Aikido-SSO enterprise application.](/files/Xc9ZEJYE47sGgPvDie1g)
4. Add the Entra group you'd like to give admin access (in this case) and add the role we created in step 2.

   ![Azure Add Assignment: Select users, groups, and roles for directory permissions.](/files/ewPcde4ckLTi8kJ0L0CQ)
5. Back in the Single Sign-on settings of the app, go to the Attributes & Claims -> Edit

   ![Azure portal SAML-based single sign-on configuration for Aikido-SSO application.](/files/9FEc8XU5Oqe1VDl8VhON)
6. Click 'Add new claim'

   ![Azure portal Attributes & Claims page for adding and managing SAML claims.](/files/k7Aq5AEq7OYAQPeL4StC)
7. Fill in the attribute name & user.assignedroles as source attribute. (this is the `admin` value we set up in step 2)

   ![Azure claim setup: mapping "aikido\_role" to "user.assignedroles" attribute.](/files/1bBsAMTt8JtDmVMi1Ycx)
8. All done. On SAML login, these changes will take effect.


# Manage Teams & Applications


# Managing User Access with Teams

## Introduction <a href="#introduction" id="introduction"></a>

Aikido lets you create teams, connect multiple repositories and clouds, and manage access using RBAC (Role-Based Access Control) for better security. This article focuses on Managing of User Access. If you are looking to use Teams to group your resources into Projects or Apps, please [**click here**](/getting-started/manage-teams-and-applications/manage-and-view-your-apps-and-projects-via-our-teams-feature).

## Use Cases <a href="#use-cases" id="use-cases"></a>

* **Selective Access Control:** Assign repository access exclusively to designated team members.
* **Filter Repositories Quickly:** In companies with multiple teams, each team may have access to the entire codebase, but their primary responsibilities are often limited to specific repositories or projects. By creating teams in Aikido, team members **can have a focused overview** of only the repositories relevant to their tasks.\
  ​

  ![](/files/BdGmoRSER3anv9MCNa1o)
* **Better overview when using a monorepo split.** You can assign team members to specific directories of your monorepo, improving their overview. More information on splitting monorepositories can be found [here](https://help.aikido.dev/en/articles/9026666-splitting-up-your-monorepo-per-directory).

## How To Create Teams <a href="#how-to-create-teams" id="how-to-create-teams"></a>

**Step 1:** Navigate to **Settings -> Teams**\
​

![Team dashboard showing user "mdschuym" with 4 active repositories and 1 member.](/files/BGZIh4VA3IncHAbnq8Q3)

**Step 2:** Click **Create Team** and give your team a name

![](/files/YFNy0WIpUSrV3hUzsEgq)

**Step 3:** **Add team members** to the newly created team.

![User management interface showing available users and team assignment options.](/files/WE3lFnmc0JxKoPq75UCS)

**Step 4:** Define the **team's responsibilities** by adding **resources via the responsibility tab.** You can add different resources such as clouds, repositories, containers, domains and zen apps.

> If you want to link specific domains to a team, you can set this up by linking your domains to a repo or container. It will automatically inherit access permissions.

![](/files/xFXnb7tFMS35ilGyBUk6)

**Step 5.** Go back to your feed and filter on a specific team. You should only see issues that are related to those repositories and clouds that were attached to the team.

## Syncing with GitHub, Bitbucket or Azure DevOps <a href="#syncing-with-github-bitbucket-or-azure-devops" id="syncing-with-github-bitbucket-or-azure-devops"></a>

If you have **existing teams** set up in GitHub, Bitbucket or Azure DevOps, Aikido will import them and maintain synchronization on a nightly basis. This ensures that any changes in team structures or access rights managed in GitHub/Bitbucket are accurately reflected in Aikido. Any new teams that are created in GitHub will appear in Aikido. The same applies to when you remove a team in GitHub: Aikido will pick this up and remove the team too. Any repos that are part of the team, will be synced too.

{% hint style="info" %}
It's important to note that in this scenario, GitHub/Bitbucket/Azure DevOps acts as the source of truth for access rights, and all management should be conducted within those platforms. This also means that **no extra users can be added to scm-linked teams** inside Aikid&#x6F;**.**
{% endhint %}

Aikido makes it clear which teams have been imported from your SCM.

![Team roles and users overview with DevOps group imported from GitHub.](/files/rNfQ8bITEgU1iPyLkB02)

## Syncing with Backstage.io <a href="#syncing-with-backstageio" id="syncing-with-backstageio"></a>

Aikido integrates seamlessly with repositories containing `catalog-info.yaml` files for [Backstage.io](https://backstage.io). This allows for the automatic importing of teams, taking into account the path of where the file is located.

{% hint style="info" %}
Please note: This feature needs to be enabled by Aikido manually. Please reach out to support to enable this.
{% endhint %}

#### How It Works <a href="#how-it-works" id="how-it-works"></a>

1. Aikido scans repositories for `catalog-info.yaml` files.
2. Aikido looks for the `spec->owner` field in the file and imports this as team.
3. Aikido records the exact path of each `catalog-info.yaml` file, ensuring the team is responsible for those specific paths (and repositories).

## Syncing with Port.io <a href="#syncing-with-portio" id="syncing-with-portio"></a>

Aikido integrates seamlessly with repositories containing `port.yaml` files for [Port.io](https://port.io). This allows for the automatic importing of teams, taking into account the path of where the file is located.

#### How It Works <a href="#how-it-works" id="how-it-works"></a>

1. Aikido scans repositories for `port.yaml` files.
2. Aikido looks for the `team` field in the file and imports this as team.
3. Aikido records the exact path of each `port.yaml` file, ensuring the team is responsible for those specific paths (and repositories).

## How to select your team in UI <a href="#how-to-select-your-team-in-ui" id="how-to-select-your-team-in-ui"></a>

**Aikido's Feed** features a **team filter** at the top of the page. This filter allows users to tailor the feed to display only the issues relevant to selected teams. This filter can be used on basically every page in Aikido (feed, reports, settings etc).

![](/files/l3uw6Nf4oGDCgutTvn9D)


# Assigning Resources to Teams

Assigning resources to teams defines ownership inside Aikido. It ensures that findings are routed to the right people, dashboards stay relevant, and teams only see what they are responsible for.

This page explains all available ways to assign resources, including individual and bulk options.

### Assign from the Team Page

1. Go to [Settings → Teams](https://app.aikido.dev/settings/teams)
2. Select a team
3. Open the Responsibility tab

   <figure><img src="/files/m3FI2k6C1Uq46ZehztFp" alt=""><figcaption></figcaption></figure>
4. Click "Link Resource"
5. Select resource type, and search and add resources<br>

   <figure><img src="/files/4xruBNG6KqS9959FaLLt" alt="" width="563"><figcaption></figcaption></figure>

### Assign from the Resource Page

You can also assign a team while viewing the resource itself.

#### Repositories

Open a Repository → Configure → Teams responsible

<figure><img src="/files/7OyVQF0jjh3850OsMkJk" alt=""><figcaption></figcaption></figure>

#### Cloud Accounts

Open a Cloud Connection → Configure → Teams responsible

<figure><img src="/files/EeXaWwLkFzHVd7JV83li" alt=""><figcaption></figcaption></figure>

### Domains & API's

Open the Front-end, REST, or GraphQL scan configuration from the Settings page (or the action menu in the list view) and link the domain to an asset.

You can link it to either a repository or a container. Once linked, the scan inherits the team permissions from that asset.

<figure><img src="/files/rCMlnjOTSd04RHesZlra" alt=""><figcaption></figcaption></figure>

### Bulk Assignment

Bulk actions are available on resource list pages in [settings](https://app.aikido.dev/settings/account).

{% hint style="info" %}
If bulk actions are not visible, assignment must be done individually.
{% endhint %}

**Repositories**

[Settings → Repositories](https://app.aikido.dev/settings/integrations/repositories) → Select multiple → Bulk Actions → Assign to team

<figure><img src="/files/zgUUALxbba5KVMjcnJ72" alt=""><figcaption></figcaption></figure>

**Containers**

[Settings → Containers](https://app.aikido.dev/settings/container-image-registry) → Select multiple → Bulk Actions → Assign to team

<figure><img src="/files/JlHs9GrAzMngYnLGn0Va" alt=""><figcaption></figcaption></figure>

**Cloud**

[Settings -> Clouds](https://app.aikido.dev/settings/integrations/clouds) -> Select multiple -> Bulk Actions -> Assign to team

<figure><img src="/files/84gAnJZpBXgf0zGe9tKd" alt=""><figcaption></figcaption></figure>


# Add labels to resources

Labels are custom metadata you add to repositories and container images in Aikido. Use them to group resources on different metadata properties.

Examples include `payments`, `production`, `frontend`, `lambda` , `critical`, `PII` etc.

{% hint style="info" %}
Labels are not the same as a container's **Scanned tag**. The scanned tag controls which image version Aikido scans. Labels only help you organize resources and filter issues.
{% endhint %}

### Manage labels on a repository

1. Open **Repositories** and select a repository.
2. Open the **Settings** tab.
3. In the **Labels** card, click **Edit**.

<figure><img src="/files/B3D4bQF26Umm2BfXirdm" alt="" width="375"><figcaption></figcaption></figure>

Each repository can have multiple labels. Labels are free-form text.

You need permission to manage repositories. Team-restricted users can only edit labels on repositories they can access.

#### Import repository labels from GitHub

For GitHub repositories, Aikido can import GitHub topics as labels. These synced labels are read-only in Aikido. They stay in sync with GitHub topics automatically. You can still add manual labels next to them. **Contact us to enable this functionality.**

### Manage labels on a container

1. Open **Containers** and select a container image.
2. Open the **Settings** tab.

You need permission to manage containers. Team-restricted users can only edit labels on containers they can access.

#### Automatic labels from workloads

If your Kubernetes or cloud workload integration is connected, Aikido can promote workload labels onto the container.

Today this supports `owner` and `team`. Aikido formats them as `owner:<value>` and `team:<value>`.

These labels are managed by the integration. You can't edit or delete them manually. Manual labels stay separate and remain editable.

### Filter the issue feed by labels

1. Open the main **Issues** feed.
2. Open **Quick filter**.
3. Select the labels you want to keep.

The **Labels** filter only appears after at least one label exists in your workspace. In some versions, this filter appears as **Repo Labels**.

<figure><img src="/files/vIUe3sidnPb6UVqBNFbD" alt="" width="364"><figcaption></figcaption></figure>


# Manage and View Your Apps and Projects via Our Teams Feature

## Introduction <a href="#introduction" id="introduction"></a>

Aikido lets you create teams, connect multiple repositories and clouds to have a clear overview of your apps and projects. This project/app view is available throughout the entire Aikido app, going from feed, alerting and reporting. This article focuses on using Teams in order to group resources into Project and Apps. Managing of User Access. If you are looking to manage User Access with teams, please [**click here**](/getting-started/manage-teams-and-applications/managing-user-access-with-teams).

## Use Cases <a href="#use-cases" id="use-cases"></a>

* **Agency Project Management:** Agencies frequently handle multiple clients, necessitating a structured approach to manage each client's repositories separately. Aikido facilitates this by allowing the creation of teams for each client, making it straightforward to organize and access client-specific repositories. Additionally, this allows for easy generation of client-specific reports.

  ![Dropdown menu for selecting "All teams" or individual client teams.](/files/1lDmmJuT59N9OFnQduT9)
* **Specify resources connect to an app:** you can use the team functionality to combine resources that are part of the same app (combination of repos, containers and clouds). This also allows you to view all reports
* **Better overview when using a monorepo split.** You can assign team members to specific directories of your monorepo, improving their overview. More information on splitting monorepositories can be found [here](https://help.aikido.dev/en/articles/9026666-splitting-up-your-monorepo-per-directory).

{% hint style="info" %}
Repo linking is only available for manually created teams (not imported from SCM). Other resources like containers, clouds & Zen apps can be linked to both manually created and SCM-imported teams.
{% endhint %}

## How To Create Teams <a href="#how-to-create-teams" id="how-to-create-teams"></a>

**Step 1:** Navigate to **Settings -> Teams**\
​

![Team dashboard for “mdschuym” showing 4 active repositories and management options.](/files/BGZIh4VA3IncHAbnq8Q3)

**Step 2:** Click **Create Team** and give your team a name\
​

![Form to create a new team by entering a team name for vulnerability tracking.](/files/YFNy0WIpUSrV3hUzsEgq)

**Step 3 (optional):** **Add team members** to the newly created team.

![User management interface for assigning people to the "Architects" team.](/files/WE3lFnmc0JxKoPq75UCS)

**Step 4:** **Link different resources** via the **responsibility tab.** You can add different resources such as repositories, clouds, containers, domains and zen apps. You can add repositories and containers **in bulk** via the [repository](https://app.aikido.dev/settings/integrations/repositories) and [container settings](https://app.aikido.dev/settings/container-image-registry) screen.

> If you want to link specific domains to a team, you can set this up by linking your domains to a repo or container. It will automatically inherit access permissions.

![Interface for linking repositories, cloud, or container resources to the Backend team.](/files/xFXnb7tFMS35ilGyBUk6)

**Step 5.** Go back to your feed and filter on a specific team. You should only see issues that are related to those repositories and clouds that were attached to the team.

## How to select your team in UI <a href="#how-to-select-your-team-in-ui" id="how-to-select-your-team-in-ui"></a>

**Aikido's Feed** features a **team filter** at the top of the page. This filter allows users to tailor the feed to display only the issues relevant to selected teams. This filter can be used on basically every page in Aikido (feed, reports, settings etc).

![Team filter dropdown with stats for solved and newly detected issues this week.](/files/l3uw6Nf4oGDCgutTvn9D)


# Assign Team Responsibilities by Specific Path in Repo

Assigning **specific repo paths** to teams in Aikido can help to streamline issue management in **large monorepos** and enabling **more granular reporting**.

### Use Cases <a href="#use-cases" id="use-cases"></a>

* **Monorepo management:** Assign specific paths to teams instead of the full monorepo. This allows you to filter your feed in a more granular way.
* **Specific reporting:** Allows reports to be generated based on service-level/path-level rather than at the repo level.

### Assigning Specific Paths <a href="#assigning-specific-paths" id="assigning-specific-paths"></a>

**Step 1:** Create a Team and Link Repositories (see [article](/getting-started/manage-teams-and-applications/managing-user-access-with-teams))

* Create a new team or select an existing one, then link the relevant repositories to this team.

**Step 2:** Click Limit Access By Path in the dropdown menu

![](/files/IoWQnHNWKnZ945BUrr0p)

**Step 3:** Enter the paths within the repo that you want the team to have access to.

![](/files/t6BUuHbTS9HFnhpRMN5G)

**Wildcard support**

`**` means anything in any subdirectory\
`*` means anything in the current directory\
`?` means any single char

**Step 4:** Filter Issues in Feed/Reports

Go to the **Feed** or **Reports** section. Apply a filter based on the team, and you will see only the issues related to the paths assigned to that team.

![Dashboard showing security findings, severity levels, and issue statuses for the "devs" team workspace.](/files/t2SPdLWOMyYM7rsIULcP)


# Assign Team Responsibilities with Gitlab Topics

Aikido allows you to use **Gitlab Project Topics** to automatically manage team assignments in Aikido. This streamlines issue management in large organizations and enables more granular reporting without manual setup.

### Use Cases <a href="#use-cases" id="use-cases"></a>

* **Clear ownership across many repos**: In large orgs, each repo has a defined owning team, making it easier to track who is responsible.
* **Automatic onboarding**: When new repos are created with the right topic, they’re instantly assigned to the correct team in Aikido.

### Configuration <a href="#assigning-specific-paths" id="assigning-specific-paths"></a>

{% hint style="warning" %}
This feature is **not enabled by default** and needs to be activated for your account. Please contact **Aikido support** for assistance.
{% endhint %}

For each repository you want managed by Aikido:

1. In GitLab, [go to your repository’s Settings → General → Topics](https://docs.gitlab.com/user/project/project_topics/).
2. Add a topic like: `owner:Internal Tooling Team`.
3. Aikido will automatically create (or update) the team and assign the repo.
4. If the topic is removed or changed later, Aikido will unassign or reassign the repo automatically.


# Assign Team Responsibilities with Code Owners

Aikido allows you to use **Code Owners** to automatically manage team assignments in Aikido. This streamlines issue management in large organizations and enables more granular reporting without manual setup.

{% hint style="info" %}
Code Owners is independent from source code manager. It can easily be used with GitHub, Gitlab, Bitbucket and even our Local Scanning workspaces.
{% endhint %}

### Use Cases <a href="#use-cases" id="use-cases"></a>

* **Clear ownership across many repos**: In large orgs, each repo has a defined owning team, making it easier to track who is responsible.
* **Path-level ownership:** For codebases where multiple teams own different directories or paths (e.g. monorepos), Aikido maps CODEOWNERS paths directly to teams, no manual assignment needed.
* **Automatic onboarding**: When new repos are created with the right topic, they’re instantly assigned to the correct team in Aikido.

### Configuration <a href="#assigning-specific-paths" id="assigning-specific-paths"></a>

{% hint style="warning" %}
This feature is **not enabled by default** and needs to be activated for your account. Please contact **Aikido support** for assistance.
{% endhint %}

1. In Github/Gitlab/Bitbucket, create a new file called `CODEOWNERS.` See [GitHub docs](https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners), [Gitlab docs](https://docs.gitlab.com/user/project/codeowners/) and [Bitbucket docs](https://support.atlassian.com/bitbucket-cloud/docs/set-up-and-use-code-owners/). Aikido assumes there is only 1 codeowner file and will use the first one it finds.
2. Aikido will automatically create (or update) the team and assign the repo.
3. If the Codeowners file is changed later, Aikido will unassign or reassign the repo automatically.


# Bitbucket Cloud: Assigning Repositories to Teams via Projects

### Introduction

In Bitbucket, repositories can be linked to a project, and that project can be linked to a team. Aikido now supports automatically linking those repositories to the team their Bitbucket project belongs to.

{% hint style="info" %}
This feature is currently behind a feature flag. Please contact [Aikido Support](mailto:support@aikido.dev) to have it enabled for your workspace.
{% endhint %}

### Setup

Once support has enabled the feature for your workspace:

1. Go to [**Settings → Bitbucket → Update Workspace Access Token**](https://app.aikido.dev/onboarding/bitbucket/update-workspace-access-token)
2. Scroll to the **Show Extra Tokens** section and add a new workspace token.
3. Make sure the token includes the following scopes:
   * `repository:admin`
   * `project:admin`
4. Save the token.

Aikido will now use your Bitbucket project structure to assign repositories to the correct teams during the next team sync.

{% hint style="info" %}
These additional scopes are required by the Bitbucket v2 API to read project-level access.
{% endhint %}


# Manage Findings


# Main Feed

Aikido's Feed is meticulously designed to streamline security management: it groups similar issues for clarity, allows for customizable views to highlight what's currently important. The main feed focusses on open issues only. Snoozed and ignored issues are accessible on a separate page for a clean giving a focused and clean overview.

### Aikido's Main Feed <a href="#aikidos-main-feed" id="aikidos-main-feed"></a>

The **Feed** is the central hub for monitoring and managing security issues. A similar view can be found all over Aikido when going into details of repositories, clouds and domains.

By default, Aikido enables the **Focus** view, containing all issues that are important to follow-up. By toggling to **All** we will also show issues that have been auto-triaged and ignored.

*Status Column*

Shows the status of the particular issue.

* *New*: issues that have been around for less than 7 days
* *To Do:* all other issues that are still unresolved
* *Task Open:* only when a task manager is linked
* *PR Open:* clicking will take you to PR / branch scan overview.<br>

  <figure><img src="/files/sSTbc8dMtZZ9MTYDElnZ" alt=""><figcaption></figcaption></figure>

### Sidebar <a href="#sidebar" id="sidebar"></a>

Aikido's Feed is equipped with a detailed sidebar, designed to provide users with comprehensive information and actionable options for each security issue. The image below shows the main important actions one can take.

**#1 Group Actions:** these are actions that can be taken on group level of an issue.

**#2 Subissue Actions:** you can also take actions on a subissue separately. This can be important when certain subissues want to be snoozed or ignored, but the overall issue group should remain in the main feed.

**#3 Reachability Analysis:** visualizes accessible code paths for that specific issue.

**#4 Detail Screen**: Separate detail screen with even more information (e.g., CVE information).

![Security dashboard showing a critical vulnerability in the 'bson' package with actionable steps.](/files/PGhjMOCp4m2UeUGBb8si)

**Reachability Analysis**

![](/files/ml4Pev2YkzGpYoWLHxNu)

### Filter Issues <a href="#filter-issues" id="filter-issues"></a>

You can easily adjust the view in order to filter on those issues that are most important to you in the moment. These filters can be found above the issue table in every feed view. You can filter on

* **Issue Type**
* **Predefined filtered views**
  * If you are using the [**SLA functionality**](https://help.aikido.dev/en/articles/8926339-enabling-slas-in-aikido), you will be able to see all upcoming and out of SLA issues

![](/files/hRo8g2Uar99wBOf4FHyx)

### Export Issues to CSV or PDF <a href="#export-issues-to-csv-or-pdf" id="export-issues-to-csv-or-pdf"></a>

You can export a CSV or PDF of issues. You can configure which issues to export exactly. This can be triggered from the Actions menu in the top right.

![Export issues: Filter by status, type, team, and format for CSV or PDF download.](/files/OtTzFqyCtLm4tAPN1oiH)

### Show issues per team or project <a href="#show-issues-per-team-or-project" id="show-issues-per-team-or-project"></a>

**Aikido's Feed** features a **team filter** at the top of the page. This filter allows users to tailor the feed to display only the issues relevant to selected teams ([📖 Set Up Teams](https://help.aikido.dev/en/articles/9005606-using-teams-for-repository-and-user-management)).

![Team selector dropdown with search and statistics on solved and new issues.](/files/l3uw6Nf4oGDCgutTvn9D)


# Aikido Security Checks

### Introduction <a href="#introduction" id="introduction"></a>

Aikido uses a robust array of security checks. Aikido organizes them into Repository, Cloud, Container, and Domain overviews, making it straightforward for you to access and understand the security measures in place.

### Checks <a href="#checks" id="checks"></a>

* [**Repository Scanning checks**](https://app.aikido.dev/repositories/checks): Get insights into the checks for OSS, Secrets, Licences, SAST, IaC, Malware Detection and Mobile Issues
* [**Cloud Configuration Checks**](https://app.aikido.dev/clouds/checks)**:** You can filter on the type of cloud(s) you use for an easy overview.
* [**Container Scanning Checks**](https://app.aikido.dev/containers/checks): Open source dependency monitoring and end-of-life runtimes
* [**Domain Scanning Checks**](https://app.aikido.dev/domains/checks)**:** Checks for your domains and API's

### Other recommended views <a href="#other-recommended-views" id="other-recommended-views"></a>

* [**Overview of licenses and license groups**](https://app.aikido.dev/licenses)
* [**Malware Scanning**](https://app.aikido.dev/reports/malware/software-supply-chain-attacks)
* [**Runtimes and Frameworks**](https://app.aikido.dev/reports/runtimes)


# Manually Adjust Issue Severity

### Introduction <a href="#introduction" id="introduction"></a>

When Aikido finds vulnerabilities in your code repos, cloud environments or public facing domains, our scoring engine gives the vulnerability a severity from 'low' to 'critical'. Our scoring engine takes into account a whole set of rules to assign this severity, but the most important one would be the urgency to fix.

If for some reason, you believe a vulnerability has been given a wrong severity, either to low or to high, Aikido gives you the opportunity to adjust the severity manually so it ends up higher or lower on your list of things to fix.

You can either adjust a **single issue's severity**, or the **severity of a whole group** of issues, in which case they will all get the same severity, regardless of their previous severity.

### Adjust severity of a single issue <a href="#adjust-severity-of-a-single-issue" id="adjust-severity-of-a-single-issue"></a>

A single issue's severity can be adjusted via the issue's action menu found in the sidebar, as shown in the image below.

{% hint style="warning" %}
Severity adjustments are not available for **pentest issues** for compliance reasons. If you believe the priority of a pentest finding is incorrect, please flag it to us so we can discuss it together.
{% endhint %}

![](/files/6cFzhIST9Ly1GDh2Sgth)

### Adjust severity of a whole issue group <a href="#adjust-severity-of-a-whole-issue-group" id="adjust-severity-of-a-whole-issue-group"></a>

To adjust the severity of a whole issue group, you can click on "Adjust severity" on the issue group's action menu in a row in any table.

![Security vulnerabilities dashboard showing critical issues, severity, affected systems, and assigned team members.](/files/nhZw1PzEWKNdtpG3ss2Y)

When adjusting the severity, you need to provide the new severity the vulnerability as well as a reason why you think the severity should be adjusted.

![](/files/8SxW2veUKsd14MUYW9ZI)

If you decide to lower or increase the severity of an issue group, Aikido's scoring engine will not apply that adjusted severity to any newly discovered issue in that group. This is because we believe that you should at that moment evaluate this new finding after which you can again adjust the severity.


# Ignore Issues to Remove Issues From Main Feed

#### Use Cases <a href="#introduction" id="introduction"></a>

While Aikido boasts advanced detection capabilities with auto-ignore (see the [ignore criteria](https://app.aikido.dev/issues/ignored/criteria)), the occasional false positive may slip through, or an issue may be irrelevant to your specific context. The ignore functionality is designed to address this, ensuring your security overview remains accurate.

Users without ignore permissions submit requests instead of ignoring directly. Admins review those in the [Approval Inbox for Ignored Issues](/getting-started/core-functionalities/approval-inbox-for-ignored-issues).

#### How to ignore an issue group or subissue <a href="#how-to-ignore-an-issue-group-or-subissue" id="how-to-ignore-an-issue-group-or-subissue"></a>

**Step 1:** Navigate to the **issue group**, or **subissue** in Aikido you wish to ignore and select the "Ignore" option in the actions menu (triple dots).

![Action menu options for task management and issue handling in a software interface.](/files/XitUA7aoDKy2Hpbss4B0)

**Step 2:** For subissues, you will be asked about how Aikido should treat this subissue and potential similar detections in the future.

![](/files/HP2SdmBHPXQA60r6lygO)

You have a few options available to ignore the current and future issues. The options available depend on the context in which you are ignoring an issue (single issue or issue group), but also on the issue type (e.g., Surface Monitoring and Cloud Issues show different options).

Below are all the ignore options listed that you might see

* **Only this issue/only this issue group**\
  This option will only ignore this subissue, or this issue group and all its sub issues, depending on the context. *Note. If you ignore an issue group, new future subissues will not be auto-ignored and will re-open the group containing this specific subissue.*\
  ​
* **Ignore by path**\
  When choosing this option, you create an issue rule which will ignore all current and future file based issues (open source, SAST, IAC and exposed secrets) under a certain path. You can edit the path there for convenience to make the rule as specific as you'd like.\
  ​\
  This can be helpful when there are testing frameworks in a specific path that you do not want Aikido to scan.

  ![](/files/pAE3fdXdwKHAcZ54oYGa)

  ​
* **Ignore all findings related to CVE**\
  This option creates an issue rule which ignores all current and future open source dependencies linked to that CVE. This ignore rule is global and is applied to all repositories.\
  ​
* **Ignore all findings related to rule**\
  Most issues in Aikido are related to a specific rule code such as SAST, IAC and Cloud issues. When selecting this option, you create an issue rule which ignores all current and future issues related to that specific rule. This ignore rule is global and is applied to all repositories.

**Step 3:** Confirm your choice to ignore the issue, effectively removing it from your main feed in Aikido.

#### View all (auto-) ignored issues <a href="#check-out-all-auto--ignored-issues" id="check-out-all-auto--ignored-issues"></a>

The [ignore view](https://app.aikido.dev/issues/ignored) consolidates all issues ignored by Aikido's triaging algorithm, as well as those manually ignored by users. Here, you can review the rationale behind each automatically ignored issue (see the [ignore criteria](https://app.aikido.dev/issues/ignored/criteria)). Your manually ignored issues will also be displayed here, providing a comprehensive overview of all exclusions made within Aikido.

![](/files/2Fw7Ie7D39XJVKqTpEm8)


# Approval Inbox for Ignored Issues

The approval inbox lets you require admin sign-off before users without ignore permissions can dismiss findings. Team members submit ignore requests with a reason, and admins review them in a central inbox before anything is removed from the feed.

## Use cases

* 🛡️ **Governance over risk acceptance**: Keep security leads in control of which findings get ignored.
* 👥 **Empower developers**: Let engineers triage false positives without handing out full ignore rights.
* 📋 **Audit trail**: Every request records who asked, why, and who approved or declined.

## Enabling ignore requests

Ignore requests are **not enabled by default**. Only workspace admins can turn them on from the [Triage settings](https://app.aikido.dev/settings/advanced).<br>

<figure><img src="/files/bbH6lr7lrABb0GZ0orxP" alt=""><figcaption></figcaption></figure>

## How it works

Whether a user can ignore an issue directly depends on their **Ignore permissions** (see [Setting Roles and Permissions](/getting-started/automated-user-management/setting-roles-and-permissions)) and whether **Allow Issue Ignore Requests** is enabled for your workspace:

* **With ignore permissions**: Users ignore findings immediately, the same as before.
* **Without ignore permissions, with ignore requests enabled**: Users submit an ignore request with a reason. The issue stays in the feed until an admin approves or rejects it.
* **Without ignore permissions, with ignore requests disabled**: Users cannot ignore findings or submit requests.

<img src="/files/uA2T7VNANDy8aEMrn4BV" alt="" width="375">

{% hint style="info" %}
Ignore requests apply to **individual subissues only**. Broader ignore rules (by path, CVE, or rule) still require ignore permissions.
{% endhint %}

When a user submits a request, admins are notified and can review it in the [Request Inbox](https://app.aikido.dev/inbox/issues/actions). The inbox lists the issue details, severity, location, requester, and their stated reason.

## Review ignore requests

{% stepper %}
{% step %}

### Open the inbox

Go to the [Request Inbox](https://app.aikido.dev/inbox/issues/actions), or click a pending notification in the **messages** indicator in the top navigation. The inbox shows a badge with the number of pending requests.<br>

<figure><img src="/files/mlIpGk3AqV8utoR3sPBV" alt="" width="375"><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Review a request

Click a row or the **Review** button on a pending request. The review modal shows the full issue context and the requester's reason.

<figure><img src="/files/3zJ3x8FSRBpK1C8fMi6X" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Approve or reject

Click **Approve** to ignore the issue with the requester's stated reason, or **Reject** to decline the request and keep the issue open.<br>

<figure><img src="/files/0EnIg5MOi66JsVkxnyzG" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

### Pending and handled

The inbox has two tabs:

* **Pending**: Requests waiting for a decision.
* **Handled**: Requests you have already approved or rejected, including who reviewed them and when.

Use the search bar to filter by issue title or requester name. If you have a team filter active in Aikido, the inbox only shows requests for issues in that team.

### What happens after a decision

**Approved**: Aikido ignores the issue using the requester's reason. The finding moves to the [ignored view](https://app.aikido.dev/issues/ignored) and disappears from the main feed. The request is attributed to the original requester.

**Rejected**: The issue stays open or snoozed in the feed. The requester can submit a new request if needed.

## Notifications

Admins or users with ignore permissions see new ignore requests in the **messages** indicator in the top navigation. Each notification shows the request type and who submitted it. Click the notification to open the Request Inbox.<br>

<figure><img src="/files/SDPUxaJ5HD7BynHqJVco" alt=""><figcaption></figcaption></figure>

### Slack notifications

You can also receive Slack alerts when a new ignore request is submitted. Aikido posts a message to your chosen channel with a **Review in Aikido** button that links directly to the Request Inbox.

{% stepper %}
{% step %}

### Connect Slack

If you haven't already, connect Slack from [Slack integration settings](https://app.aikido.dev/settings/integrations/notifications/slack). See [Slack Notifications](/getting-started/chat-and-alerts/slack-notifications) for setup steps.
{% endstep %}

{% step %}

### Create a Slack alert

Go to the [Request Inbox](https://app.aikido.dev/inbox/issues/actions), open the **Ignore Issues** tab, and click **Manage Alerts** → **Slack**. Click **Create Alert** and select the channel that should receive ignore request notifications.
{% endstep %}

{% step %}

<figure><img src="/files/Q6pjksKKD3hn27m0yVEe" alt=""><figcaption></figcaption></figure>

### Test the alert

After saving, use **Send test alert** on the alert row to confirm messages arrive in the selected channel.
{% endstep %}
{% endstepper %}


# Snooze Issues for Later

### Use Case <a href="#introduction" id="introduction"></a>

Aikido introduces a flexible snooze feature that allows the snoozing of issue groups or subissues separately. This functionality clears the main feed of non-urgent items, providing a cleaner workspace to focus on immediate priorities.

### How to snooze issues <a href="#how-to-snooze-issues" id="how-to-snooze-issues"></a>

**Step 1.** Navigate to the **issue group**, or **subissue** in Aikido you wish to snooze and select the "Snooze" option in the actions menu (triple dots).

![Context menu displays task management actions like create, snooze, ignore, and adjust severity.](/files/Y1nWjqSotaXG8x32Cnbk)

**Step 2.** Choose the duration for snoozing: 1 day, 1 week, 1 month, 1 year, or specify a custom period.\
​

![](/files/gxDdQ1UPSnCJjbgHZU8D)

**Step 3.** Optionally, add a reason for snoozing to keep track of the decision-making process.\
​

![](/files/7Vv4ksuc4nD58yL6kUW5)

​After snoozing, these items will disappear from the main feed, simplifying your view to focus on what's urgent.

### Viewing Snoozed Items: <a href="#viewing-snoozed-items" id="viewing-snoozed-items"></a>

* Access the [Snooze View](https://app.aikido.dev/issues/snoozed) in Aikido to see all snoozed issue groups and subissues. You can extend or unsnooze any issue from this view.\
  ​

  ![](/files/XACep7OVEl927GM3HgMX)


# Display License Issues in Feed

In addition to the license report, Aikido allows you to display licenses directly in the feed. These issues are grouped by license type and show all locations where a specific license is used. This feature helps you stay informed and take immediate action on license-related issues.

### Benefits <a href="#benefits" id="benefits"></a>

* Directly act licenses: snooze, ignore, or create tasks.
* Receive alerts for new critical and high severity license issues.

### How to enable Licenses in feed <a href="#how-to-enable-licenses-in-feed" id="how-to-enable-licenses-in-feed"></a>

**Step 1:** Navigate to the [License & SBOM Reports page](https://app.aikido.dev/licenses)

**Step 2:** Click the Action dropdown menu and select 'Display Licenses in Feed'

![Dropdown menu with option to display licenses in the feed.](/files/2pPJ99UOd7qrA73nMJFe)

**Step 3:** Select one of the three options. You have the option to show only the critical licenses issues, or also including the high severity ones.

> **Note:** all issues in the feed are reflected in the trends over time report. This means that by enabling this functionality, there might be a bump in the number of open issues.

![License issue feed settings with options for filtering severity and reporting.](/files/9blw57zMRjiT8yDGQJAh)

**Step 4:** Go back to Feed and select License Issues in the filter. All open critical and/or high severity license issues will be displayed. **Aikido will run a scan in the background to start showing licenses - this can take a minute.**

![Security dashboard menu highlighting resolved License Issues.](/files/cccVINOYwZAl3mmFpRmp)


# Enable SLAs in Aikido

## Enable SLAs in Aikido

You can enable SLA settings in Aikido to automatically assign due dates to tickets. This facilitates a structured and timely approach to issue resolution based on their reported time and severity.

#### Detection and SLA Reset Logic <a href="#how-to-enable-slas-in-aikido" id="how-to-enable-slas-in-aikido"></a>

* SLA countdown starts the moment Aikido first detects the issue and are measured in calendar days, not business days
* When the severity of an issue is manually changed, the SLA date resets.
* When an issue is unsnoozed, the SLA date resets.
* When an issue is unignored, the SLA date resets.

#### How to enable SLAs in Aikido <a href="#how-to-enable-slas-in-aikido" id="how-to-enable-slas-in-aikido"></a>

1. Navigate to the Settings -> [SLA settings](https://app.aikido.dev/settings/sla)
2. Ensure the 'Enable SLAs' option is turned on to implement SLA rules.\
   ​

   ![Set and enable SLAs per severity to manage vulnerabilities and notify stakeholders via Slack.](/files/uGVcgaxnUKdqhOrHKMzr)
3. Input the **number of days** for resolution in the fields for Critical, High, Medium, and Low priority issues to establish SLA time frames.\
   ​

   ![Issue resolution deadlines by priority: critical (5 days), high (20), medium (60), low (100).](/files/fHiygcyfx12YnNhXxLzr)

   ​
4. Set up the '**Due Soon' notification threshold** by specifying the number of days before the SLA deadline, which will highlight impending due dates on the [SLA Due Soon](https://app.aikido.dev/queue?filter=due_soon) view.\
   ​

   ![Set the 'Due Soon' issue status by days before the SLA deadline.](/files/xPngeMyECbDVww6D1Fjg)
5. Click **'Save'** to apply these configurations.

#### SLA Information in Aikido UI <a href="#sla-information-in-aikido-ui" id="sla-information-in-aikido-ui"></a>

After setting up your SLA parameters, here's how you can monitor your SLA due dates.

* **Sidebar Information**: Next to each subissue in the sidebar, you will see the SLA information, providing a quick reference to gauge urgency. Hover over the label in order to view the date.\
  ​

  ![NodeGoat subissues list with priorities, due dates, authors, and commit links.](/files/h6J2AgsXVoGerNOEuDTX)
* **SLA Due Soon Filter**: The [**SLA Due Soon**](https://app.aikido.dev/queue?filter=due_soon) view view displays issues that are close to breaching the SLA, based on the threshold set. **Enable this filtered view** by clicking the Filter Icon on your Feed and select SLA Due Soon.\
  ​

  ![Security vulnerabilities dashboard showing severity, status, and assignment for identified software issues.](/files/kAdVeiYqHeGfONDrxg41)
* **Out of SLA View**: The [**Out of SLA**](https://app.aikido.dev/queue?filter=out_of_sla) view lists all issues and subissues that have exceeded their SLA limits. **Enable this filtered view** by clicking the Filter Icon on your Feed and select Out of SLA.\
  ​

  ![Critical vulnerabilities dashboard showing unassigned open tasks and their fix times.](/files/iusuRBu4QwUSaPQsXQuZ)

***


# How is Severity Score Calculated

Aikido provides a contextual, risk-based severity score from 0 to 100, offering 10× more granularity than traditional CVSS scoring (which is on a 0–10 scale). This allows for better prioritization and filtering.

<table><thead><tr><th width="143.943603515625">Severity</th><th width="155.927001953125">Score</th></tr></thead><tbody><tr><td>Critical</td><td>90 - 100</td></tr><tr><td>High</td><td>70 - 89</td></tr><tr><td>Medium</td><td>40 - 69</td></tr><tr><td>Low</td><td>1 - 39</td></tr></tbody></table>

### 1. Multiple Vulnerability Data Sources

We continuously monitor a variety of vulnerability feeds and databases, that provide baseline severity information and help establish initial severity scores. Databases include:

* Public vulnerability databases (e.g., NVD, GHSA,... | [See full list](https://help.aikido.dev/code-scanning/scanning-practices/external-vulnerability-databases-used-in-our-sca-engine))
* Operating system and vendor-specific advisories
* Our own Aikido Intel: <https://intel.aikido.dev/>

### 2. Contextual Severity Adjustments

To reflect actual risk more accurately, Aikido layers in additional context such as exploitability, environment, threat intelligence, and custom rules.<br>

**Exploitability & Threat Intelligence:**

Severity can increase when there’s evidence of real-world risk:

* The vulnerability is actively exploited or appears on the CISA KEV list
* A public PoC exploit is available (e.g., on GitHub)

#### Business Context

Severity is adjusted based on the importance of the affected asset. Some example are:

* Production vs test environments
* Backend vs frontend code
* Whether the vulnerable code is reachable or executed

#### Customer Rules

You can further refine issue scoring by adding contextual information to your project

* Learn how you can improve the risk score for repositories and containers [here](/code-scanning/miscellaneous/improve-risk-scoring-for-repositories-and-containers)

#### Exploit Prediction (EPSS)

Aikido also supports EPSS-based prioritization to automatically downgrade or ignore vulnerabilities that are unlikely to be exploited in the next 30 days. This is optional and turned off by default, more info here: [Exploit Intelligence with KEV and EPSS](/code-scanning/miscellaneous/use-epss-values-to-further-reduce-noise)

{% hint style="success" %}
You can click the score to view a detailed breakdown of why this issue received this severity rating
{% endhint %}

<figure><img src="/files/zIMv8Wyft3w1nozoHQeQ" alt="" width="375"><figcaption></figcaption></figure>


# Why Was an Issue Marked as Solved

In Aikido, issues automatically move from **Open** to **Solved** when they are no longer detected in the latest scan.

There are several common reasons why this might happen:

***

### ✅ The Issue Was Fixed <a href="#the-issue-was-fixed" id="the-issue-was-fixed"></a>

Someone in your team resolved the problem, so it's no longer showing up in the scan because it has been **completely removed or fixed in code**.

***

### 🌿 Branch Change <a href="#branch-change" id="branch-change"></a>

If you're scanning a **different branch**, Aikido will:

* Close issues tied to the old branch
* Open any issues found on the new one
* 💡You can verify which branch is being scanned via the tag on the [repository page](https://app.aikido.dev/repositories)

  ![Highlighted "master" branch in the about-github repository navigation menu.](/files/O1TVf2R0ipMsPFY62ePl)

***

### 📁 File Relocation <a href="#file-relocation" id="file-relocation"></a>

If the affected file was **moved or renamed**, Aikido will:

* Mark the original issue as solved (since the file path changed)
* Potentially open a new issue under the new file location

***

### 🔐 CVE Database Update <a href="#cve-database-update" id="cve-database-update"></a>

Sometimes CVEs get updated to narrow down the versions affected.

**Example**:

* Aikido flagged a vulnerability in log4j:2.17.1 based on CVE-2021-44832.
* Later, the CVE was updated to say only versions ≤2.17.0 are affected.
* Aikido picked up the change and automatically removed the issue for 2.17.1.

***

### 📦 Dependency Moved to Dev-Dependency <a href="#dependency-moved-to-dev-dependency" id="dependency-moved-to-dev-dependency"></a>

If a vulnerable package is moved from a production dependency to a dev-dependency, Aikido will:

* Mark the original issue as solved (since the dependency type changed)
* Not longer report the issue as dev-dependencies are **by default** not scanned.
* 💡 You can enable scanning of dev-dependencies on a **per-repository** basis. [More information in this doc](/code-scanning/scanning-practices/scanning-dev-dependencies-for-cves)

***

### 🧠 SAST Rule Improvements <a href="#sast-rule-improvements" id="sast-rule-improvements"></a>

Static analysis rules are continuously improved to reduce false positives. As these rules become more accurate, Aikido may:

* **Mark previously flagged issues as solved**
* Prevent future false alarms for similar patterns

***

### 🗂️ Local Scanning – Scan Location Changed <a href="#local-scanning-scan-location-changed" id="local-scanning-scan-location-changed"></a>

When scanning locally, changing the **target directory** will influence what gets scanned.

* Issues in unscanned paths will be marked as solved
* New issues may show up in the new location

***

### Still Not Sure? <a href="#still-not-sure" id="still-not-sure"></a>

This list covers the most frequent causes, but there may be other edge cases.

👉 If you're unsure why something was marked as solved, reach out through the in-app chat. We're happy to help.


# Resolving Malware and Leaked Secret Issues

**Malware** and **leaked secret findings** require you to close them manually using **Mark as solved**. For leaked secrets, Aikido detects the secret in your version history but leaves invalidation to you, as this happens in an external system and cannot be fully verified. For malware, Aikido flags the infected package but requires you to confirm removal, since automated verification of a clean state is never fully reliable.

{% hint style="info" %}
More about our Malware Detection and Prevention?

* Read more about [Aikido malware detection](/code-scanning/scanning-practices/malware-detection-in-open-source-dependencies)
* Use [Safe Chain](/code-scanning/aikido-malware-scanning) to block malicious packages before they are installed
  {% endhint %}

<figure><img src="/files/OE5zPkuckB7eW4fLMVVw" alt=""><figcaption></figcaption></figure>

### What to do before marking an issue as solved

#### Leaked secrets

A secret can stay in Git history forever, even after you remove it from the latest commit.

Before marking the issue as solved:

1. Revoke or rotate the secret immediately.
2. Confirm the old secret no longer works.
3. Check that no system still depends on it.
4. Only then mark the issue as solved.

{% hint style="warning" %}
Marking a leaked secret as solved does **not** mean the secret disappeared from version history. It means you invalidated it and removed the risk.
{% endhint %}

#### Malware findings

For malware, Aikido cannot prove removal unless it no longer appears in your dependency data.

Before marking the issue as solved:

1. Remove the affected package from the project.
2. Remove it from the lockfile.
3. Reinstall dependencies if needed.
4. Confirm it no longer appears in the dependency tree.
5. Only then mark the issue as solved.

{% hint style="warning" %}
If you are not sure the malware package is gone, contact Aikido support before marking it as solved.
{% endhint %}

### How to mark an issue as solved

1. Open the issue from the issue list, grouped issue view, or queue sidebar.
2. Open the action menu.<br>

   <figure><img src="/files/3Ric80GVd8zWTxBPBgvC" alt=""><figcaption></figcaption></figure>
3. Select **Mark as solved**.
4. Review the confirmation prompt.<br>

   <figure><img src="/files/oOviJI5hMLjbvvCBL0Jz" alt=""><figcaption></figcaption></figure>
5. Confirm.


# What Does "No Fix" Mean

When a package has no fix version available, Aikido may automatically suppress or collapse the related vulnerabilities, especially if they come from an end-of-life (EOL) base image. Instead of showing dozens or hundreds of unfixable issues, we give you one actionable alert: upgrade the base image.

### What Does “No Fix Version” Mean?

Some vulnerabilities (CVEs) are labeled as having “no fix available.” This typically means:

* The package maintainer has stopped support, so no patches are being released.
* The OS version is EOL, so upstream security teams are no longer issuing fixes.
* A patched version of the affected package doesn’t exist.<br>

This is common in old Linux distributions used in container base images, such as:

* Ubuntu 14.04 / 16.04
* Debian Jessie / Stretch
* Alpine 3.10 or older

***

### Why Does Aikido Ignore These CVEs?

We don’t *fully* ignore them. Instead, we collapse them into a higher-level issue that’s actually fixable:

Instead of flooding your dashboard with hundreds of Critical CVEs that can’t be fixed, Aikido points to the real solution: replacing the EOL base image.

<figure><img src="/files/uTc6SISMvhenU81LbWy5" alt=""><figcaption></figcaption></figure>

### Examples

#### **Debian**

Debian Security Team often marks issues for end-of-life releases as *“not covered”* or *“no DSA”*. For supported releases they may mark *“no-dsa”* (that is, they won’t issue an advisory) when risk is low or impact is limited. This effectively means no patch will be shipped via security updates and the distro relies on regular point releases or upstream-only fixes.

#### Alpine

Alpine’s SecDB advisory database may show no fixed version for older branches where backports are not produced. The remediation is to move to a supported branch.

#### Unmaintained Libraries

Projects using the abandoned or unmaintained libraries might show as no fix available. This is because maintainers no longer ship fixes. You will ultimately need to replace the library with a maintained alternative, which Aikido may recommend in its issue analysis (for example, replacing the obsolete `pycrypto` with `pyca/cryptography`).

<figure><img src="/files/G6GyglSPtPRa754wWvfF" alt=""><figcaption></figcaption></figure>

### Benefits of This Approach

✅ **Clearer Priorities**: You won’t waste time triaging vulnerabilities that have no resolution path.

✅ **Less Noise**: By compressing unfixable issues, Aikido helps you focus on what you *can* fix.

✅ **Real Fixes**: We highlight the only practical solution: upgrade the container base image to a supported version.

### But Isn’t That Risky?

No, and here’s why:

We **only** suppress CVEs when:

* Upstream has confirmed no fix will ever be released.
* The issue is not relevant in context (e.g., cannot be exploited in a container).
* Aikido can replace the signal with a more actionable alert (e.g., EOL image).<br>

We **never** suppress vulnerabilities that:

* Have a patch or fix available
* Are known to be exploitable in your context
* Require immediate action for active threats

### What Should You Do?

🔍 Look for:

* “End-of-Life container” warnings or recommendations to upgrade your base image
* Update the base image to a newer, supported version. That will automatically remove most of the unfixable CVEs in one go.

### Advanced Options (Enterprise)

If you must continue using older software, Aikido offers:

* 🔧[ Auto-upgrading containers](/autofix-and-remediation/scope/ai-autofix-for-containers)
* 🔐 [Aikido Images: zero-CVE base images with backported patches](/autofix-and-remediation/scope/autofix-for-containers-using-aikido-images)


# How Is Fix Time Calculated

### What Is Fix Time?

Fix time is a rough estimate of how long it may take to remediate a security issue. It’s not exact, but it can help you prioritize and plan based on the relative effort required.

### How It’s Calculated

Aikido uses a custom algorithm per issue type. Here’s how it works:

#### 🧬 Dependency (SCA) Issues

Fix time depends on the type of version upgrade:

* Minor upgrade (e.g. 4.5.1 → 4.5.2) → 5–15 minutes
* Major upgrade (e.g. 1.0 → 3.0, or across EOL boundaries) → at least 1 hour

#### 🔍 SAST (Code Issues)

Calculated as: Issue count × static time per issue type

Examples:

* SQL Injection ≈ 30 min/issue
* Secrets ≈ 10 min/issue

#### ☁️ Cloud Issues

Similar logic as SAST: static values per issue type, multiplied by count.

#### 🔑 Secrets

One fixed estimate per issue (e.g., rotate a key = 5–10 minutes).

{% hint style="success" %}
When there's an [Aikido AutoFix ](/autofix-and-remediation/overview-aikido-autofix)available, the actual fix time will be lower
{% endhint %}


# Task Management Tools

### Jira

{% content-ref url="/pages/s7ArXQbQNd7CXc6fL9Z8" %}
[Jira Cloud](/getting-started/task-management-systems/all-supported-task-trackers/jira-cloud)
{% endcontent-ref %}

{% content-ref url="/pages/WfzmwGRszNZsxsLit2xy" %}
[Troubleshoot Jira Task Creation: Set Up Default Issue Types](/getting-started/task-management-systems/troubleshoot-jira-task-creation-set-up-default-issue-types)
{% endcontent-ref %}

{% content-ref url="/pages/OcpQXllbbE7ApQdqQ2Hi" %}
[Jira Data Center](/getting-started/task-management-systems/all-supported-task-trackers/jira-data-center)
{% endcontent-ref %}

{% content-ref url="/pages/Vn09m74DFty8op2s18p3" %}
[Auto-Close Jira Tasks When Aikido Issues Are Resolved / Ignored](/getting-started/task-management-systems/advanced-functionalities/auto-close-jira-tasks-when-aikido-issues-are-resolved)
{% endcontent-ref %}

### Linear

{% content-ref url="/pages/amQjsuScSm860YvcyNOo" %}
[Linear](/getting-started/task-management-systems/all-supported-task-trackers/linear)
{% endcontent-ref %}

{% content-ref url="/pages/wILek0K1ugPeN6QiGI0q" %}
[Auto-Close Linear Tasks When Aikido Issues Are Resolved / Ignored](/getting-started/task-management-systems/advanced-functionalities/auto-close-linear-tasks-when-aikido-issues-are-resolved)
{% endcontent-ref %}

### Others

{% content-ref url="/pages/IW7dwgSkdg8Fsw2m1V4w" %}
[Asana](/getting-started/task-management-systems/all-supported-task-trackers/asana)
{% endcontent-ref %}

{% content-ref url="/pages/ksHTEsXT6kf5yZsaBWBG" %}
[Azure DevOps Boards](/getting-started/task-management-systems/all-supported-task-trackers/azure-devops-boards)
{% endcontent-ref %}

{% content-ref url="/pages/E67t7cvel70gsbgesE6J" %}
[ClickUp](/getting-started/task-management-systems/all-supported-task-trackers/clickup)
{% endcontent-ref %}

{% content-ref url="/pages/OMf0HBMgMdwa2fxmL4DJ" %}
[GitHub Issues](/getting-started/task-management-systems/all-supported-task-trackers/github-issues)
{% endcontent-ref %}

{% content-ref url="/pages/52DvGrsHujSyEkkWKMoP" %}
[GitHub Enterprise Cloud Issues](/getting-started/task-management-systems/all-supported-task-trackers/github-enterprise-cloud-issues)
{% endcontent-ref %}

{% content-ref url="/pages/AA4em9z3TTylSuDQQgQY" %}
[GitLab Issues](/getting-started/task-management-systems/all-supported-task-trackers/gitlab-issues)
{% endcontent-ref %}

{% content-ref url="/pages/MOn0KkWFHCqtLxOmIuzM" %}
[GitLab Issues Self-Managed](/getting-started/task-management-systems/all-supported-task-trackers/gitlab-issues-self-managed)
{% endcontent-ref %}

{% content-ref url="/pages/cjRLm8xzMPRDZl7M8gfe" %}
[JetBrains YouTrack](/getting-started/task-management-systems/all-supported-task-trackers/jetbrains-youtrack)
{% endcontent-ref %}

{% content-ref url="/pages/FIVKrCNtam6oBIjKCpcE" %}
[Monday.com](/getting-started/task-management-systems/all-supported-task-trackers/mondaycom)
{% endcontent-ref %}

{% content-ref url="/pages/UAZRG426sexlkkyoFvwR" %}
[Shortcut](/getting-started/task-management-systems/all-supported-task-trackers/shortcut)
{% endcontent-ref %}


# All Supported Task Trackers


# Jira Cloud

This one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in Jira Cloud.

Following use cases are supported :

* **Automated Ticket Creation**: Automatically create and push tickets to specified Jira projects for seamless tracking of security issues.
* **Manual Ticket Addition**: Manually add security issue tickets to Jira, ensuring targeted attention for critical vulnerabilities.

{% hint style="warning" %}
Note: the ticket creation is linked to the user who has set up the integration. We recommend creating an extra 'Aikido' user inside Jira with write access to all projects.
{% endhint %}

## Connecting the Aikido App to Jira <a href="#connecting-the-aikido-app-to-jira" id="connecting-the-aikido-app-to-jira"></a>

1. Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app.
2. In the 'Task Trackers' section, select 'Jira Issues'
3. A prompt will request authorization for Jira.\
   ​

   ![Jira access unauthorized; prompt to authorize account for issue-tracking integration.](/files/TZqlIRVIfonod9yKk68L)
4. Login into your Jira account
5. Grant Aikido permission to access your Jira workspace

   ![Aikido Security requests permission to access and manage your Atlassian Jira account.](/files/vF2sflL3WnqZp2euqHdU)
6. Once authorized, Aikido is successfully connected to Jira, enhancing your task management capabilities 🚀<br>

<figure><img src="/files/nKPnqEDd4ooEppm5trGC" alt="" width="563"><figcaption></figcaption></figure>

## ​Options for Task Creation in Jira via Aikido <a href="#options-for-task-creation-in-jira-via-aikido" id="options-for-task-creation-in-jira-via-aikido"></a>

There are two different options to create new tasks from Aikido into Jira.

1. Manually create tasks from the Aikido interface
2. Automatically create new tasks via Aikido's auto creation functionality.

## 1. Manual Task Creation <a href="#id-1-manual-task-creation" id="id-1-manual-task-creation"></a>

1. Hover over any issue in your feed and click the ***+*** in the **assign column.**

   ![Task management table with “Assignee” column and options to add or edit entries.](/files/qHdYxduZ8eHuhsF9A0fa)

   Alternatively, you can click the triple dots in the last columns to open up the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.

   ![Menu of task management actions: create, snooze, ignore, copy link, adjust severity.](/files/7xp9HLvMM8GGtAjHhf52)
2. Fill in the required details in the popup modal.\
   ​

   ![Jira task creation form detailing a critical security vulnerability.](/files/N2YGobr1CcXY7Bi0ws7o)
3. The newly created task in Jira will be linked in the Aikido Issue Detail under the 'Tasks' tab (sidepanel).

![Critical security task: var\_dump() may expose sensitive user information; action required.](/files/bLGFCrC1jGet4HszJo3r)

## 2. Automated Task Creation <a href="#id-2-automated-task-creation" id="id-2-automated-task-creation"></a>

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [Jira Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings
2. Make sure to enable '**Autocreation**' by clicking the toggle to **On.**
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will autonomously generate Jira tickets hourly until the configured daily limit of tasks is reached

### Jira Sync Information <a href="#jira-sync-information" id="jira-sync-information"></a>

Aikido automatically syncs a couple of fields to Jira

* Severity is mapped to the 'Priority field' in Jira (one way)
* Assignees are synced both ways (so updates in Jira will be reflected in Aikido too

***


# ServiceNow

This one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in ServiceNow.

Following use cases are supported:

* **Automated Ticket Creation**: Automatically create and push tickets to ServiceNow for seamless tracking of security issues.
* **Manual Ticket Addition**: Manually add security issue tickets to ServiceNow, ensuring targeted attention for critical vulnerabilities.

{% hint style="info" %}
Aikido currently pushes tickets to the **Incident** table in ServiceNow. Support for additional tables can be requested via Support.
{% endhint %}

### Prerequisites: Register an OAuth App in ServiceNow

Before connecting Aikido, you'll need to register an OAuth application in your ServiceNow instance to generate a **Client ID** and **Client Secret**.

{% stepper %}
{% step %}
**Activate the OAuth 2.0 plugin**

Log in to your ServiceNow instance and activate the OAuth 2.0 plugin if it isn't already.
{% endstep %}

{% step %}
**Enable OAuth system property**

In the `sys_properties` table, set the system property `com.snc.platform.security.oauth.is.active` to `true`.
{% endstep %}

{% step %}
**Open the Application Registry**

Navigate to **System OAuth > Application Registry**.
{% endstep %}

{% step %}
**Create a new OAuth endpoint**

Click **New**, then select **Create an OAuth API endpoint for external clients**.
{% endstep %}

{% step %}
**Configure the application**

Set the following fields:

* **Name**: A unique name (e.g. `Aikido`)
* **Client ID**: Auto-generated by ServiceNow
* **Client Secret**: Auto-generated by ServiceNow
* **Redirect URI**: `https://unify.apideck.com/vault/callback`
* **Refresh Token Lifespan**: Time in seconds the refresh token is valid
* **Access Token Lifespan**: Set to `3600`
* **Scope Restriction**: Set to **Broadly scoped**

{% hint style="info" %}
The default `Securely scoped` will cause API calls to fail.
{% endhint %}
{% endstep %}

{% step %}
**Save and copy credentials**

Click **Submit**, then reopen the record to copy the **Client ID** and **Client Secret** values.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
Note: the ticket creation is linked to the user who has set up the integration. We recommend creating a dedicated 'Aikido' user inside ServiceNow with write access to the Incident table.
{% endhint %}

### Connecting the Aikido App to ServiceNow

{% stepper %}
{% step %}
**Open the integration**

Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app. In the 'Task Trackers' section, select **ServiceNow**.

<figure><img src="/files/cx5AXDrhKcXeLuEZ6fNu" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Fill in your credentials**

Enter your ServiceNow **instance name**, **Client ID**, and **Client Secret**, then click **"Save"**.

{% hint style="info" %}
Your ServiceNow **instance name** is the subdomain in your admin URL (e.g. `dev394641` from `https://dev394641.servicenow.com`).
{% endhint %}

<figure><img src="/files/NpW9yhcqjRtaFAmxuUX8" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Authorize the connection**

Click **"Authorize"** to grant Aikido access to your ServiceNow instance.

<figure><img src="/files/lQkXSlkfah2VpT2roU7c" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Confirm**

Click **"Save"** once more to complete the setup. Aikido is now connected to ServiceNow.

<figure><img src="/files/kpYjqshO0N4e0IKfC3k8" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

### Options for Task Creation in ServiceNow via Aikido

There are two different options to create new tasks from Aikido into ServiceNow.

#### 1. Manual Task Creation

1. Hover over any issue in your feed and click the ***+*** in the **assign column.** Alternatively, you can click the triple dots in the last column to open up the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.\
   \
   ![](/files/Qb7Y04BrqDzbbXCIcmXs)
2. Fill in the required details in the popup modal.\
   \
   ![](/files/zZvfssnnLnWEAzBQUbrF)
3. The newly created task in ServiceNow will be linked in the Aikido Issue Detail under the 'Tasks' tab.

#### 2. Automated Task Creation

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [ServiceNow Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings
2. Make sure to enable '**Autocreation**' by clicking the toggle to **On.**
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will autonomously generate ServiceNow tickets hourly until the configured daily limit of tasks is reached.

<figure><img src="/files/64D5EuIMN9uCu8TkSs7N" alt=""><figcaption></figcaption></figure>

### ServiceNow Sync

Aikido automatically syncs a couple of fields to ServiceNow:

* Severity is mapped to the 'Priority' field in ServiceNow
* Assignees are synced both ways (so updates in ServiceNow will be reflected in Aikido too)


# Jira Data Center

This article focuses on those companies that have Jira Data Center running (i.e., Jira on premise, different from [Jira Cloud](https://help.aikido.dev/en/articles/8680218-setting-up-automated-task-creation-in-jira-cloud)). The following one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in Jira On Prem.

Following use cases are supported :

* Automated Ticket Creation: Automatically create and push tickets to specified Jira projects for seamless tracking of security issues.
* Manual Ticket Addition: Manually add security issue tickets to Jira, ensuring targeted attention for critical vulnerabilities.

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

In order to make the connection to JIRA Data Center, you'll need to create a personal access token. This token will then be used to carry out all requests to your instance.\
​\
Please note that the level of access the integration has will be equal to the person who created the personal access token (PAT). It's therefore advised to let a person with sufficient access rights in the environment to create the PAT.

To create a PAT, you can follow the steps below:

1. Navigate to your JIRA Data Center environment
2. Click on your avatar in the navigation bar on top and navigate to "Profile"
3. Click on "Personal Access Tokens", you should end up on a screen similar to the one below**​**

   ![Jira Software personal access tokens page prompting user to create their first token.](/files/Z25FgiBJs9Rc6oGf9XES)
4. Click on "Create token" and give it an appropriate name
5. We advise to not set an expiry date, but if you do, you'll have to remind yourself to update the token in Aikido periodically
6. Once the token is created, you'll get to copy it momentarily, copy the token and keep it for the next step

### Connecting the Aikido App to Jira <a href="#connecting-the-aikido-app-to-jira" id="connecting-the-aikido-app-to-jira"></a>

1. Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app.
2. In the 'Task Trackers' section, select 'Jira Data Center'
3. Enter the url of your environment
4. Enter the PAT from the previous step and hit "Save"**​**

   ![Jira Data Center integration setup: enter server URL and personal access token.](/files/oT5pVsbFNirQiypg94UW)
5. Once authorized, Aikido is successfully connected to Jira, enhancing your task management capabilities 🚀

   ![Jira Data Center integration settings for repo mapping, task autocreation, and default labels.](/files/HI2Awle93IMtSSWM43ql)

### Options for Task Creation in Jira via Aikido <a href="#options-for-task-creation-in-jira-via-aikido" id="options-for-task-creation-in-jira-via-aikido"></a>

There are two different options to create new tasks from Aikido into Jira.

1. Manually create tasks from the Aikido interface
2. Automatically create new tasks via Aikido's auto creation functionality.

### 1. Manual Task Creation <a href="#id-1-manual-task-creation" id="id-1-manual-task-creation"></a>

1. Hover over any issue in your feed and click the *+* in the assign column.**​**

   ![Task assignment table with add and options buttons under "Assignee" column.](/files/qHdYxduZ8eHuhsF9A0fa)

   Alternatively, you can click the triple dots in the last columns to open up the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.\
   ​

   ![Action menu with options to manage, share, or adjust task settings.](/files/7xp9HLvMM8GGtAjHhf52)
2. Fill in the required details in the popup modal.\
   ​

   ![Jira task creation form with project, assignee, scope, summary, and description fields.](/files/N2YGobr1CcXY7Bi0ws7o)
3. The newly created task in Jira will be linked in the Aikido Issue Detail under the 'Tasks' tab (sidepanel).

![Critical task: var\_dump() exposes sensitive info, needs attention and assignment.](/files/bLGFCrC1jGet4HszJo3r)

### 2. Automated Task Creation <a href="#id-2-automated-task-creation" id="id-2-automated-task-creation"></a>

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [Jira Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings
2. Make sure to enable 'Autocreation' by clicking the toggle to On.
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will then autonomously generate Jira tickets based on these settings 🚀

***


# Linear

This one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in Linear.

Following use cases are supported :

* **Automated Ticket Creation**: Automatically create and push tickets to specified Linear projects for seamless tracking of security issues.
* **Manual Ticket Addition**: Manually add security issue tickets to Linear, ensuring targeted attention for critical vulnerabilities.

## Connecting the Aikido App to Linear <a href="#connecting-the-aikido-app-to-linear" id="connecting-the-aikido-app-to-linear"></a>

1. Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app.
2. In the 'Task Trackers' section, select 'Linear Issues'
3. A prompt will request authorization for Linear.\
   ​

   ![Authorization prompt for Linear issue-tracking; user currently unauthorized.](/files/Wljg9FGErm53iD9RQTwa)
4. Login into your Linear account
5. Grant Aikido permission to access your Linear workspace

   ![Aikido Security requests access to manage and comment on issues in your Linear workspace.](/files/rOLDvUgnPXMeL5gS3zCt)
6. Once authorized, Aikido is successfully connected to Linear, enhancing your task management capabilities 🚀

## ​Options for Task Creation in Linear via Aikido <a href="#options-for-task-creation-in-linear-via-aikido" id="options-for-task-creation-in-linear-via-aikido"></a>

There are two different options to create new tasks from Aikido into Linear.

1. Manually create tasks from the Aikido interface
2. Automatically create new tasks via Aikido's auto creation functionality.

### 1. Manual Task Creation <a href="#id-1-manual-task-creation" id="id-1-manual-task-creation"></a>

1. Hover over any issue in your feed and click the ***+*** in the **assign column.**\
   ​

   ![Task management interface showing the "Assignee" column with add and options buttons.](/files/qHdYxduZ8eHuhsF9A0fa)

   Alternatively, you can click the triple dots in the last columns to open up the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.\
   ​

   ![Dropdown menu offering task creation and additional action options.](/files/ksHpznbFtFyrXO7rXIga)
2. Fill in the required details in the popup modal.\
   ​

   ![Task creation form for reporting a critical Content Security Policy issue in Aikido.](/files/CiIwsZ8vVnqmLmlAi3CS)
3. The newly created task in Linear will be linked in the Aikido Issue Detail under the 'Tasks' tab (sidepanel).

![Critical task: CSP header missing, issue unassigned and currently open for resolution.](/files/LD2ClfdCwQmZlcxmKdEg)

### 2. Automated Task Creation <a href="#id-2-automated-task-creation" id="id-2-automated-task-creation"></a>

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [Linear Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings
2. Select '**Change auto creation**'
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will then autonomously generate Linear tickets based on these settings 🚀

***


# ClickUp

This one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in ClickUp.

Following use cases are supported :

* **Automated Ticket Creation**: Automatically create and push tickets to specified ClickUp projects for seamless tracking of security issues.
* **Manual Ticket Addition**: Manually add security issue tickets to ClickUp, ensuring targeted attention for critical vulnerabilities.

## Connecting the Aikido App to ClickUp <a href="#connecting-the-aikido-app-to-clickup" id="connecting-the-aikido-app-to-clickup"></a>

1. Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app.
2. In the 'Task Trackers' section, select 'ClickUp'
3. A prompt will request authorization for ClickUp.\
   ​

   ![ClickUp authorization prompt for issue-tracking; user currently unauthorized.](/files/dR9r8jASq8C3Sdarn28I)
4. Login into your ClickUp account
5. Grant Aikido permission to access your ClickUp workspace

   ![ClickUp workspace selection screen for connecting with Aikido Security integration.](/files/oNyu4EUD3ridXdiNskvx)
6. Once authorized, Aikido is successfully connected to ClickUp, enhancing your task management capabilities 🚀

![Map repositories to ClickUp projects and enable automatic task creation with Aikido.](/files/IurGnCQnMrOcNxRX9V0C)

## ​Options for Task Creation in ClickUp via Aikido <a href="#options-for-task-creation-in-clickup-via-aikido" id="options-for-task-creation-in-clickup-via-aikido"></a>

There are two different options to create new tasks from Aikido into ClickUp.

1. Manually create tasks from the Aikido interface
2. Automatically create new tasks via Aikido's auto creation functionality.

## 1. Manual Task Creation <a href="#id-1-manual-task-creation" id="id-1-manual-task-creation"></a>

1. Hover over any issue in your feed and click the ***+*** in the **assignee column.**\
   ​

   ![Assignee section with options to add or manage task assignments.](/files/qHdYxduZ8eHuhsF9A0fa)

   Alternatively, you can click the triple dots in the last columns to open up the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.\
   ​

   ![Action menu with options: create task, snooze, ignore, copy link, adjust severity.](/files/zvs68TcOu3zZ4fFdHaRf)
2. Fill in the required details in the popup modal.\
   ​

   ![ClickUp task creation form for reporting high-severity XSS vulnerability findings.](/files/FSBd55gWZvzrcZDTrRLJ)
3. The newly created task in ClickUp will be linked in the Aikido Issue Detail under the 'Tasks' tab (sidepanel).

![Task warning about high-risk XSS attacks from unescaped input, labeled as open.](/files/O7KizEctPUMALLWJ5GdF)

## 2. Automated Task Creation <a href="#id-2-automated-task-creation" id="id-2-automated-task-creation"></a>

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [ClickUp Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings
2. Make sure to enable '**Autocreation**' by clicking the toggle to **On.**
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will then autonomously generate ClickUp tickets based on these settings 🚀

***


# Azure DevOps Boards

This one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in Azure DevOps Boards.

Following use cases are supported :

* **Automated Ticket Creation**: Automatically create and push tickets to specified Boards projects for seamless tracking of security issues.
* **Manual Ticket Addition**: Manually add security issue tickets to Boards, ensuring targeted attention for critical vulnerabilities.

## Connecting the Aikido App to Boards <a href="#connecting-the-aikido-app-to-boards" id="connecting-the-aikido-app-to-boards"></a>

1. Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app.
2. In the 'Task Trackers' section, select 'Azure DevOps Boards'\
   A modal will request some more information to authenticate:

   * **UserID**​: this is your **email**
   * **Access Token**: Can be found inside Azure DevOps. As scope, under '**Work Items**', you can select '**Read & write**'.
   * **Organisation** ***Name*****:** name of the organisation, can be found in the URL <mark style="color:red;">Make sure to include the organisation name ONLY, without the prefix of the url https\://...</mark>\ <br>

   ![Azure DevOps integration setup screen prompting for user ID, token, and organization.](/files/5uJBtix5TuXlcVjk8aTm)
3. After filling in the credentials correctly, press save and Close the modal.\
   ​
4. Open the Azure DevOps Boards Integration page to manage the auto creation settings.\
   ​

   ![Azure DevOps Boards integration setup: map repos, enable autocreation, set default task type.](/files/XVF82W4q011sAyd0GjGZ)

## Options for Task Creation in Azure DevOps Boards via Aikido <a href="#options-for-task-creation-in-azure-devops-boards-via-aikido" id="options-for-task-creation-in-azure-devops-boards-via-aikido"></a>

There are two different options to create new tasks from Aikido into Boards

1. Manually create tasks from the Aikido interface
2. Automatically create new tasks via Aikido's auto creation functionality.

## 1. Manual Task Creation <a href="#id-1-manual-task-creation" id="id-1-manual-task-creation"></a>

1. Hover over any issue in your feed and click the ***+*** in the **assignee column.**\
   ​

   ![Task assignment table section with add and options buttons.](/files/qHdYxduZ8eHuhsF9A0fa)

   Alternatively, you can click the triple dots in the last columns to open up the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.\
   ​

   ![Actions dropdown menu with options for task management and severity adjustment.](/files/NIKZAPGURNA0QU3SzNQm)
2. Fill in the required details in the popup modal.\
   ​

   ![Azure DevOps Boards task creation form with fields for project, assignee, scope, summary, and description.](/files/BAzoxPUOKa1FGFqiuxte)

   ​
3. The newly created task in Boards will be linked in the Aikido Issue Detail under the 'Tasks' tab (sidepanel).

![High-priority task: Minor upgrade for @babel/traverse, assigned to aaron aikidodev.](/files/Kh50eAjjgWRExqLIM1Wd)

## 2. Automated Task Creation <a href="#id-2-automated-task-creation" id="id-2-automated-task-creation"></a>

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [Azure DevOps Boards Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings page
2. Select '**Change auto creation**'
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will then autonomously generate Boards tickets based on these settings 🚀

***


# GitHub Issues

This one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in GitHub Issues

Following use cases are supported :

* **Manual Ticket Addition**: Manually sync security issue tickets to GitHub Issues.
* **Automated Ticket Creation**: Automatically create and push tickets to specified GitHub Issue projects/repos.

{% hint style="warning" %}
All issues will be automatically created in the respective repo. If you wish to disable this functionality, contact us.
{% endhint %}

{% hint style="info" %}
This integration is for GitHub.com. If you are on a GitHub Enterprise Cloud with data residency tenant (`SUBDOMAIN.ghe.com`), use the [GitHub Enterprise Cloud Issues](/getting-started/task-management-systems/all-supported-task-trackers/github-enterprise-cloud-issues) integration instead.
{% endhint %}

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* GitHub account needs to be an organisation account
* Issues need to be enabled inside GitHub

### Connecting the Aikido App to GitHub Issues <a href="#connecting-the-aikido-app-to-github-issues" id="connecting-the-aikido-app-to-github-issues"></a>

1. Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app.
2. In the 'Task Trackers' section, select 'GitHub Issues'
3. **Install the Issues App inside your organisation** ([Install Link](https://github.com/apps/aikido-issues/installations/new)). This is needed in order to select your organisation.\
   ​

   <img src="/files/TvGOXeB7d0Y9KpkXhGp8" alt="GitHub issue-tracking integration setup requires authorization and organization configuration." width="375">
4. Select your organisation and repos\
   ​

   ![Aikido Issues installation prompt with user selection interface.](/files/qYHPszZRFA0AAAwadpNg)
5. When installed succesfully, you will get a notification on top of the page in GitHub. **Return to Aikido.**\
   ​

   ![Notification confirming "Aikido Issues" was updated for the specified user account.](/files/weUte9OGkBxm3EB9e13H)
6. **Select your organisation** in the modal.\
   ​

   <img src="/files/SbNln8zYwcMIinbOp0d0" alt="Dropdown menu for selecting an organization in settings." width="375">
7. **Click Save.** The status will now change to **Connected.**

   <img src="/files/T5V6NisfCP0Lu7z7nYpm" alt="GitHub issue-tracking integration successfully connected and ready for use." width="375">
8. Close the modal & open the GitHub Issues Integration page. By default all issues will be synced to the 'Default Repo'. **Contact us** if you'd like to have autosyncing issues to the respective repo.

![](/files/25o9nQosBfPUXd77lqyz)

You can set a Default Label that will be send for all Aikido Issues. These will be synced and appear in GitHub.​\
​

![Open GitHub issue for minor aws/aws-sdk-php upgrade, labeled low priority security fix.](/files/wNkzUKFYm9eqSDNd8M7K)

#### Options for Task Creation in GitHub Issues via Aikido <a href="#options-for-task-creation-in-github-issues-via-aikido" id="options-for-task-creation-in-github-issues-via-aikido"></a>

There are two different options to create new tasks from Aikido into GitHub Issues

1. Manually create tasks from the Aikido interface
2. Automatically create new tasks via Aikido's auto creation functionality.

### Manual Task Creation <a href="#manual-task-creation" id="manual-task-creation"></a>

1. Hover over any issue in your feed and click the ***+*** in the **assignee column.**\
   ​

   <img src="/files/qHdYxduZ8eHuhsF9A0fa" alt="Task management interface showing &#x22;Assignee&#x22; column with add and options buttons." width="327">

   Alternatively, you can click the triple dots in the last columns to open up the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.\
   ​

   <img src="/files/1mYYMqMMleKdLNX3PTM1" alt="Dropdown menu with task management actions: create, snooze, ignore, copy link, adjust severity." width="221">
2. Fill in the required details in the popup modal.\
   ​

   <img src="/files/Qc9USsYja6WN8r5pYje9" alt="Form for creating a new GitHub issue task with project, assignee, and description fields." width="375">

   ​
3. The newly created task in GitHub Issues will be linked in the Aikido Issue Detail under the 'Tasks' tab (sidepanel).

![Task management dashboard showing a low-priority AWS SDK PHP upgrade task.](/files/QjRcXm9WBtM3zL96Ldsg)

### Automated Task Creation <a href="#automated-task-creation" id="automated-task-creation"></a>

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [GitHub Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings page
2. Make sure to enable '**Autocreation**' by clicking the toggle to **On.**
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will then autonomously generate GitHub Issues based on these settings 🚀

### Automatically Close Issues in GitHub

Aikido can automatically close linked GitHub issues once the related vulnerability is resolved in Aikido, for example after a successful scan no longer reports it, or when you manually mark it solved. The GitHub issue is only closed when there are no remaining open or snoozed Aikido issues for that link (ignored issues do not block closing). You need a GitHub issue linked to the Aikido finding for this to apply.

<figure><img src="/files/7wYF8NqbRYYbSVTdKFum" alt=""><figcaption></figcaption></figure>

***


# GitHub Enterprise Cloud Issues

This one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in a GitHub Enterprise Cloud **data residency** tenant (`SUBDOMAIN.ghe.com`).

Following use cases are supported:

* **Manual Ticket Addition**: Manually sync security issue tickets to GitHub Issues.
* **Automated Ticket Creation**: Automatically create and push tickets to specified GitHub Issue repos.

{% hint style="info" %}
This integration is for **GitHub Enterprise Cloud with data residency** tenants (`SUBDOMAIN.ghe.com`). If you are on GitHub.com, use the [GitHub Issues](/getting-started/task-management-systems/all-supported-task-trackers/github-issues) integration instead.
{% endhint %}

Unlike GitHub.com, GitHub Enterprise Cloud data-residency tenants require you to register your own OAuth app directly on your tenant. Setup therefore has two parts: first register the OAuth app on your tenant, then connect it in Aikido.

{% embed url="<https://www.youtube.com/watch?v=6lvyiBRTctU>" %}

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* A GitHub Enterprise Cloud data-residency tenant (`SUBDOMAIN.ghe.com`).
* You must be an **owner** of the GitHub organization you want to connect. Only one organization is supported per connection.
* Permission to register an OAuth app on your tenant.
* Issues need to be enabled inside GitHub.

### Step 1: Register an OAuth App on Your Tenant

1. Log in to your GitHub Enterprise Cloud tenant at `https://SUBDOMAIN.ghe.com` (e.g. `https://octocorp.ghe.com`).
2. Click your **profile picture** in the top-right corner and select **Settings**.
3. In the left sidebar, scroll to **Developer settings**.
4. Click **OAuth Apps**, then click **New OAuth App**.
5. Fill in the application details:
   * **Application name**: a meaningful name (e.g. `Aikido integration`).
   * **Homepage URL**: your company's website or product URL (e.g. `https://aikido.dev`).
   * **Authorization callback URL**: set this to `https://unify.apideck.com/vault/callback`.
6. Click **Register application**.

### Step 2: Copy the Client ID and Client Secret

1. On the app's settings page, copy the **Client ID**.
2. Click **Generate a new client secret** and copy the value immediately.

{% hint style="warning" %}
Copy the client secret right away. GitHub only displays it once and you won't be able to see it again.
{% endhint %}

### Step 3: Connect the Aikido App to GitHub Enterprise Cloud

1. Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app.
2. In the 'Task Trackers' section, select **GitHub Enterprise Cloud issues**.
3. In the modal, fill in:
   * **Tenant Subdomain**: the `SUBDOMAIN` part of your `SUBDOMAIN.ghe.com` tenant.
   * **Client ID**: the Client ID from Step 2.
   * **Client Secret**: the Client Secret from Step 2.
4. Click **Save**. The status will show as **Unauthorized**.
5. Click **Authorize**. You will be redirected to a GitHub authorization screen. Review the access and click **Authorize**.
6. Back in the modal, open the **Organization** dropdown and select your organization. The dropdown is populated after authorizing, and you must be an **owner** of the organization.
7. Click **Save**. The status will now change to **Connected**.
8. Close the modal & open the GitHub Enterprise Cloud Issues Integration page. By default all issues will be synced to the 'Default Repo'. Use **Map To GitHub Repos** to map individual repositories.

You can set a Default Label that will be sent for all Aikido Issues. These will be synced and appear in GitHub.

#### Options for Task Creation in GitHub Enterprise Cloud via Aikido

There are two different options to create new tasks from Aikido into GitHub Issues

1. Manually create tasks from the Aikido interface
2. Automatically create new tasks via Aikido's auto creation functionality.

### Manual Task Creation

1. Hover over any issue in your feed and click the ***+*** in the **assignee column.** Alternatively, click the triple dots in the last column to open the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.
2. Fill in the required details in the popup modal.
3. The newly created task in GitHub Issues will be linked in the Aikido Issue Detail under the 'Tasks' tab (sidepanel).

### Automated Task Creation

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [GitHub Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings page
2. Make sure to enable '**Autocreation**' by clicking the toggle to **On.**
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will then autonomously generate GitHub Issues based on these settings 🚀

### Automatically Close Issues in GitHub

Aikido can automatically close linked GitHub issues once the related vulnerability is resolved in Aikido, for example after a successful scan no longer reports it, or when you manually mark it solved. The GitHub issue is only closed when there are no remaining open or snoozed Aikido issues for that link (ignored issues do not block closing). You need a GitHub issue linked to the Aikido finding for this to apply.


# GitLab Issues

Aikido can connect to GitLab so that you can create issues for security findings found through Aikido. For each of the findings in the 'Feed' of Aikido, a GitLab issue can be created, and linked.

You will be able to follow along in the Feed, to whom the ticket is assigned.

### 1. Set up integration <a href="#id-1-set-up-integration" id="id-1-set-up-integration"></a>

Go to <https://app.aikido.dev/settings/integrations> and scroll down to the 'Task trackers' section.

![GitLab integration for tracking and managing security issues; connect to create GitLab issues.](/files/qAxCbJsSNDR4jTMLYNxZ)

Click on 'Connect'

![GitLab authorization prompt for issue-tracking, awaiting user permission to proceed.](/files/I3HbgedK2aeG0AvU9lE4)

Click on 'Authorize GitLab'

![Authorization prompt for Aikido Issues to access GitLab user's API and account data.](/files/75jzlBZ8j7Tlevgaepnm)

And select a 'Group' for which you want to activate the integration.

Click 'Save' and you're connected.

![GitLab issue-tracking integration status: Connected.](/files/es3njIVnvl5qkrMxXDkt)

### 2. Create a GitLab issue for a finding, inside Aikido <a href="#id-2-create-a-gitlab-issue-for-a-finding-inside-aikido" id="id-2-create-a-gitlab-issue-for-a-finding-inside-aikido"></a>

Go to the [Feed](https://app.aikido.dev/queue), and go to the security finding of choice. In the column 'Assignee', you will find the ability to assign a GitLab Issue to someone.

![Assign a new task owner by clicking the plus icon.](/files/7mrVyVX36Oo5SDzM7xPh)

When you click on it, a popup will open.

![Task creation form for assigning and summarizing a security fix in GitLab.](/files/Vz8afWCMfuCNhWZ8XSYV)

When creating the Issue Task, this will be made clear in the UI of Aikido

![Open task assigned to user "roelanddel" displayed in a project management dashboard.](/files/21hmAPgKpiooyDsYd66l)

You're done!

### &#x20;<a href="#set-up-gitlab-issues-integration" id="set-up-gitlab-issues-integration"></a>

***


# GitLab Issues Self-Managed

Aikido can connect to GitLab Self-Managed (On-prem) so that you can create issues for security findings found through Aikido. For each of the findings in the 'Feed' of Aikido, a GitLab issue can be created, and linked.

You will be able to follow along in the Feed, to whom the ticket is assigned.

### 1. Set up integration <a href="#id-1-set-up-integration" id="id-1-set-up-integration"></a>

**Step 1.** Go to <https://app.aikido.dev/settings/integrations> and scroll down to the 'Task trackers' section.

<figure><img src="/files/eoqjdnfBvYv70tJZayMM" alt="" width="375"><figcaption></figcaption></figure>

**Step 2.** Click on 'Connect' and fill in the serve base URL, the PAT and Group ID

<figure><img src="/files/Q3V5m062OLgRoO45KQW0" alt="" width="373"><figcaption></figcaption></figure>

**Step 3.** Click 'Save' and you're connected. Close the modal and you will redirected to the settings page.

### 2. Create a GitLab issue for a finding, inside Aikido <a href="#id-2-create-a-gitlab-issue-for-a-finding-inside-aikido" id="id-2-create-a-gitlab-issue-for-a-finding-inside-aikido"></a>

Go to the [Feed](https://app.aikido.dev/queue), and go to the security finding of choice. In the column 'Assignee', you will find the ability to assign a GitLab Issue to someone.

![Assign a new task owner by clicking the plus icon.](/files/7mrVyVX36Oo5SDzM7xPh)

When you click on it, a popup will open.

![Task creation form for assigning and summarizing a security fix in GitLab.](/files/Vz8afWCMfuCNhWZ8XSYV)

When creating the Issue Task, this will be made clear in the UI of Aikido

![Open task assigned to user "roelanddel" displayed in a project management dashboard.](/files/21hmAPgKpiooyDsYd66l)

You're done!

***


# JetBrains YouTrack

This one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in YouTrack.

Following use cases are supported :

* **Automated Ticket Creation**: Automatically create and push tickets to specified YouTrack projects for seamless tracking of security issues.
* **Manual Ticket Addition**: Manually add security issue tickets to YouTrack, ensuring targeted attention for critical vulnerabilities.

## Connecting the Aikido App to YouTrack <a href="#connecting-the-aikido-app-to-youtrack" id="connecting-the-aikido-app-to-youtrack"></a>

1. Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app.
2. In the 'Task Trackers' section, select 'YouTrack'\
   A modal will request the **Service URL** (of your YouTrack space) and the **Permanent Token**. The permanent token can be generated inside Profile -> Account Security in YouTrack.\
   ​

   ![JetBrains YouTrack integration setup screen requiring configuration for Service URL and token.](/files/nR8yBRFDPq7Ds5qRFEhj)
3. When you have filled in the credentials correctly, the 'Connected' status will appear.\
   ​

   ![JetBrains YouTrack issue-tracking integration is successfully connected.](/files/PI4L18HBnaT58d92RvLL)
4. Close the modal & open the YouTrack Integration page.\
   ​

![Map Git repositories to YouTrack projects and enable automatic task creation.](/files/sXRyzFb9HfkYAefHN4zN)

## Options for Task Creation in YouTrack via Aikido <a href="#options-for-task-creation-in-youtrack-via-aikido" id="options-for-task-creation-in-youtrack-via-aikido"></a>

There are two different options to create new tasks from Aikido into YouTrack.

1. Manually create tasks from the Aikido interface
2. Automatically create new tasks via Aikido's auto creation functionality.

### 1. Manual Task Creation <a href="#id-1-manual-task-creation" id="id-1-manual-task-creation"></a>

1. Hover over any issue in your feed and click the ***+*** in the **assignee column.**\
   ​

   ![Task assignment table section with options to add or manage assignees.](/files/qHdYxduZ8eHuhsF9A0fa)

   Alternatively, you can click the triple dots in the last columns to open up the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.\
   ​

   ![Action menu with options: create task, snooze, ignore, copy link, adjust severity.](/files/dmoFPYsMahfGkaO0NHiV)

   ​
2. Fill in the required details in the popup modal.\
   ​

   ![Form for creating a security task in JetBrains YouTrack with summary and details.](/files/suUfg9cnlmmDTE2ZARzq)
3. The newly created task in YouTrack will be linked in the Aikido Issue Detail under the 'Tasks' tab (sidepanel).\
   ​

   ![Security alert: HSTS header missing, high severity, reported by admin.](/files/SzC6c0VnjA64HsJ4vAyS)

### 2. Automated Task Creation <a href="#id-2-automated-task-creation" id="id-2-automated-task-creation"></a>

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [YouTrack Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings page
2. Make sure to enable '**Autocreation**' by clicking the toggle to **On.**
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will then autonomously generate YouTrack tickets based on these settings 🚀\
   ​


# Asana

This one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in Asana.

Following use cases are supported :

* **Automated Ticket Creation**: Automatically create and push tickets to specified Asana projects for seamless tracking of security issues.
* **Manual Ticket Addition**: Manually add security issue tickets to Asana, ensuring targeted attention for critical vulnerabilities.

## Connecting the Aikido App to Asana <a href="#connecting-the-aikido-app-to-asana" id="connecting-the-aikido-app-to-asana"></a>

1. Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app.
2. In the 'Task Trackers' section, select 'Asana'
3. A prompt will request authorization for Asana.

   ![Asana integration unauthorized; prompt to authorize access for issue-tracking.](/files/pcf8ILgUDhsyopGshTSp)

   ​
4. Login into your Asana account
5. Grant Aikido permission to access your Asana workspace

   ![Asana permission request for Aikido Security to access and modify your account data.](/files/5Y7BJuEdoVEH80mhAdzc)
6. Once authorized, Aikido is successfully connected to Asana, enhancing your task management capabilities 🚀

![Configure Asana integration to map repositories and enable automatic task creation.](/files/uZJjKybVuWPr42J7bHsj)

## ​Options for Task Creation in Asana via Aikido <a href="#options-for-task-creation-in-asana-via-aikido" id="options-for-task-creation-in-asana-via-aikido"></a>

There are two different options to create new tasks from Aikido into Asana.

1. Manually create tasks from the Aikido interface
2. Automatically create new tasks via Aikido's auto creation functionality.

## 1. Manual Task Creation <a href="#id-1-manual-task-creation" id="id-1-manual-task-creation"></a>

1. Hover over any issue in your feed and click the ***+*** in the **assignee column.**\
   ​

   ![Task assignee section with add and options buttons visible.](/files/qHdYxduZ8eHuhsF9A0fa)

   Alternatively, you can click the triple dots in the last columns to open up the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.

   ![Action menu with options to manage, snooze, ignore, share, or adjust task severity.](/files/Cxt8PY3L6Dcjjd8FAiuN)

   ​
2. Fill in the required details in the popup modal.\
   ​

   ![Create a ClickUp task reporting a high-severity XSS vulnerability with details and link.](/files/FSBd55gWZvzrcZDTrRLJ)
3. The newly created task in Asana will be linked in the Aikido Issue Detail under the 'Tasks' tab (sidepanel).

![High-priority task warning: Unescaped input may cause XSS attacks.](/files/O7KizEctPUMALLWJ5GdF)

## 2. Automated Task Creation <a href="#id-2-automated-task-creation" id="id-2-automated-task-creation"></a>

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [Asana Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings
2. Make sure to enable '**Autocreation**' by clicking the toggle to **On.**
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will then autonomously generate Asana tickets based on these settings 🚀


# Monday.com

This one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in the Monday app.

Following use cases are supported :

* **Automated Ticket Creation**: Automatically create and push tickets to specified Monday.com projects for seamless tracking of security issues.
* **Manual Ticket Addition**: Manually add security issue tickets to Monday.com, ensuring targeted attention for critical vulnerabilities.

## Connecting the Aikido App to Monday.com <a href="#connecting-the-aikido-app-to-mondaycom" id="connecting-the-aikido-app-to-mondaycom"></a>

1. Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app.
2. In the 'Task Trackers' section, select 'Monday.com'\
   A modal will request an **API Key** (of your Monday workspace). This API key can be found in Administration -> Connections -> API.\
   ​

   ![Monday.com integration setup screen requesting API key for issue tracking configuration.](/files/86YJOPsMe30JZuDy02Ip)
3. When you have filled in the credentials correctly, the 'Connected' status will appear.\
   ​

   ![Monday.com issue-tracking integration successfully connected.](/files/HJz1NtcjkaEKF8ChlNFF)

Close the modal & open the Monday.com Integration page.

![Map repositories to monday.com projects and enable automated task creation with Aikido.](/files/Z7EKNlTZCCXFsLRPiSgY)

## Options for Task Creation in Monday.com via Aikido <a href="#options-for-task-creation-in-mondaycom-via-aikido" id="options-for-task-creation-in-mondaycom-via-aikido"></a>

There are two different options to create new tasks from Aikido into Monday.com.

1. Manually create tasks from the Aikido interface
2. Automatically create new tasks via Aikido's auto creation functionality.

## 1. Manual Task Creation <a href="#id-1-manual-task-creation" id="id-1-manual-task-creation"></a>

1. Hover over any issue in your feed and click the ***+*** in the **assignee column.**\
   ​

   ![Task assignment interface with options to add or manage an assignee.](/files/qHdYxduZ8eHuhsF9A0fa)

   Alternatively, you can click the triple dots in the last columns to open up the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.\
   ​

   ![Action menu with options to create task, snooze, ignore, copy link, or adjust severity.](/files/CgOR3Z2zxA1mFB8n0ttJ)
2. Fill in the required details in the popup modal.\
   ​

   ![Task creation form for project management in monday.com, detailing a critical upgrade issue.](/files/HvIB0OBCcT9Paf0zdqyJ)

   ​
3. The newly created task in Monday.com will be linked in the Aikido Issue Detail under the 'Tasks' tab (sidepanel).

![Critical Log4j upgrade task assigned to Maarten De Schuymer.](/files/4qGNWxrjWtMF3zerWMtM)

## 2. Automated Task Creation <a href="#id-2-automated-task-creation" id="id-2-automated-task-creation"></a>

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [Monday.com Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings page
2. Select '**Change auto creation**'
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will then autonomously generate Monday.com tickets based on these settings 🚀

***

***


# Shortcut

This one-time setup *per workspace* allows everyone in your Aikido organization to create issues directly in Shortcut.

Following use cases are supported :

* **Automated Ticket Creation**: Automatically create and push tickets to specified Shortcut projects for seamless tracking of security issues.
* **Manual Ticket Addition**: Manually add security issue tickets to Shortcut, ensuring targeted attention for critical vulnerabilities.

## Connecting the Aikido App to Shortcut <a href="#connecting-the-aikido-app-to-shortcut" id="connecting-the-aikido-app-to-shortcut"></a>

1. Navigate to [Integration Settings](https://app.aikido.dev/settings/integrations) within the Aikido app.
2. In the 'Task Trackers' section, select 'Shortcut'
3. A prompt will request authorization for Shortcut.\
   ​

   ![Shortcut issue-tracking setup screen prompting for API key configuration.](/files/0k5kPPVmQ4zg1pDYBg3B)

   ​
4. Login into your Shortcut account
5. Grant Aikido permission to access your Shortcut workspace
6. Once authorized, Aikido is successfully connected to Shortcut, enhancing your task management capabilities 🚀

![Map repositories to Shortcut teams and enable or disable task autocreation.](/files/KNzcH11n4hIqRVCT0NIj)

## Options for Task Creation in Shortcut via Aikido <a href="#options-for-task-creation-in-shortcut-via-aikido" id="options-for-task-creation-in-shortcut-via-aikido"></a>

There are two different options to create new tasks from Aikido into Shortcut.

1. Manually create tasks from the Aikido interface
2. Automatically create new tasks via Aikido's auto creation functionality.

## 1. Manual Task Creation <a href="#id-1-manual-task-creation" id="id-1-manual-task-creation"></a>

1. Hover over any issue in your feed and click the ***+*** in the **assignee column.**\
   ​

   ![Task table section showing "Assignee" field with add and options buttons.](/files/qHdYxduZ8eHuhsF9A0fa)

   Alternatively, you can click the triple dots in the last columns to open up the action menu. If you have grouped issues, the triple dot action menu is available on every subissue.\
   ​

   ![Dropdown menu with task management actions: create, snooze, ignore, copy link, adjust severity.](/files/T0zeHQzfCP76s5wAx1Hs)
2. Fill in the required details in the popup modal.\
   ​
3. The newly created task in ClickUp will be linked in the Aikido Issue Detail under the 'Tasks' tab (sidepanel).

![High-priority tzinfo upgrade task, currently unassigned and open for action.](/files/rpyXzz2BNLZ4zXdyBLrx)

## 2. Automated Task Creation <a href="#id-2-automated-task-creation" id="id-2-automated-task-creation"></a>

{% hint style="info" %}
Aikido will automatically create tasks **every hour in bulk.** There is at the moment no option to trigger this manually.
{% endhint %}

1. Go to the [Shortcut Integration](https://app.aikido.dev/settings/integrations/tasktracker) settings
2. Select '**Change auto creation**'
3. Define the criteria for automatic task creation.

You can configure all of these settings in the autocreation modal:

* **On/Off:** Enable or disable autocreation. When off, the threshold is effectively set to `None`.
* **Severity threshold:** Create tickets for issues at `Critical`, `High`, `Medium`, or `Low` and above. For example, `High` creates tickets for `High` and `Critical`.
* **Issue types:** Create tickets for all issue types, or limit them to specific types like `SCA`, `SAST`, `Secrets`, `Cloud`, `IaC`, `Malware`, or `License`.
* **Daily limit:** Set the maximum number of tickets created per day. The default is `25`. Some plans support higher limits.
* **Ticket creation mode:** Create one ticket per issue group, or create separate tickets per location or scope. Per-location mode can create more tickets.
* **Scope:** Available only in per-location mode. Target all repos or clouds, only mapped repos or teams, or specific repos or clouds with include and exclude lists.

<figure><img src="/files/j8Ks4x8224kIfTgKPXEk" alt=""><figcaption></figcaption></figure>

4. Aikido will then autonomously generate Shortcut tickets based on these settings 🚀

***


# Advanced Functionalities


# Link Existing Tasks

### Introduction <a href="#introduction" id="introduction"></a>

Aikido supports the linking of existing Task Tracker (e.g. Jira, Clickup) tickets to Aikido issues, crucial for integrating already flagged security concerns in Jira that are not yet connected to Aikido.

> Note: This functionality is only available for **Jira Cloud & Data Center, Linear, ClickUp** and **AzureDevops Boards integrations**. Contact us if you are using another integration and would love to see this functionality available too!

### How to Link an Existing Task <a href="#how-to-link-an-existing-task" id="how-to-link-an-existing-task"></a>

*Following example is for Jira. Functionality is similar for other task trackers.*

**Step 1:** Click on '**Add Task**'. For issue groups: located at the top of the sidebar or in the action menu. For subissues: triple dots menu on subissue level.\
​

![Task management interfaces showing action menus for workflow and issue handling.](/files/AEZHx4YunCPPF32PTg8x)

**Step 2:** Select 'Link to Existing Jira Ticket' at the top of the modal.

**Step 3**.Select your project and search for the name of the existing Jira ticket. You can also just paste the URL into the search bar.\
​\
​

![Interface for linking an existing Jira task by selecting project and task details.](/files/fJbAil2WYuOFKERyVK7c)

​**Step 4:** Click 'Link Jira Task' to finalize the linking process.\
​

**Step 5:** Once linked, Aikido will automatically sync any updates in assignee and status from Jira, ensuring both platforms are up to date.

***


# Smart Issue Routing: Map Teams or Repositories to Projects in Your Task Manager

## Introduction <a href="#introduction" id="introduction"></a>

Mapping your Aikido teams or repositories to projects within your Task Manager ensures that automated tasks are correctly routed to the appropriate project.

## Use Case <a href="#main-use-case" id="main-use-case"></a>

Often, you have different projects in your task tracker that map to different Aikido teams. This is helpful when you have certain teams that combine certain repos, cloud, containers and need those issues directed to a certain task tracker project.

### Step-by-Step Guide <a href="#step-by-step-guide" id="step-by-step-guide"></a>

**Step 1**: Navigate to the [**Task Manager Settings**](https://app.aikido.dev/settings/integrations/tasktracker)

**Step 2**: Select **Jira Project Mapping**.

<figure><img src="/files/vHvUchSNsNPd8EMoJ43z" alt=""><figcaption></figcaption></figure>

**Step 3: Map** your Task Tracker Projects to your Aikido Teams or Repositories

<figure><img src="/files/lvMaErx4xjx12mYRUsuw" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**Important**: Don't forget to set a **default project**. This project acts as a fallback for any teams or repositories not explicitly mapped, ensuring no task goes unassigned.
{% endhint %}

**Extra notes**

* This option is not included in GitHub Issues / GitLab Issues.
* For Linear, we do not map the projects, but the Teams

***


# Auto-Close Linear Tasks When Aikido Issues Are Resolved / Ignored

### Use Case

When Aikido marks issues as **resolved** or **ignored**, you can sync this status with Linear to keep tasks automatically updated.

{% hint style="info" %}
Aikido checks every **8 hours** to detect and update resolved issues. Updates are **not instantaneous**, so some delay is expected between resolution and task closure.
{% endhint %}

### **Setup**

**Step 1.** Go to your [**Task Tracker Integration Settings**](https://app.aikido.dev/settings/integrations/tasktracker) in the Aikido dashboard.

**Step 2.** In the **Advanced** section, enable **Autoclose Tasks**.<br>

<figure><img src="/files/C1AUQZUN6yj8U6AroxOT" alt=""><figcaption></figcaption></figure>

**Step 3.** Set the corresponding **completion status** that you are using in Linear (e.g., “Done”).

<figure><img src="/files/vaquDuunTmE2Yj2BxRFg" alt=""><figcaption></figcaption></figure>

**Step 4**. Hit Save in the top right

### **Troubleshoot**

* For **Linear**: if tasks don't move to “Done”, you may need to reauthorise the integration.

  * Go to **Manage Integration**
  * Click the **three dots**
  * Select **Re-authorize**

  <figure><img src="/files/T3dY2sKJMxV5ZEtOS4c3" alt="" width="375"><figcaption></figcaption></figure>


# Auto-Close Jira Tasks When Aikido Issues Are Resolved / Ignored

### Use Case

When Aikido marks issues as **resolved** or **ignored**, you can sync this status with Jira to keep tasks automatically updated.

{% hint style="info" %}
Aikido checks every **8 hours** to detect and update resolved issues. Updates are **not instantaneous**, so some delay is expected between resolution and task closure.
{% endhint %}

### **Setup**

**Step 1.** Go to your [**Task Tracker Integration Settings**](https://app.aikido.dev/settings/integrations/tasktracker) in the Aikido dashboard.

**Step 2.** In the **Advanced** section, enable **Autoclose Tasks**.<br>

<figure><img src="/files/QgUEUzhiRCeB1yOCXSlN" alt=""><figcaption></figcaption></figure>

**Step 3.** Set the corresponding **completion status** that you are using in Jira (e.g., “Done”).

<figure><img src="/files/rBT1mDRenzU07eRkGDxj" alt=""><figcaption></figcaption></figure>

**Step 4**. Hit Save Settings in the top right


# Troubleshoot Jira Task Creation: Set Up Default Issue Types

Task creation inside Aikido can fail, **particularly when the issue types that have been setup in Jira include required fields that are not available in Aikido**. The fix is to create a new issue type in Jira without any required fields, and inform Aikido about this new name.

### 1. Create a new Issue Type in JIRA <a href="#id-1-create-a-new-issue-type-in-jira" id="id-1-create-a-new-issue-type-in-jira"></a>

**Step 1:** Log in to JIRA and go to Settings > Issues > **Issue Types**

**Step 2: Add a New Issue Type**

Click *Add Issue Type*. Name it something indicative like **Security Fix**, and ensure it does not mandate any field that previously hindered Aikido task creation. This issue type must not include any required fields that Aikido cannot sync.

### 2. Configuring Aikido to Use the New Issue Type <a href="#id-2-configuring-aikido-to-use-the-new-issue-type" id="id-2-configuring-aikido-to-use-the-new-issue-type"></a>

**Step 1:** Go to [**JIRA Integration Settings**](https://app.aikido.dev/settings/integrations/tasktracker) in Aikido

**Step 2: Input the New Issue Type Name** in the default task type entry.

Enter the name of the issue type you created in JIRA (e.g., Security Fix). This links Aikido's ticket creation process with the new JIRA issue type.

![Set a default task type to "Task 2" for automatic task creation.](/files/BGmcQSbc7dSJjxZSAFux)

***


# Map Aikido Data to Jira Custom Fields

#### **Why use custom field mapping:**

* **Required fields:** If your Jira issue types have required custom fields, Aikido cannot create tickets without mapping values to them
* **Richer ticket data:** Send Aikido data like severity, SLA dates, and teams directly into Jira fields
* **Jira automations:** Use mapped field values to trigger workflows, route tickets, or set priorities automatically

#### **Simple setup**

* Just enter your Jira field names exactly as they appear in Jira
* No field IDs, API lookups, or special formatting required
* For fixed values, use only the readable name as plain text

#### **Supported Jira field types:**

* Free text: `short text` `paragraph`
* Links: `URL Field`
* Selection fields: `select list (single choice)`
* Multi-selection fields: `select list (multiple choice)`
* Numbers: `Number field`
* Dates: `Date Picker`
* Datetimes: `Datetime Picker`

#### Configure Field Mappings

1. Go to [**Integrations** > **Jira** > **Jira Field Mapping**](https://app.aikido.dev/settings/integrations/tasktracker/fields/custom) and click **Add Field**<br>

   <figure><img src="/files/mBPQChiESGTzulLkWBVb" alt=""><figcaption></figcaption></figure>
2. Enter the Jira custom field name in the **Custom Field** input exactly as it appears in Jira
3. Enter an Aikido shortcode (e.g., `$SEVERITY`) or a fixed text value in the **Aikido Value** input<br>

   <figure><img src="/files/rXbcjQKKkAWvAaBLGGM3" alt=""><figcaption></figcaption></figure>
4. Click **Save Changes**

The **Preview** column shows what value will be sent to Jira. These can be values based on shortcodes or fixed values / free text.

#### Aikido Value: Fixed Text vs Shortcodes

**Option 1: Send Fixed Values to Jira via free text**

Enter plain text instead of a shortcode to set a constant value. Use only the readable name; you don't need Jira IDs or special formatting.

For example, entering `Security` populates that Jira field with "Security" for every ticket created from Aikido.

**Option 2: Send Aikido Values to Jira via Shortcodes**

Shortcodes are placeholders that pull data from your Aikido issues. When a Jira ticket is created, the shortcode is replaced with the actual value. You can also combine shortcodes with fixed text, such as `Issue: $TLDR` or `Detected on $FIRST_DETECTED_DATE`. Need a shortcode that's not listed? Reach out to us.

| Shortcode               | Description                                                                                                   |
| ----------------------- | ------------------------------------------------------------------------------------------------------------- |
| `$SEVERITY_SCORE`       | The numeric severity score of the vulnerability (e.g., 85)                                                    |
| `$SEVERITY`             | Severity level (Critical, High, Medium, Low)                                                                  |
| `$ASSIGNEE`             | User assigned to handle the issue in Aikido                                                                   |
| `$TLDR`                 | Summary of the issue group                                                                                    |
| `$HOW_TO_FIX`           | The how to fix description of the issue group                                                                 |
| `$FIX_TIME`             | The amount of time it takes to fix the issue group in minutes                                                 |
| `$TASK_DESCRIPTION`     | The default description generated by Aikido for this task including scope, TLDR, and how to fix               |
| `$TEAMS`                | Teams responsible for the related issues                                                                      |
| `$SCOPES_REPO`          | The scopes filtered to only include repo names related to this task. Might be empty for some grouped issues.  |
| `$SCOPES_SHORT`         | The shorter version of the scopes related to this task such as repo names, container names, cloud names, etc. |
| `$SCOPES`               | Scopes/locations related to the task (repo, container, etc)                                                   |
| `$SLA_DATE`             | SLA due date                                                                                                  |
| `$SLA_TIME`             | SLA due date as a Unix timestamp                                                                              |
| `$FIRST_DETECTED_DATE`  | Date when the issue was first detected                                                                        |
| `$FIRST_DETECTED_TIME`  | First detected date as a Unix timestamp                                                                       |
| `$AIKIDO_LINK`          | Link to the issue group in Aikido                                                                             |
| `$CWE_IDS`              | The CWE ids of the issues related to this task                                                                |
| `$CVSS`                 | The highest CVSS score of the issues related to this task                                                     |
| `$ISSUE_TYPE`           | The type of the issue related to this task                                                                    |
| `$PROGRAMMING_LANGUAGE` | The programming language of the issue related to this task                                                    |

#### Date and Datetime Fields

For Jira **date** fields, use the `YYYY-MM-DD` format (e.g., `2024-03-15`) or the `_DATE` shortcodes.

For Jira **datetime** fields, use the `_TIME` shortcodes (e.g., `$SLA_TIME`, `$FIRST_DETECTED_TIME`). These output Unix timestamps, which Aikido automatically converts to Jira's required datetime format.

#### Advanced Examples

**Link all Aikido issues to one fixed parent**

If you want every Jira ticket from Aikido to use the same parent, map the Jira **Parent** field to a fixed value. In the **Aikido Value** input, enter the Jira issue key of the parent issue, such as `SEC-123`.

<figure><img src="/files/AmZnaYwY1RqQgje3eEeH" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
The parent issue must already exist in Jira. It must also be valid for the project and issue type you use in Aikido.
{% endhint %}


# Allowing IP Addresses for Issue/Task Tracker Integrations

If you only allows specific IP addresses to access your Issue/Task Management Systems (eg Jira, Linear,..), you will have to allowlist Aikido's IP addresses so tasks can be created and managed.

Add the following IPs:

* **18.197.244.247**
* **18.156.9.3**
* **3.65.139.215**

The ports required to be opened are at least port **443** for HTTPS.

For instructions on whitelisting IP addresses with third-party providers, refer to the following resources:

* [Cloudflare WAF](https://developers.cloudflare.com/waf/custom-rules/use-cases/allow-traffic-from-ips-in-allowlist/)
  * Cloudflare Turnstile does not support allowlisting specific client IP addresses. If you need to [bypass Turnstile for Aikido scanning traffic, you must do it in your application code.](https://developers.cloudflare.com/turnstile/tutorials/conditionally-enforcing-turnstile/) We recommend bypassing only when both conditions are true:
    1. The request originates from an Aikido IP range
    2. The request includes the `aikido` User Agent in headers as described above
* [Azure WAF](https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/custom-waf-rules-overview)
* [AWS WAF](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-type-ipset-match.html).
  * For WAFs behind Application Load Balancers or CloudFront, your [WAF should check the last IP address in the `X-Forwarded-For` header](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-forwarded-ip-address.html).
* [Vercel WAF](https://vercel.com/docs/vercel-firewall/vercel-waf/custom-rules)
  * Use the ["bypass" action](https://vercel.com/docs/vercel-firewall/firewall-concepts#bypass) for trusted IPs

{% hint style="info" %}
[The IP address lists are also available as JSON arrays](https://aikido.help/ips/)
{% endhint %}


# Chat & Alerts


# Slack Notifications

## Connecting the Aikido Slack app to Slack <a href="#connecting-the-aikido-slack-app-to-slack" id="connecting-the-aikido-slack-app-to-slack"></a>

Go to [the Slack integrations settings](https://app.aikido.dev/settings/integrations/notifications/slack) inside of the Aikido app.

1. Click **"Add integration"**
2. Select **the Slack workspace** you'd like to use on the top right dropdown
3. Select **the channel** you'd like to post to from the dropdown menu
4. Click "**Allow**"

Repeat this process by clicking **"Add Channel"** in case you'd like to use different channels for different notification types.

## Adding the Aikido Slackbot to a private channel <a href="#adding-the-aikido-slackbot-to-a-private-channel" id="adding-the-aikido-slackbot-to-a-private-channel"></a>

To add the Aikido Slackbot to a private channel, you first need to invite the bot to that channel. Otherwise you're not able to select that channel. (This is so for all Slackbots)

1. **Type "@Aikido Security"** in the channel & send the message
2. You'll get a popup asking if you'd like to add Aikido to the channel
3. **Click "Add to Channel"**

![Slack prompt suggesting to add a user to a channel before messaging the whole group.](/files/TaFRE5FQKce0fyDSp5LH)

Now you should be able to find your private channel in the app.

Next, go [to Slack integration settings](https://app.aikido.dev/settings/integrations/notifications/slack) in the Aikido app.

1. **Enable the toggles** for the types of notifications you'd like to get
2. **Select the channels** you'd like the notifications to arrive in.
3. Hit "**Save**"

### Alternative method <a href="#alternative-method" id="alternative-method"></a>

Alternatively you can add the bot in the following steps:

1. Navigate to the channel you'd like to add the Slackbot to
2. Click the dropdown arrow
3. Navigate to the "Integrations" tab
4. Click "Add an App"
5. Search for "Aikido Security" and click "Add"

Now you should be able to find your private channel in the app.

![Slack channel integrations tab showing options to add workflows or apps, with buttons highlighted.](/files/JzwJhQcdrn5IqTveyqNm)

## Device Protection

{% content-ref url="/pages/c8juUG0pkeoH5JbRzfbB" %}
[Approving Install Requests](/aikido-device-protection/using-aikido-endpoint/reviewing-install-requests)
{% endcontent-ref %}


# Send Alerts to Multiple Slack Channels

## Introduction <a href="#introduction" id="introduction"></a>

Streamline your security response with Aikido by setting up tailored alerts to be sent to designated Slack channels. This guide will help you ensure that your team receives timely and relevant security notifications.

## Setting Up Slack Alerts <a href="#setting-up-slack-alerts" id="setting-up-slack-alerts"></a>

*Prerequisites: Ensure your Slack integration is active. You can find how to set up the Slack Integration* [*here*](https://help.aikido.dev/en/articles/8153269-how-to-set-up-slack-notifications)*.*

#### Step 1: Create an Alert <a href="#step-1-create-an-alert" id="step-1-create-an-alert"></a>

* Navigate to the [Slack integration page](https://app.aikido.dev/settings/integrations/notifications/slack) and click ‘Create Alert’ to bring up the configuration modal.

#### Step 2: Opt for Team-Based Notifications <a href="#step-2-opt-for-team-based-notifications" id="step-2-opt-for-team-based-notifications"></a>

* Choose 'Team-based' to route alerts to specific channels. Preconfigure your Teams with the right repositories and containers access.

![Configure Slack alerts for all users or specific teams with custom options.](/files/7BRysbyzIEaXwLNlTva5)

#### Step 3: Map Channels to Teams <a href="#step-3-map-channels-to-teams" id="step-3-map-channels-to-teams"></a>

* For **Weekly Digests**, link a channel for summaries of weekly security issues.
* For **Critical Issues**, link a channel for real-time alerts on urgent vulnerabilities.

![Notification channels selection for weekly digest and critical issues alerts.](/files/N4Kt5Zu36s4wOQCK35Ap)

> Note: you can decide to only pick one of the two options to create alerts.

#### Step 4: Save Your Configuration <a href="#step-4-save-your-configuration" id="step-4-save-your-configuration"></a>

* Confirm your choices and click 'Save Alert' to activate the alerting system.

## Implementation Tips <a href="#implementation-tips" id="implementation-tips"></a>

* Regularly review and correct team settings in Aikido to maintain alert accuracy.
* Confirm that the Slack channels correspond to the correct teams to ensure proper communication

***


# Microsoft Teams Notifications

## Connecting Aikido to Microsoft Teams <a href="#connecting-aikido-to-ms-teams" id="connecting-aikido-to-ms-teams"></a>

{% hint style="warning" %}
Please note that only **Aikido admin users** can link a new Microsoft Team to your Aikido workspace.

If you are using the **OLD version** of the Microsoft Teams Integration, **please delete all alerts** before setting up the new version. You can setup the new version by removing the integration and then following the steps below.\
\
App requires application-level permissions; access is limited to the Microsoft it's installed in, not the whole org.
{% endhint %}

Follow these steps to connect Aikido to Microsoft Teams:

#### Step 0. Uninstall the MS Teams Integration v1 <a href="#id-1-click-add-integration" id="id-1-click-add-integration"></a>

In case you are still running the old MS Teams integration, first **uninstall** this one from the Aikido UI!

#### Step 1. Install the Aikido app in Microsoft Teams <a href="#id-1-click-add-integration" id="id-1-click-add-integration"></a>

* Open the [Aikido app](https://teams.microsoft.com/l/app/c2baec07-db8a-49de-b066-c0ddc19cc9c0?source=store-copy-link) in the Microsoft Teams app store and click "Add to a Team".
* Select a channel for initial installation. You can configure alerts for all public channels of the selected Team later.

<figure><img src="/files/NZvhBkMyDk8kaqRotYHk" alt="" width="563"><figcaption><p>Select the team to which the messages should be sent.</p></figcaption></figure>

You can find more information on how to install an app on Microsoft Teams in [this Microsoft support article](https://support.microsoft.com/en-us/office/add-an-app-to-microsoft-teams-b2217706-f7ed-4e64-8e96-c413afd02f77).

#### Step 2. Link the Microsoft Team to an Aikido workspace <a href="#id-2-select-which-ms-teams-team-youd-like-to-connect" id="id-2-select-which-ms-teams-team-youd-like-to-connect"></a>

* The Aikido bot will send a message to the selected Microsoft Team channel. Click "Open Aikido" and log in.
* Complete the app setup by confirming the installation in the modal.

![Select a Microsoft Teams group to connect with Aikido integration.](/files/CYLsD5qfHtPGgkciKrQ9)

#### Step 3. Configure the alerts you'd like to receive <a href="#id-3-configure-the-alerts-youd-like-to-receive" id="id-3-configure-the-alerts-youd-like-to-receive"></a>

{% hint style="warning" %}
Due to limitation on Microsoft side, some public channels may not be discovered automatically. You can add them manually by selecting "Public channel missing..." in the channel selection options.
{% endhint %}

Once the connection to Microsoft Teams was successful, you can start adding alerts.

* Choose whether you want to send global or team-based notifications
* Choose for which severity types
* Choose for which issue types

<figure><img src="/files/QbqWIlKhqoT8fG1XYSA8" alt="" width="375"><figcaption></figcaption></figure>

***

## Unlinking Aikido and Microsoft Teams

1. Open the Microsoft Teams app and right click on the team where the Aikido bot is installed.
2. Click **Manage team** and select the **Apps** tab.
3. Search for the Aikido app in the list of installed apps, click on the three dots next to it, and select **Remove**.
4. Confirm the removal in the pop-up dialog. All settings for this team will be deleted automatically.

***

## FAQ

<details>

<summary>Can I link multiple Teams to one Aikido Workspace?</summary>

Yes, this is possible. Just follow the same steps again.

</details>

<details>

<summary>Is it possible to link multiple Aikido Workspaces to one Microsoft Team?</summary>

To link additional workspaces to the same Microsoft Team, click the button "Link another workspace" in the confirmation message sent by Aikido to your selected Teams channel. You will find theses message inside the Microsoft channel where you first installed the Aikido App. Please **do not** try to install the app multiple times.

</details>

<details>

<summary>How can I receive alerts in a private channel?</summary>

This is not easily possible due to restrictions imposed by Microsoft. We recommend creating a private Team with a public channel instead. But we describe a [workaround on this page](/getting-started/chat-and-alerts/send-alerts-to-private-microsoft-teams-channels).

</details>

<details>

<summary>I don't receive the "Connect to Aikido" chat message</summary>

Please ensure that no moderation settings are configured for the selected channel that prevent bots from sending messages. Uninstall the app and try the process again using a different channel. If this does not help, please contact the Aikido support team.

</details>

<details>

<summary>Can I use the app in the Government Community Cloud (GCC)?</summary>

This is currently not possible. Please contact us to let us know that you would like to use our Teams app in a GCC environment.

</details>

***


# Send Alerts to Private Microsoft Teams Channels

Because Microsoft Teams apps can't be member of a private Teams channel, additional setup is required to send alerts to a private channel. The reason for this is a technical limitation in Microsoft Teams that exists since several years and was not solved until now. In some cases it might be easier to create a new MS Team instead, and only allow authorized people access to this team. Please note that alerts in private channels will be sent as the user who has performed the setup steps and not as Aikido.

***

Follow these steps to send alerts to a private Microsoft Teams channel:

{% stepper %}
{% step %}
**Install the Aikido app**

If not already done, follow the steps described on this page: [Microsoft Teams Notifications](/getting-started/chat-and-alerts/ms-teams-notifications)
{% endstep %}

{% step %}
**Create the Workflow**

Select the private channel that should receive the alerts, click on "More Options" (the three dots) and select "Workflows".

Search for and select **"Send webhook alerts to a channel"**. After that select the Microsoft Team and the private channel where the alerts should be sent. Finish the creation by clicking on "Save".

<figure><img src="/files/yh2z510KgKBJwR5vfGuE" alt=""><figcaption><p>Select Microsoft Team and private channel</p></figcaption></figure>

Copy and save the workflow URL using the copy button. You need this URL later.

<figure><img src="/files/3C5RvDljIYycBbv8jswV" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Finish setup**

Open the Microsoft Teams integration page in the Aikido dashboard and click on "New alert". Inside the channel select input, click on "Link a different private channel". After that the following dialog is opened. Select the Microsoft Team and enter the channel name and the workflow URL. Click on "Add Channel" to finish the setup.

<figure><img src="/files/i7jHy8OKGxJdM4yWQdPu" alt="" width="563"><figcaption><p>Finish the connection</p></figcaption></figure>
{% endstep %}

{% step %}
**Confirm successful setup**

After clicking on "Add Channel", you should receive the message "This channel has been successfully added to Aikido." in your private Microsoft Teams channel. If you did not receive any message, please check the following step.
{% endstep %}

{% step %}
**Edit the Workflow (Not always needed)**

{% hint style="info" %}
This step is only required if you did not receive the success message in your private channel.
{% endhint %}

The workflow is sometimes configured to send messages as the Power Automate bot, but this bot cannot send messages to private channels either.

Click on "Workflows Home" in the right bottom corner of the dialog and then on "Edit in Power Automate". Expand the "Attachment is null" section by clicking on it. Modify the "Post card in a chat or channel" action and select "User" for the "Post as" setting as shown in the following screenshot. Make sure to save your changes after that.

<figure><img src="/files/HQPEBV2JfWp2HwQ7rMKM" alt=""><figcaption><p>Modify Workflow</p></figcaption></figure>
{% endstep %}
{% endstepper %}


# Email Forwarding

This feature lets workspace admins configure external email addresses to receive automated alert notifications when new vulnerabilities are detected.

Use it for shared inboxes like `security@company.com`, forward to robot emails, escalation aliases, or teams that do not use chat alerts.

#### Set up Email Forwarding

{% stepper %}
{% step %}
**Open the integration**

Go to **Settings** → **Integrations** → Email Forwarding
{% endstep %}

{% step %}
**Configure forwarding**

Enter the email address that should receive alerts.

Choose a minimum severity (`Critical, High, etc` )

The address will receive alerts for that severity and anything higher.
{% endstep %}

{% step %}
**Save additional addresses if needed**

Repeat the same setup for every inbox that should receive alerts.

Each forwarding address can have its own minimum severity.
{% endstep %}

{% step %}
**Send a test email**

Click **Send Test Email** to confirm the integration works.

Use this after setup to verify delivery to the target inbox.
{% endstep %}
{% endstepper %}

<figure><img src="/files/M3WhTohXtNWRcTZP3Mok" alt=""><figcaption></figcaption></figure>


# Reachability Analysis

{% content-ref url="/pages/aor4m48Yw3ao4PrdFMAG" %}
[Introduction to Reachability Analysis](/getting-started/reachability-analysis/introduction-to-reachability-analysis)
{% endcontent-ref %}

{% content-ref url="/pages/khpdkI8K2Pw3DeLpOX06" %}
[Reachability Analysis Examples in Aikido](/getting-started/reachability-analysis/reachability-engine-to-remove-false-positives)
{% endcontent-ref %}

{% content-ref url="/pages/7m8m0PZ4neFDumcRTs9j" %}
[Container Reachability Analysis](/container-image-scanning/container-reachability-analysis)
{% endcontent-ref %}

{% content-ref url="/pages/UNv1RVacVk2u3H469uUj" %}
[Virtual Machine Reachability Analysis](/virtual-machine-scanning/misc/virtual-machine-reachability-analysis)
{% endcontent-ref %}


# Introduction to Reachability Analysis

Learn how Aikido helps you identify which vulnerabilities are exploitable.

Aikido’s reachability analysis is focused on identifying whether a vulnerability is actually exploitable in the context of your application. Instead of flagging every vulnerable dependency or risky pattern as equally critical, Aikido builds a graph of modules, functions, and data flows within your codebase. It then asks a key question: ***Is there an execution path from real application behavior to the vulnerable code?*** Only when such a path exists is the finding considered truly security-relevant.

### Conceptual Overview

At a high level, Aikido constructs an abstract program graph in which:

* **Nodes** represent functions, methods, modules, files, and sometimes higher-level components.
* **Edges** represent relations such as function calls, imports, dependency inclusion, and data-flow between variables and parameters.

Vulnerabilities are anchored at specific nodes in this graph (for example, a known vulnerable function in a third-party library, or a sink such as a SQL execution point). Aikido then computes whether there exists a path from **entry points** (HTTP handlers, CLI commands, background jobs, etc.) to these vulnerable nodes. If no such path exists under the current code and configuration, the vulnerability is treated as non-reachable for that project revision.

In this way, reachability transforms a flat list of alerts into a structured subset of issues that are provably connected to real program behavior.

### Types of Reachability

Aikido uses several complementary notions of reachability. They share the same foundation, but operate at different levels of abstraction:

| Type                     | Scope                       | Main Question                                            | Typical Signals                                    |
| ------------------------ | --------------------------- | -------------------------------------------------------- | -------------------------------------------------- |
| **Dependency-level**     | SCA / package dependencies  | “Does the project ever call into the vulnerable symbol?” | Imports, symbol references, dependency manifests   |
| **Function-level**       | SAST / taint analysis       | “Can untrusted input flow into a dangerous sink?”        | Sources, sanitizers, sinks, inter-procedural flows |
| **Contextual (runtime)** | Build & runtime environment | “Does this code execute in the actual runtime context?”  | Prod vs dev deps, dead code, build-only tooling    |

These categories are not mutually exclusive. A typical Aikido finding may be filtered first by dependency-level reachability, then refined by function-level reachability, and finally reinterpreted in the context of how the project is built and deployed.

### How Reachability Works

#### 1. Graph construction

For each project, Aikido constructs a lightweight, language- and framework-aware graph:

* **Structural relations**: imports, requires, module references, inheritance, and other static relationships.
* **Call relations**: function calls, method invocations, event handlers.
* **Data-flow relations**: propagation of potentially tainted data through variables, parameters, and return values.

This graph is intentionally approximate but designed to preserve the properties needed to answer “is there a path?” questions efficiently.

#### 2. Anchoring vulnerabilities

The scanners then map each raw finding to one or more *anchor points* in the graph:

* For **SCA**, the anchor is usually a vulnerable symbol (a specific function, class, method, or module) associated with a CVE or advisory.
* For **SAST**, the anchor is a code location of interest, often a security sink such as `exec`, SQL queries, file system access, or deserialization.
* For **infrastructure scans**, anchor points may correspond to images, packages, or configuration elements that participate in the runtime execution environment.

#### 3. Reachability queries

Given a set of entry points and anchor nodes, Aikido asks reachability questions of the form:

> “Is there at least one valid execution path from any entry point to this anchor, under the current build and configuration?”

Algorithmically, this reduces to graph reachability (forward or backward traversal) constrained by language semantics and configuration knowledge. For data-flow analysis, the reachability relation is enriched with t**aint information**: a path is only considered security-relevant if untrusted data is able to traverse it without being fully neutralized by sanitization.

#### 4. Integration with triage and prioritization

Reachability is applied *before* higher-level triage:

* Findings with **no reachable path** are removed or heavily downgraded.
* Findings with a **clear, explainable path** are retained and passed to later stages (e.g., risk scoring, business impact analysis).
* Developers can inspect the concrete path (call stack and data-flow) to understand how the issue becomes exploitable.

This pipeline ensures that most “cry-wolf” findings are filtered out at the structural level rather than simply hidden behind severity tuning.

### Effects on Findings and Workflow

Reachability analysis has several practical consequences for how teams experience Aikido:

1. **Noise reduction**

   Many alerts produced by traditional tools stem from dependencies that are present but never invoked, or from code paths that are effectively dead. By eliminating issues without a demonstrable execution path, Aikido substantially reduces false positives and redundant tickets.
2. **More meaningful severity**

   Severity is no longer just a property of the CVE or rule; it is a property of the CVE *plus* the project’s usage. A medium-severity library issue that is deeply embedded on a hot path may be more urgent than a high-severity issue in a dev-only tool that is never executed in production.
3. **Developer-aligned explanations**

   Showing the concrete path (“request handler → service → library function → vulnerable symbol”) reframes security findings as recognizable program behavior. This lowers the cognitive overhead for developers and makes remediation efforts more targeted and efficient.
4. **Stable signal over time**

   Because reachability is recomputed as code and dependencies change, the issue backlog tracks actual architectural evolution. As dead dependencies are removed or code is refactored, previously reachable findings may transition to non-reachable, and vice versa, providing a dynamic, architecture-aware view of risk.

### Limitations and Design Choices

Aikido’s reachability engine uses a ‘conservative **under-approximation**,’ so it only marks code as unreachable when it can be determined with high confidence. Dynamic language features like reflection, dynamic imports, metaprogramming, or complex build steps can make parts of the call graph unclear or invisible. In these ambiguous cases, Aikido errs on the side of caution: instead of suppressing a potentially relevant issue, it will either keep it as-is or lower its severity.

This trade-off strikes a balance between two goals:

* Reducing noise by filtering out issues that are definitely not reachable at runtime.
* Preventing a false sense of security when reachability can’t be determined with certainty.

### Summary

Reachability analysis in Aikido maps how different parts of your application are connected by tracing function calls, data flows, and interactions between components across source code, dependencies, and infrastructure. A vulnerability is only treated as a real risk if there’s a clear, executable path from an application entry point to the vulnerable behavior. By embedding this reasoning into every scanner and integrating it tightly with triage, Aikido transforms a large, noisy stream of raw alerts into a smaller, high-confidence set of findings that more accurately reflect how attackers could exploit the system in practice.


# Reachability Analysis Examples in Aikido

Aikido combines 100+ custom rules to reduce false positives and irrelevant alerts. Most of those ground rules are powered by our own reachability analysis engine.

When Aikido detects a known vulnerability in your dependencies or first-party code, it checks whether your application can actually call into the vulnerable code path. In practice, we build a lightweight call/dependency graph and trace references from your code to the functions/classes known to be affected. If the vulnerable code isn’t reachable (or is only used in non-production contexts like tests or tooling), the alert is downgraded or suppressed.

This results in significant noise reduction compared to legacy scanners that report every vulnerable package regardless of usage.

{% hint style="info" %}
Note: We continuously extend this mechanism across languages and ecosystems to further improve noise suppression.
{% endhint %}

#### **Example 1:** **You're not using the affected function**

Aikido’s internal knowledge base indicates that **CVE-2020-7774** only affects the `setLocale` function. If our analysis sees that your codebase never references `setLocale`, you’re not affected. Aikido will downgrade the issue and continue to monitor future changes in case the function starts being used.

![Security analysis found no usage of CVE-2020-7774 vulnerability in repository.](/files/8AWDmSEdvY013qb4t9xs)

#### **Example 2:** **Vulnerable package used only in tooling**

The JS package `minimatch` is vulnerable, but we detect it’s only pulled in by `eslint` and `mochajs`. Because these are linting/testing dependencies and are not shipped to production, your end-users are not exposed. Aikido downgrades the issue accordingly.

#### **Example 3:** Dead dependency path

A package (`path-parse`) is known to have a CVE and is required by `pug`. Our trace shows `pug` is no longer used by your application (no imports/references, or it’s excluded from your build). In this case, the CVE can be safely discarded.

![Dependency reachability analysis for CVE-2021-23343 showing vulnerable package path in repository.](/files/xYzD3EBin8kk432JJs6q)

***

### How Aikido makes the call

* **Call/dependency graphing:** We map how your code imports and calls into packages, and then follow edges toward functions tied to a CVE.
* **Context awareness:** We distinguish production runtime code from dev and test tools (such as linting, test, or build code), so tooling-only usage won’t trigger production-impacting alerts
* **Guarded downgrades:** Findings are downgraded or suppressed only when the vulnerable symbol is provably unreachable. If evidence changes (such as with a new import), the severity is automatically reevaluted.

### Additional things to keep in mind

* **Heuristics and build setups:** Highly dynamic patterns, custom loaders, or unusual build steps can obscure call graphs. Some issues may be kept at a higher severity if usage is unclear.
* **Transitive changes:** Updating indirect dependencies can make previously unreachable code reachable. Aikido continually rechecks after dependency updates and code changes


# How Aikido Uses AI

Aikido uses AI throughout the full software development lifecycle. It starts in the IDE, continues in pull requests and scans, helps teams fix and enforce security standards, and extends into runtime protection and pentesting.

At the center of that intelligence is [Aikido Agent](/aikido-agent/aikido-agent). It understands your security data and powers [Ask Aikido](/aikido-agent/ask-aikido), [Custom Reports](/aikido-agent/custom-reports), [SAST AutoTriage](/aikido-agent/sast-autotriage), [Secrets AutoTriage](/aikido-agent/secrets-autotriage), and [CVE Exploitability Analysis](/aikido-agent/cve-exploitability-analysis).

{% hint style="info" %}
We never use, store, or train on any customer data. Small, anonymized code fragments may be used to guarantee the accuracy of triaging and fixing vulnerabilities.

All AI operations are inference-only, meaning data are processed transiently in memory and never retained or reused.

For a detailed overview of our controls, environments, and compliance measures, please refer to our AI Policy, available upon request through our [Trust Center](https://www.aikido.dev/trust-center).
{% endhint %}

### AI across the SDLC

From first code to production, Aikido uses AI to:

* prioritize issues early
* interrogate findings with Ask Aikido
* analyze dependency CVEs against real code usage
* generate and refine fixes
* generate API specs
* enforce custom code and cloud rules
* learn repo-specific standards through extra code context
* track AI usage in production
* validate security with AI-powered pentests

### 1. Start in the IDE

Aikido brings AI directly into the IDE. Developers can prioritize findings and apply fixes before code reaches a pull request.

Read [Aikido AI in IDE](/ai-and-dev-tools/ide-plugins-overview/features/aikido-ai-in-ide).

### 2. Reduce noise during scans and review

As code moves through scans and pull requests, [Aikido Agent](/aikido-agent/aikido-agent) cuts noise and surfaces what matters first. It checks exploitability, reads real code context, and reprioritizes issues based on likely impact. Check out [SAST AutoTriage](/aikido-agent/sast-autotriage).

Aikido applies the same approach to secret findings. [Secrets AutoTriage](/aikido-agent/secrets-autotriage) filters out false positives and prioritizes exposed secrets by whether they are still active and how much access they grant.

For dependency findings, Aikido also runs [CVE Exploitability Analysis](/aikido-agent/cve-exploitability-analysis). The Agent inspects how a vulnerable package is used in your repository and decides whether the CVE is actually exploitable in your environment. Based on your settings, Aikido can downgrade, upgrade, snooze, or ignore the finding automatically.

When you want to inspect one finding in more detail, use [Ask Aikido](/aikido-agent/ask-aikido). It helps you validate severity, understand realistic attack paths, and ask whether an issue is actually reachable or exploitable in your app. For dependency CVEs, it can also explain the reachability path and the full impact of the vulnerable package in plain language.

To turn security data into reusable workspace reports, use [Custom Reports](/aikido-agent/custom-reports). Describe the insights you need in natural language, refine the charts and tables in chat, and save the result for your team.

Code Quality is also AI-powered. It reviews newly introduced pull request changes and helps enforce engineering standards across many languages. More info in [Code Quality Overview](/code-quality/code-quality-overview).

You can also add extra code context. This gives Aikido AI more signal and less noise. Use it to explain accepted exceptions, architectural choices, and repo-specific standards. Aikido then uses that context to make Code Quality comments more relevant. Check out how to [Add Extra Code Context](/code-quality/add-extra-code-context).

### 3. Fix issues with AutoFix

Aikido generates reviewable fixes for code, dependencies, infrastructure, and containers. You can apply fixes in the IDE or open pull requests for review.

You can also refine generated fixes with follow-up instructions, so the patch better matches your codebase and standards.

Read [AutoFix Overview](/autofix-and-remediation/overview-aikido-autofix), [AutoFix for SAST and IaC Issues](/autofix-and-remediation/scope/ai-autofix-for-sast-and-iac-issues), [AutoFix for Open Source Dependencies](/autofix-and-remediation/scope/autofix-for-open-source-dependencies), [AutoFix for Containers](/autofix-and-remediation/scope/ai-autofix-for-containers), and [Refine AutoFixes with Aikido AI](/autofix-and-remediation/automation-and-merging/refine-autofixes-with-aikido-ai).

### 4. Generate specs and enforce policies

Aikido can generate an OpenAPI specification directly from backend code. That helps teams start API scanning without maintaining the spec by hand.

Read [Autogenerate OpenAPI via Aikido AI (Code2Swagger)](/dast-surface-monitoring/api-scanning/autogenerate-openapi-via-aikido-ai-code2swagger).

Aikido also uses AI for custom rule creation. Teams can define custom code checks in natural language and generate custom cloud misconfiguration checks for their environment.

Read [Add Custom Code Rules](/code-quality/add-custom-code-rules) and [Custom CSPM Rules](/cloud-scanning/custom-cspm-rules).

### 5. Track runtime AI usage

Zen Firewall tracks LLM provider usage, model activity, token consumption, and estimated cost. That gives teams visibility into how AI is used in running applications.

Read [Tracking AI / LLM usage with Zen Firewall](/zen-firewall/zen-features/tracking-ai-llm-usage-with-zen-firewall).

### 6. Validate security with Pentests

Aikido Pentest uses autonomous agents to discover, exploit, and validate vulnerabilities across applications, APIs, and infrastructure.

Read [Pentest Overview](/pentests/aikido-pentest).


# AGI Readiness

Stay ahead of AI-driven software risk with automated fixes, AI-powered audits, and live exposure visibility.

The AI era ships more code. It pulls in more dependencies. It expands the surface attackers can reach. That means more vulnerabilities can pile up, faster.

AGI Readiness helps you stay ahead of that curve. Automatically fix vulnerabilities before they accumulate. Audit your code and APIs with AI-powered security testing. Keep a live view of the cloud resources and domains attackers can reach.

<figure><img src="/files/TMOTKZyvobyI2lc3vY8L" alt=""><figcaption></figcaption></figure>

### What AGI Readiness includes

#### Set up automated PR creation

Use AutoFix to create reviewable pull requests automatically. That keeps remediation moving without adding manual busywork.

Start with [Automatic Creation of Pull Requests](/autofix-and-remediation/automation-and-merging/automatic-creation-of-pull-requests).

#### Run AI-powered code and API audits

Use Code Audit for pentest-grade reasoning on source code. Use Pentest to validate exploitability against live apps and APIs.

Start with [Code Audit Overview](/ai-code-analysis/ai-code-audit-overview) and [Pentest Overview](/pentests/aikido-pentest).

#### Connect your cloud and attack surface

Connect your cloud to track resources, misconfigurations, and inventory. Add your domains to monitor your external attack surface.

Start with [Connect Your Cloud](/cloud-scanning/connect-your-cloud) or [Attack Surface Monitoring](/dast-surface-monitoring/attack-surface-scanning).


# Securing AI-Generated Code

Guardrails for AI-generated code with malicious package blocking, pre-commit secrets blocking, MCP integrations, and PR gating.

**Enhance Your AI Development Workflow with Aikido**

AI coding agents like Claude can speed up development by writing and committing code autonomously. They also introduce new risks. They can leak secrets, install fake packages, miss IDE feedback, or ship code without enough security checks.

**How Aikido Helps**

* **Pre-commit controls:** Catch mistakes before code lands in the repo.
* **During code generation:** Keep security checks close to the agent workflow.
* **Pre-merge checks:** Stop risky changes before they hit your main branch.

Whether your team uses Claude or another AI tool, Aikido adds guardrails across the full workflow.

### Main Risks

* Hallucinated package names that point to malware
* Secrets or tokens committed by mistake
* Security findings missed because the agent runs outside the IDE
* No security checks between code generation and merge

### Recommended Controls

#### Safe Chain: Block Malicious and Hallucinated Packages

[Safe Chain](/code-scanning/aikido-malware-scanning) validates packages against trusted registries before installation. It blocks fake or hallucinated package names before they reach your environment. It also scans nested dependencies for malicious behavior such as obfuscated code, data exfiltration, install scripts, and crypto miners. New package versions published less than 24 hours ago are blocked by default, and Safe Chain falls back to the latest older safe version so builds keep moving.

#### Secrets Pre-Commit Hook: Prevent Secrets from Being Committed

The [Aikido Secrets Pre-Commit Hook](/ai-and-dev-tools/aikido-secrets-pre-commit-hook) scans staged changes and blocks commits that contain secrets, passwords, or API keys. It works for both developer-written and agent-generated changes. Because it runs locally before code leaves the machine, it reduces the chance of accidental exposure in Git history, CI logs, or pull requests. Teams using the IDE plugins can also install it directly through [Aikido Expansion Packs](/ai-and-dev-tools/ide-plugins-overview/features/aikido-expansion-packs) (currently available for VS Code and related IDEs).

#### Aikido MCP: Scan Code During Generation

The [AI Coding Assistants (MCP)](/ai-and-dev-tools/aikido-mcp) setup connects Aikido directly to your agent environment. It runs secret scanning and SAST while code is being written, and can help fix issues before commit. When used with [Automatically handle MCP rules in IDE](/ai-and-dev-tools/aikido-mcp/automatically-handle-mcp-rules-in-ide), Aikido can automatically enforce a scan-fix-rescan loop for generated, added, and modified code. That keeps security checks inside the AI workflow instead of waiting for a later scan.

#### Aikido AI in IDE and Expansion Packs: Keep Findings Visible

[Aikido AI in IDE](/ai-and-dev-tools/ide-plugins-overview/features/aikido-ai-in-ide) keeps findings and fixes visible while code is being written. It can use AI AutoTriage to prioritize the issues that matter most and AI AutoFix to generate reviewable fixes with a diff preview and automatic rescan. If you want faster rollout, [Aikido Expansion Packs](/ai-and-dev-tools/ide-plugins-overview/features/aikido-expansion-packs) can install related tooling like the pre-commit hook, Safe Chain, and MCP directly from the IDE. This keeps the full developer and agent workflow in one place.

#### PR Gating: Enforce Checks Before Merge

[PR Gating](/pr-and-release-gating/aikido-ci-gating-functionality) is the final control point for agent-generated changes before they reach your main branch. It scans the branch diff for new issues across SCA, IaC, Secrets, SAST, malware, license risks, and code quality. It also shows which existing issues the branch solves. You can set severity thresholds, choose which scans run, and decide whether draft pull requests should be checked. That makes it a strong backstop even if earlier controls were skipped or bypassed.

### Suggested Setup

1. Enable [Safe Chain](/code-scanning/aikido-malware-scanning) for package installs
2. Install the [Aikido Secrets Pre-Commit Hook](/ai-and-dev-tools/aikido-secrets-pre-commit-hook)
3. Connect [AI Coding Assistants (MCP)](/ai-and-dev-tools/aikido-mcp) to your agent environment
4. Keep [PR Gating](/pr-and-release-gating/aikido-ci-gating-functionality) enabled as a final check


# Secrets Pre-Commit Hook

Aikido prevents secrets at three points before they reach production: in the IDE, at pre-commit, and at PR gating. Our pre-commit githook scans your staged code for secrets, passwords and API keys. It stops sensitive data from ever reaching your repository, which reduces the risk of leaks and accidental exposure.

## Installation

{% tabs %}
{% tab title="From IDE" %}
When the [Aikido IDE plugin](broken://pages/TtCgRvpjJR8sPsXdszal) is installed you can use the Aikido Expansion Packs to install the pre commit hook with one click.

[Learn more in the Expansion Packs docs.](/ai-and-dev-tools/ide-plugins-overview/features/aikido-expansion-packs)
{% endtab %}

{% tab title="Mac/Linux" %}
To install the Aikido Secrets pre-commit hook for all git repositories, run:

```shellscript
curl -fsSL https://raw.githubusercontent.com/AikidoSec/pre-commit/6cc79e039ee78b206520f143d618a44665c904b3/installation-samples/install-global/install-aikido-hook.sh | bash
```

This will download the Aikido pre-commit scanner used for secrets detection and install the pre-commit hook script in the global hooks directory.
{% endtab %}

{% tab title="Windows" %}
To install the Aikido Secrets pre-commit hook for all git repositories, run the following in PowerShell:

```powershell
iex (iwr "https://raw.githubusercontent.com/AikidoSec/pre-commit/6cc79e039ee78b206520f143d618a44665c904b3/installation-samples/install-global/install-aikido-hook.ps1" -UseBasicParsing)
```

This will download the Aikido pre-commit scanner used for secrets detection and install the pre-commit hook script in the global hooks directory.
{% endtab %}

{% tab title="Pre-Commit Framework" %}
If you're already using the [pre-commit](https://pre-commit.com/) framework, add this to your `.pre-commit-config.yaml`:

```
repos:
  - repo: https://github.com/AikidoSec/pre-commit
    rev: main  # or pin to a specific commit
    hooks:
      - id: aikido-local-scanner
```

Then install the hooks:

```
pre-commit install
```

**Note:** The `aikido-local-scanner` binary must be installed separately. Run the global installation script first:

**macOS/Linux:**

```
curl -fsSL https://raw.githubusercontent.com/AikidoSec/pre-commit/2235fe0536f9135aa561ce108702fac708b38977/installation-samples/install-global/install-aikido-hook.sh | bash -s -- --download-only
```

**Windows (PowerShell):**

```
irm https://raw.githubusercontent.com/AikidoSec/pre-commit/2235fe0536f9135aa561ce108702fac708b38977/installation-samples/install-global/install-aikido-hook.ps1 | % { iex \"& { $_ } -DownloadOnly\" }
```

This installs the scanner to `~/.local/bin/aikido-local-scanner`.
{% endtab %}
{% endtabs %}

The [source of the script and more information about its workings](https://github.com/AikidoSec/pre-commit) are available on Github.

## Testing the pre-commit hook

To test the pre-commit hook after you've set it up, create a `sample.js` file in a repository:

```javascript
const password = "eRwjQKVUSRX7uYV017B0cRHVKv45Gv8G"
```

Add this file to your staged changes. If you try commit this file, the pre-commit hook will run and block the commit with the following message:

```log
Detected secrets in staged files!
Secret #1:
  File: sample.js
  Line: 1
  Secret: password = "****************************Gv8G"
  Description: Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
```

## Skipping a specific secret

To skip a [specific secret from being flagged](/code-scanning/scanning-practices/ignoring-secrets-via-code-comments), add a comment on the line of the detected secret:

```javascript
const password = "eRwjQKVUSRX7uYV017B0cRHVKv45Gv8G" // gitleaks:allow
```

## Disable the Aikido Secrets pre-commit scan

Temporarily bypass pre-commit hooks for a single commit

```sh
git commit --no-verify
```

Temporarily bypass the Aikido Secrets pre-commit hook for a single commit

```bash
AIKIDO_SKIP_PRE_COMMIT=1 git commit
```

## Uninstall

Use the uninstall script or follow the step below to manually uninstall the hook.

{% tabs %}
{% tab title="Mac/Lunix" %}
If you've installed the Aikido pre-commit hook using the install script and want to uninstall, run:

```bash
curl -fsSL https://raw.githubusercontent.com/AikidoSec/pre-commit/e6f541e65378dd30f3f320628000f837cfba0ec4/installation-samples/install-global/uninstall-aikido-hook.sh | bash
```

{% endtab %}

{% tab title="Windows" %}
If you've installed the Aikido pre-commit hook using the install script and want to uninstall, run:

```powershell
iex (iwr "https://raw.githubusercontent.com/AikidoSec/pre-commit/e6f541e65378dd30f3f320628000f837cfba0ec4/installation-samples/install-global/uninstall-aikido-hook.ps1" -UseBasicParsing)
```

{% endtab %}
{% endtabs %}

### Manual uninstall of global pre-commit hooks

This fully removes all global Git hooks and the Aikido binary.

1. Remove the global hooks directory:
   * Unix/Linux/macOS: `rm -rf ~/.git-hooks`
   * Windows: `Remove-Item -Recurse -Force $env:USERPROFILE\.git-hooks`
2. Reset Git hooks path: `git config --global --unset core.hooksPath`
3. Optionally remove the binary:
   * Unix/Linux/macOS: `rm ~/.local/bin/aikido-local-scanner`
   * Windows: `Remove-Item $env:USERPROFILE\.local\bin\aikido-local-scanner.exe`

### Manual uninstall of only Aikido Git Hook

If you already had your own global Git hooks and want to keep them, do not delete the hooks directory.

Instead:

1. Open the pre-commit file in your global hooks directory (for example \~/.git-hooks/pre-commit).
2. Remove only the lines that invoke aikido-local-scanner or are clearly marked as added by Aikido.
3. Save the file.

Git will keep using your existing hooks, without running Aikido Secrets.

## Related articles

* [Ignoring secrets via code comments](/code-scanning/scanning-practices/ignoring-secrets-via-code-comments)
* [Ignoring files using .aikido file](/code-scanning/scanning-practices/ignore-via-code-with-aikido-files)


# IDE Plugins

Aikido’s IDE integrations help you catch security issues at the moment they are introduced.\
You get code scanning results directly in your editor, instant secret detection, vulnerable package insights, smart AutoFix suggestions, and clear AutoTriage help so you know which issues matter most.

## Features to explore

* [Aikido Expansion Packs](/ai-and-dev-tools/ide-plugins-overview/features/aikido-expansion-packs)
* [Real-Time Code Scanning in IDE](/ai-and-dev-tools/ide-plugins-overview/features/real-time-code-scanning-in-ide)
* [Open-Source Dependency Scanning (SCA) in IDE](/ai-and-dev-tools/ide-plugins-overview/features/open-source-dependency-scanning-sca-in-ide)
* [Full Workspace Scan in IDE](/ai-and-dev-tools/ide-plugins-overview/features/full-workspace-scan-in-ide)
* [Aikido AI in IDE](/ai-and-dev-tools/ide-plugins-overview/features/aikido-ai-in-ide)

## IDEs

* [Visual Studio IDE](/ai-and-dev-tools/ide-plugins-overview/visual-studio-plugin)
* [VS Code IDE](/ai-and-dev-tools/ide-plugins-overview/vs-code-plugin)
* [JetBrains IDEs](/ai-and-dev-tools/ide-plugins-overview/jetbrains-ide-plugins)
  * IntelliJ IDEA, GoLand, PhpStorm, PyCharm, Rider, WebStorm, RubyMine, RustRover, and Android Studio
* [Cursor IDE](/ai-and-dev-tools/ide-plugins-overview/cursor-ide)
* [Windsurf IDE](/ai-and-dev-tools/ide-plugins-overview/windsurf-ide)
* [Kiro IDE](/ai-and-dev-tools/ide-plugins-overview/kiro-ide)
* [Google Antigravity IDE](/ai-and-dev-tools/ide-plugins-overview/google-antigravity)
* [Eclipse IDE](/ai-and-dev-tools/ide-plugins-overview/eclipse-ide)

## Additional

* [Supported languages in IDE](/ai-and-dev-tools/ide-plugins-overview/features/supported-languages-in-ide)


# Features


# Aikido AI in IDE

Aikido’s AI features bring smart prioritization and safe, automated fixes directly into your IDE. Instead of manually reviewing every issue, you can focus on what really matters and even fix problems with one click.

## AI AutoTriage

When a scan detects multiple issues, AI AutoTriage can help you identify which ones deserve attention first.

Aikido can automatically analyzes findings for reachability and impact based on your code context, marking the most critical ones for review and de-emphasizing noise.

### How to use

1. Open the Aikido panel or hover the inline finding.
2. Select a finding that supports AutoTriage.
3. Click Assess with AI.

## AI AutoFix

For supported SAST and SCA findings, Aikido offers AI AutoFix, an AI-generated fix you can preview and apply directly in your IDE.

Each fix includes:

* A proposed safe code change generated by Aikido’s security AI.
* A side-by-side preview so you can review before applying.
* Context on why the fix is recommended.

Once applied, your code is automatically updated and rescanned to confirm the issue is resolved.

<figure><img src="/files/ZcONVBAwy6kJfdZukYFn" alt=""><figcaption></figcaption></figure>

### Benefits

* Reduce noise: Let AI filter and prioritize issues automatically.
* Save time: Fix common vulnerabilities instantly without leaving your editor.
* Stay consistent: IDE results match the rules and severities defined in your Aikido workspace.

### How to use

1. Open a supported SAST or dependency finding.
2. Click AutoFix.
3. Review the proposed patch in the diff preview.
4. Apply the change. Aikido rescans the file to verify the issue is resolved.


# Aikido Expansion Packs

Aikido Expansion Packs allows you to add extra security tooling that runs on your machine from inside your IDE. You can enable or disable these add-ons from the Expansion Packs screen. Each pack improves a different part of your workflow and helps keep your code and device secure without slowing you down.

<figure><img src="/files/jbBP76DiDRafiatXCxsj" alt=""><figcaption></figcaption></figure>

## How to use

Open the Aikido sidebar, toggle open `Getting Started` if not already and click on the `Configure Aikido Expansion Packs` link.

Alternatively use the [Command Palette](https://code.visualstudio.com/docs/getstarted/userinterface) and run `Aikido: Expansion Packs`

<figure><img src="/files/o3EvpbAsgBJOUM9QY6PS" alt="" width="375"><figcaption></figcaption></figure>

## Features

### Pre-commit Hook

The secrets pre-commit hook checks your code for hardcoded secrets before you commit. It prevents accidental leaks and runs locally without configuration. Read more on [Secrets Pre-Commit Hook](/ai-and-dev-tools/aikido-secrets-pre-commit-hook)

### Safe Chain

Safe Chain protects your environment from malicious packages. It adds a safety layer around your package manager and prevents installation of known malware. Read more on [Safe Chain: Prevent Malware Installs](/code-scanning/aikido-malware-scanning)

### Aikido MCP

The Aikido MCP Server brings Aikido's security scanning capabilities directly into your AI coding workflow. Read more on [AI Coding Assistants (MCP)](/ai-and-dev-tools/aikido-mcp)


# Full Workspace Scan in IDE

The Aikido Workspace Scan lets you analyze your entire project at once, so you can quickly review security issues across all files, not just the ones you have open.

<figure><img src="/files/TxRz7RNdWzWa5Ymwlrr7" alt=""><figcaption></figcaption></figure>

#### When to Use a Full Scan

Use full scans when:

* You want a security baseline for your repository.
* You’re about to push significant code changes.

For regular development, open/save scans continue to provide instant feedback as you write code.

#### Run a Full Scan

You can start a full scan directly from the Aikido panel in VS Code:

1. Open the Aikido sidebar.
2. Click Workspace Scan at the top of the view.
3. Select whether you want to scan:
   * **Entire workspace** – runs a complete analysis of all source files in your project.
   * **Changed files only** – scans only files that have been modified since your last Git commit.

<figure><img src="/files/ZZBtnLCOT3vBt06Lxe8F" alt=""><figcaption></figcaption></figure>

During the scan, Aikido checks for:

* Code issues (SAST): insecure coding patterns and misconfigurations.
* Secrets: exposed tokens, passwords, and API keys.

Results appear inline in your editor and in the Scan Results panel, grouped by category. You can hover over each finding for more details or open it in Aikido for deeper triage.

{% hint style="warning" %}
The workspace scan does not run automatically. You’ll need to start a new scan manually whenever you want updated results.
{% endhint %}


# Real-time SAST, Secrets and IaC scanning in IDE

The Aikido IDE plugin helps you catch security issues the moment they’re introduced. Every time you open or save a file, Aikido runs a quick scan in the background and highlights problems directly in your editor.

<figure><img src="/files/Pqi0SYzaj9gZdUBVUYCD" alt=""><figcaption></figcaption></figure>

#### What It Scans

Aikido performs two types of scans in real time:

* SAST (Static Application Security Testing): Detects insecure coding patterns, potential injections, unsafe deserialization, and other code-level vulnerabilities.
* Secrets: Finds exposed credentials such as API keys, passwords, or tokens.
* IAC: (Infrastructure as Code): Detects cloud and infrastructure misconfigurations in Terraform, CloudFormation, Dockerfiles, and similar files.

#### How It Works

When you open or save a file, Aikido scans the code using the same analysis engine as the Aikido platform.

Detected issues appear:

* Inline, underlined or highlighted in the editor.
* In the Aikido sidebar, grouped by severity and category.
* In the Problems panel, for quick navigation.

Hover over any finding to see context and remediation details. For supported findings, you can [analyse using AI Autotriage or apply an AI AutoFix](/ai-and-dev-tools/ide-plugins-overview/features/aikido-ai-in-ide) to safely patch the issue without leaving your IDE.


# Open-Source Dependency Scanning (SCA) in IDE

Aikido’s IDE extension helps you find and fix vulnerabilities in your open-source dependencies without leaving your editor. It scans your project’s manifests and lockfiles to detect outdated or insecure packages, highlight affected versions, and suggest safe upgrades.

<figure><img src="/files/fdOBcguka3bYLdYh5k12" alt=""><figcaption></figcaption></figure>

### How it works

* Aikido reads your dependency manifests and lockfiles to build an accurate list of packages and versions.
* Results include known CVEs, severity, affected versions, and safe upgrade ranges.
* After you run a manual SCA scan once, the extension watches your workspace for lockfile changes and refreshes results automatically.

### Run a manual SCA scan

#### VSCode

1. Open the Aikido sidebar in VS Code.
2. Go to Open-source dependencies.
3. Click Start scanning.
4. When results appear, select a package to view details, advisories, and fix guidance.
5. Each finding shows the minimum safe version or version ranges that resolve the issue.
6. For supported ecosystems, [AI AutoFix](/ai-and-dev-tools/ide-plugins-overview/features/aikido-ai-in-ide) can update the manifest or suggest a safe version bump that you can apply from the IDE.

#### Eclipse

1. Open "Aikido Workspace Scan"
2. Press "Scan All Code"
3. When results appear, select a package lockfile to view details, advisories, and fix guidance.
4. Each finding shows the minimum safe version or version ranges that resolve the issue.

<figure><img src="/files/zl3SDM6w9Yj74ceBytoB" alt=""><figcaption></figcaption></figure>


# Supported languages in IDE

## Secrets

Secret scanning can analyze any file that stores its content as text, including code, configuration files, logs, and documentation.

## Code Issues (SAST) Language Support

* Android
* Apex
* C/C++
* C# / .NET
* Clojure
* Dart
* Elixir
* Go
* Java
* JavaScript
* Kotlin
* Python
* PHP
* Ruby
* Rust
* Scala
* Swift
* TypeScript
* Visual Basic

## Open-Source Dependency Scanning (SCA) Support

Same as Aikido platform scans

{% content-ref url="/pages/E5ENgfMdszxSZ3Wiv6vc" %}
[Support for Dependency Scanning by Language (SCA)](/code-scanning/scanning-practices/support-for-dependency-scanning-by-language)
{% endcontent-ref %}


# IDE Adoption Stats

The IDE Adoption Stats page gives you visibility into how Aikido is used across your organization. It shows both IDE usage and [Aikido Expansion Pack](/ai-and-dev-tools/ide-plugins-overview/features/aikido-expansion-packs) installation and adoption, per developer.

This helps you understand which IDEs are actively used, which security capabilities are enabled, and where additional rollout or onboarding may be needed.

<figure><img src="/files/DSsl4yaI1QYBDMXl06e1" alt=""><figcaption></figcaption></figure>

You can find this page by going to Integrations and clicking Adoption Stats.

<figure><img src="/files/TJmRGmwJsAagjGRW8P5r" alt=""><figcaption></figcaption></figure>

### Why this matters

IDE Adoption Stats help you:

* Track IDE usage across your development teams
* Verify that expansion packs are installed and used
* Identify developers who may need setup or onboarding help
* Measure adoption after rolling out new IDE features or security capabilities

### Who can access this

IDE Adoption Stats are available to organization admins


# Difference Between Aikido Cloud Scanning and IDE Scanning

Aikido offers security scanning in two places: inside the developer’s editor and in the cloud platform. Both scan code and dependencies, but with different depth and context.

### Cloud Scans

* Run SAST, SCA and IaC checks across full repositories and connected cloud environments.
* Analyse complete codebases, dependency graphs and configuration files rather than only what is open in the editor.
* Provide richer context, for example reachability, deployment paths, and whether an issue affects production.
* Use advanced auto triage to cut down false positives and highlight real risk.
* Suitable for full-scope audits, CI pipelines and organisation-wide posture.

### IDE Scans

* Run SAST and SCA directly in the editor for fast feedback while coding.
* Limited to the current project and the files or manifests present in the workspace.
* Shallower analysis because it needs to be fast and local.
* Less context about how the code is built or deployed, so more findings require manual validation.
* Helpful for preventing issues before commit, but not a replacement for full cloud-based scanning.


# Cursor IDE

Aikido automatically scans your projects for hardcoded secrets (API keys, tokens) and insecure code patterns (SQL injections, path traversal, ..) so you can catch issues early and keep your codebase safe.

Scans run automatically whenever you open a file or save changes, making it easy to catch issues early in development.

When security issues are found, they're highlighted directly in your code and listed in the Aikido window.

{% stepper %}
{% step %}

### Open Extensions and Install "Aikido Security"

<figure><img src="/files/TP6PMzhEQHNmNy8WihAT" alt=""><figcaption></figcaption></figure>

Alternatively use these links to go to the Marketplaces

* [VS Code](https://marketplace.visualstudio.com/items?itemName=AikidoSecurity.aikido)
* [Windsurf](https://open-vsx.org/extension/AikidoSecurity/aikido) / [Cursor](https://open-vsx.org/extension/AikidoSecurity/aikido) / [Kiro](https://open-vsx.org/extension/AikidoSecurity/aikido) / [Google Antigravity](https://open-vsx.org/extension/AikidoSecurity/aikido)
  {% endstep %}

{% step %}

### Authenticate with Aikido

<img src="/files/ONAv4fYbgTXF7pMJ6iot" alt="" data-size="line"> Open the Aikido plugin by clicking on the sidebar icon and click on "Connect to Aikido" to authenticate with Aikido platform.

<figure><img src="/files/K7BvEJyzOdUEKqumgfdI" alt=""><figcaption></figcaption></figure>

Alternatively you can open up the Command Palette and run `Aikido: Log In`

If the automated authentication does not work you can manually create a personal access within Aikido by going to the [Integrations page and following the instructions](https://app.aikido.dev/settings/integrations?section=ide).
{% endstep %}

{% step %}

### Try out our examples

Below you can find an example `index.js` file that can be used to verify if the extension is working correctly, it should detect one SAST issue (SQL injection) and one exposed secret (SQL Server connection string).

```javascript
const app = {}

app.get("/user", (req, res) => {
    const connStr = "Server=tcp:myserver.database.windows.net,1433;Initial Catalog=mydb;Persist Security Info=False;User ID=myuser;Password=$uperSecret123!@#";
    const username = req.query.username
    const unsafeQuery = `SELECT * FROM users WHERE username = '${username}'`
    sql.connect(connStr).query(unsafeQuery, (err, result) => {
        res.status(200).send(result)
    })
})
```

{% endstep %}

{% step %}

### Turn on Additional Security Tooling

Extend Aikido in your IDE with Expansion Packs like [MCP for AI agents](/ai-and-dev-tools/aikido-mcp), [pre-commit hooks](/ai-and-dev-tools/aikido-secrets-pre-commit-hook), and [Safe Chain](/code-scanning/aikido-malware-scanning). For more details, see the documentation below.

{% content-ref url="/pages/BlcMVHrRgvP9HMKc2BJs" %}
[Aikido Expansion Packs](/ai-and-dev-tools/ide-plugins-overview/features/aikido-expansion-packs)
{% endcontent-ref %}
{% endstep %}
{% endstepper %}

Now that the plugin is installed, you can dive into the features that help you spot security issues while you work:

{% content-ref url="/pages/JahfnwEjZfhYiedCJiRf" %}
[Real-time SAST, Secrets and IaC scanning in IDE](/ai-and-dev-tools/ide-plugins-overview/features/real-time-code-scanning-in-ide)
{% endcontent-ref %}

{% content-ref url="/pages/7i2dwzkrBY6h9JJxKMiv" %}
[Broken mention](broken://pages/7i2dwzkrBY6h9JJxKMiv)
{% endcontent-ref %}

{% content-ref url="/pages/VHkf3JZol0Ev7NoGW7Mo" %}
[Open-Source Dependency Scanning (SCA) in IDE](/ai-and-dev-tools/ide-plugins-overview/features/open-source-dependency-scanning-sca-in-ide)
{% endcontent-ref %}

{% content-ref url="/pages/PnC2O8bNLN58q3huxlu2" %}
[Full Workspace Scan in IDE](/ai-and-dev-tools/ide-plugins-overview/features/full-workspace-scan-in-ide)
{% endcontent-ref %}

{% content-ref url="/pages/DQN8YWwg6NjpNanCvqwo" %}
[Aikido AI in IDE](/ai-and-dev-tools/ide-plugins-overview/features/aikido-ai-in-ide)
{% endcontent-ref %}

{% content-ref url="/pages/EdBhlGHmXPTI17yEJA8f" %}
[VS Code - Extension Keeps Disconnecting](/ai-and-dev-tools/ide-plugins-overview/troubleshooting/vs-code-extension-keeps-disconnecting)
{% endcontent-ref %}

{% content-ref url="/pages/U2xtX88ANZV0NrYmqi0D" %}
[VS Code - Information for Support](/ai-and-dev-tools/ide-plugins-overview/troubleshooting/vs-code-information-for-support)
{% endcontent-ref %}

## Aikido MCP for Cursor

You can add Aikido Cursor Plugin to your Cursor AI workflow via Expansion Packs or the Cursor Marketplace. The plugin lets Cursor scan your code for security issues as you build.

[Set up Aikido MCP for Cursor](https://help.aikido.dev/ai-and-dev-tools/aikido-mcp/cursor-mcp)


# Eclipse IDE

Aikido automatically scans your projects for hardcoded secrets (API keys, tokens) and insecure code patterns (SQL injections, path traversal, ..) so you can catch issues early and keep your codebase safe.

Scans run automatically whenever you open a file or save changes, making it easy to catch issues early in development.

When security issues are found, they're highlighted directly in your code and listed in the Aikido window.

## Installation and Authentication

{% stepper %}
{% step %}
**Go to the** [**Eclipse marketplace**](https://marketplace.eclipse.org/content/aikido-security) **and install the Aikido Plugin**

In Eclipse, go to `Help` > `Eclipse Marketplace...` and look for 'Aikid&#x6F;*'* in the search bar. Click 'Install'.

<figure><img src="/files/UdkQODjTzsThingB2aLz" alt=""><figcaption></figcaption></figure>

After installation, restart Eclipse.
{% endstep %}

{% step %}
**Authenticate with Aikido**

In Aikido, go to the [Eclipse Integration Screen](https://app.aikido.dev/settings/integrations/ide/eclipse) and create your token.

<figure><img src="/files/GDumRJ0qo4Ovj2azT949" alt=""><figcaption></figcaption></figure>

After installation the Aikido Security View will open automatically in Eclipse. If this is not the case, go to `Window` > `Show View` > `Other...` > Look for Aikido and select the 'Aikido Security' view. In the Aikido Security view, click `Connect to Aikido` and enter your token.

<figure><img src="/files/PTd3OGNmO3TvtUftTmO7" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Try out an example**

Below you can find an example `sample.java` file that can be used to verify if the extension is working correctly, it should detect one SAST issue on line 29 and one exposed secret on line 23.

```java
import java.sql.Connection;
import java.sql.DriverManager;
import java.sql.ResultSet;
import java.sql.Statement;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import com.google.gson.Gson;
import java.io.IOException;
import java.util.ArrayList;
import java.util.HashMap;
import java.util.List;
import java.util.Map;

public class UserServlet extends HttpServlet {
    
    @Override
    protected void doGet(HttpServletRequest req, HttpServletResponse res) 
            throws IOException {
        String connStr = "jdbc:sqlserver://myserver.database.windows.net:1433;" +
                        "database=mydb;" +
                        "user=myuser;" +
                        "password=$uperSecret123!@#;" +
                        "encrypt=true;" +
                        "trustServerCertificate=false;" +
                        "loginTimeout=30;";
        
        String username = req.getParameter("username");
        String unsafeQuery = "SELECT * FROM users WHERE username = '" + username + "'";
        
        try (Connection conn = DriverManager.getConnection(connStr);
             Statement stmt = conn.createStatement();
             ResultSet result = stmt.executeQuery(unsafeQuery)) {
            
            // Convert ResultSet to JSON-like structure
            List<Map<String, Object>> resultList = new ArrayList<>();
            int columnCount = result.getMetaData().getColumnCount();
            
            while (result.next()) {
                Map<String, Object> row = new HashMap<>();
                for (int i = 1; i <= columnCount; i++) {
                    row.put(result.getMetaData().getColumnName(i), 
                           result.getObject(i));
                }
                resultList.add(row);
            }
            
            res.setStatus(200);
            res.setContentType("application/json");
            res.getWriter().write(new Gson().toJson(resultList));
            
        } catch (Exception e) {
            res.setStatus(500);
            res.getWriter().write("Error: " + e.getMessage());
        }
    }
}
```

{% endstep %}
{% endstepper %}

### Uninstall

To uninstall the Aikido Eclipse plugin:

Go to `Help` > `Eclipse Marketplace...` > `Installed` > Look for Aikido Security and click `Uninstall`




---

[Next Page](/llms-full.txt/1)

