> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloudthinker.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Prowler

> Connect Prowler to CloudThinker to review failed security findings, exposed resources, and compliance status across your cloud accounts

Connect Prowler to let CloudThinker agents review failed security checks, affected resources, and compliance status. Prowler authenticates with an **API key**, and the connection is read-only.

***

## Prerequisites

* A **Prowler Cloud** account, or a self-managed Prowler that CloudThinker can reach.
* At least one cloud account already scanned in Prowler.
* A Prowler user with the **Manage Account** permission. Prowler requires it to create API keys.

***

## Setup

<Steps>
  <Step title="Create an API key">
    In Prowler, go to **Profile → Account** and click **Create API Key**. Name it `cloudthinker` and optionally set an expiration date; without one, the key expires after 365 days.

    Click **Create API Key** and copy the key. Prowler shows it only once.
  </Step>

  <Step title="Add the connection in CloudThinker">
    Navigate to **Connections → Prowler** and enter:

    * **PROWLER\_API\_KEY**: the key you copied
    * **API\_BASE\_URL**: leave blank for Prowler Cloud, or enter your self-managed Prowler API address

    Click **Connect**. CloudThinker shows a **Connected** status.
  </Step>
</Steps>

<Note>
  **Connected** does not prove the key works. Prowler checks it the first time an agent calls it, so run the verify prompt below.
</Note>

***

## Connection details

| Field | Description | Example |
| - | - | - |
| **PROWLER\_API\_KEY** | Prowler API key | `<your-api-key>` |
| **API\_BASE\_URL** | Optional. Prowler API address. Default `https://api.prowler.com/api/v1` | `https://prowler.example.com/api/v1` |

***

## Required permissions

A Prowler API key has the permissions of the user who created it.

| Goal | Prowler setup |
| - | - |
| Read findings, resources, and compliance | **Unlimited Visibility**, or the provider groups agents should see |
| Create the key | **Manage Account** |

<Tip>
  Create the key from a dedicated Prowler user, so you can manage its access without affecting anyone else.
</Tip>

***

## Agent capabilities

| Capability | Description |
| - | - |
| **Provider coverage** | Cloud accounts Prowler monitors |
| **Failed findings** | Failed checks by severity, with details |
| **Resources** | Affected resources and their findings |
| **Compliance** | Framework status and failing requirements |
| **Checks** | What a Prowler check covers |

Agents only read results. They cannot add accounts, start scans, or mute findings.

### Verify the connection

```text theme={null}
Summarize my Prowler providers and the count of failed findings by severity
```

### Example prompts

```text theme={null}
List the critical failed Prowler findings and the resources they affect
Which Prowler compliance frameworks have the most failing requirements?
Show the Prowler resource inventory for my AWS accounts
```

***

## Troubleshooting

<Accordion title="Every request fails with 401">
  Prowler rejected the key. It may be mistyped, expired, or revoked, or its user was removed from the tenant. Create a new key and update the connection.
</Accordion>

<Accordion title="Requests fail with a not-found error">
  **API\_BASE\_URL** is wrong. Clear it for Prowler Cloud, or enter your self-managed API address ending in `/api/v1`.
</Accordion>

<Accordion title="Agents see no providers or findings">
  The key's user cannot see any providers, or nothing has been scanned yet. Give the user **Unlimited Visibility** or the right provider groups, and check that Prowler has scan results.
</Accordion>

***

## Security

* **Least privilege** — grant only the permissions the agents need for your use case; start read-only and widen later.
* **Read-only by default** — use read-only credentials unless you want agents to make changes through this connection.
* **Rotate credentials** — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
* **Revoke on offboarding** — remove the credential at the provider when you delete a connection or a teammate leaves.

- **Revoke, do not delete** — Prowler cannot delete an API key. Use **Revoke** to disable a key you no longer need.
- **Rotate before expiry** — keys expire after 365 days by default.

***

## Related

<CardGroup cols={2}>
  <Card title="GitGuardian Connection" icon="https://mintcdn.com/cloudthinker/tTYzPaZv-jtM39C4/images/icons/gitguardian.svg?fit=max&auto=format&n=tTYzPaZv-jtM39C4&q=85&s=b89a979a6dd2d28506ae7517286d83e4" href="/guide/connections/gitguardian" width="24" height="24" data-path="images/icons/gitguardian.svg">
    Secrets detection and incident triage
  </Card>

  <Card title="AWS Connection" icon="https://mintcdn.com/cloudthinker/aLd-ttc-SCW-aFky/images/icons/aws.svg?fit=max&auto=format&n=aLd-ttc-SCW-aFky&q=85&s=45d526a3e9345214c0345f277da2e829" href="/guide/connections/aws" width="24" height="24" data-path="images/icons/aws.svg">
    Inspect the accounts Prowler scans
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.