Skip to main content
Connect Semgrep to let CloudThinker agents scan code, test custom rules, and read the findings Semgrep has reported for your repositories. Semgrep authenticates with an API token from the Semgrep AppSec Platform.

Prerequisites

  • Admin access to the Semgrep AppSec Platform. Only admins can create API tokens.
  • Repositories already scanned by Semgrep, if you want agents to read existing findings.

Setup

1

Create an API token

In the Semgrep AppSec Platform, go to Settings → Tokens → API tokens and click Create new token.
2

Set the scope and copy the token

Under Token scopes, select Web API, name it cloudthinker, and copy the Secrets value. Semgrep shows it only once. Click Save.
3

Add the connection in CloudThinker

Navigate to Connections → Semgrep, paste the token into SEMGREP_APP_TOKEN, and click Connect. CloudThinker shows a Connected status.
Connected does not prove the token works. Semgrep checks it the first time an agent reads platform findings, so run the verify prompt below.

Connection details


Required permissions

Use a token only for CloudThinker, so you can revoke it without breaking your CI scans.

Agent capabilities

Agent scans analyze one function at a time. For cross-file results from your CI scans, ask agents to read platform findings.

Verify the connection

Example prompts


Troubleshooting

The token is wrong, revoked, or has the Agent (CI) scope. Create a Web API token and update the connection.
The rule set may not match the file’s language. Ask the agent to use a rule set for that language, such as p/python.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Revoke when done — Semgrep API tokens do not expire. Revoke the token under Settings → Tokens when you remove the connection.

GitGuardian Connection

Secrets detection and incident triage

SonarQube Connection

Code quality and security scanning