Prerequisites
- Admin access to the Semgrep AppSec Platform. Only admins can create API tokens.
- Repositories already scanned by Semgrep, if you want agents to read existing findings.
Setup
1
Create an API token
In the Semgrep AppSec Platform, go to Settings → Tokens → API tokens and click Create new token.
2
Set the scope and copy the token
Under Token scopes, select Web API, name it
cloudthinker, and copy the Secrets value. Semgrep shows it only once. Click Save.3
Add the connection in CloudThinker
Navigate to Connections → Semgrep, paste the token into SEMGREP_APP_TOKEN, and click Connect. CloudThinker shows a Connected status.
Connected does not prove the token works. Semgrep checks it the first time an agent reads platform findings, so run the verify prompt below.
Connection details
Required permissions
Agent capabilities
Agent scans analyze one function at a time. For cross-file results from your CI scans, ask agents to read platform findings.
Verify the connection
Example prompts
Troubleshooting
Platform findings fail to load
Platform findings fail to load
The token is wrong, revoked, or has the Agent (CI) scope. Create a Web API token and update the connection.
A scan returns no findings
A scan returns no findings
The rule set may not match the file’s language. Ask the agent to use a rule set for that language, such as
p/python.Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Revoke when done — Semgrep API tokens do not expire. Revoke the token under Settings → Tokens when you remove the connection.
Related
GitGuardian Connection
Secrets detection and incident triage
SonarQube Connection
Code quality and security scanning