Prerequisites
- A Prowler Cloud account, or a self-managed Prowler that CloudThinker can reach.
- At least one cloud account already scanned in Prowler.
- A Prowler user with the Manage Account permission. Prowler requires it to create API keys.
Setup
1
Create an API key
In Prowler, go to Profile → Account and click Create API Key. Name it
cloudthinker and optionally set an expiration date; without one, the key expires after 365 days.Click Create API Key and copy the key. Prowler shows it only once.2
Add the connection in CloudThinker
Navigate to Connections → Prowler and enter:
- PROWLER_API_KEY: the key you copied
- API_BASE_URL: leave blank for Prowler Cloud, or enter your self-managed Prowler API address
Connected does not prove the key works. Prowler checks it the first time an agent calls it, so run the verify prompt below.
Connection details
Required permissions
A Prowler API key has the permissions of the user who created it.Agent capabilities
Agents only read results. They cannot add accounts, start scans, or mute findings.
Verify the connection
Example prompts
Troubleshooting
Every request fails with 401
Every request fails with 401
Prowler rejected the key. It may be mistyped, expired, or revoked, or its user was removed from the tenant. Create a new key and update the connection.
Requests fail with a not-found error
Requests fail with a not-found error
API_BASE_URL is wrong. Clear it for Prowler Cloud, or enter your self-managed API address ending in
/api/v1.Agents see no providers or findings
Agents see no providers or findings
The key’s user cannot see any providers, or nothing has been scanned yet. Give the user Unlimited Visibility or the right provider groups, and check that Prowler has scan results.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Revoke, do not delete — Prowler cannot delete an API key. Use Revoke to disable a key you no longer need.
- Rotate before expiry — keys expire after 365 days by default.
Related
GitGuardian Connection
Secrets detection and incident triage
AWS Connection
Inspect the accounts Prowler scans