Skip to main content
Connect Prowler to let CloudThinker agents review failed security checks, affected resources, and compliance status. Prowler authenticates with an API key, and the connection is read-only.

Prerequisites

  • A Prowler Cloud account, or a self-managed Prowler that CloudThinker can reach.
  • At least one cloud account already scanned in Prowler.
  • A Prowler user with the Manage Account permission. Prowler requires it to create API keys.

Setup

1

Create an API key

In Prowler, go to Profile → Account and click Create API Key. Name it cloudthinker and optionally set an expiration date; without one, the key expires after 365 days.Click Create API Key and copy the key. Prowler shows it only once.
2

Add the connection in CloudThinker

Navigate to Connections → Prowler and enter:
  • PROWLER_API_KEY: the key you copied
  • API_BASE_URL: leave blank for Prowler Cloud, or enter your self-managed Prowler API address
Click Connect. CloudThinker shows a Connected status.
Connected does not prove the key works. Prowler checks it the first time an agent calls it, so run the verify prompt below.

Connection details


Required permissions

A Prowler API key has the permissions of the user who created it.
Create the key from a dedicated Prowler user, so you can manage its access without affecting anyone else.

Agent capabilities

Agents only read results. They cannot add accounts, start scans, or mute findings.

Verify the connection

Example prompts


Troubleshooting

Prowler rejected the key. It may be mistyped, expired, or revoked, or its user was removed from the tenant. Create a new key and update the connection.
API_BASE_URL is wrong. Clear it for Prowler Cloud, or enter your self-managed API address ending in /api/v1.
The key’s user cannot see any providers, or nothing has been scanned yet. Give the user Unlimited Visibility or the right provider groups, and check that Prowler has scan results.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Revoke, do not delete — Prowler cannot delete an API key. Use Revoke to disable a key you no longer need.
  • Rotate before expiry — keys expire after 365 days by default.

GitGuardian Connection

Secrets detection and incident triage

AWS Connection

Inspect the accounts Prowler scans