> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloudthinker.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Semgrep

> Connect Semgrep to CloudThinker to scan code for security issues, write custom rules, and review findings from the Semgrep AppSec Platform

Connect Semgrep to let CloudThinker agents scan code, test custom rules, and read the findings Semgrep has reported for your repositories. Semgrep authenticates with an **API token** from the Semgrep AppSec Platform.

***

## Prerequisites

* **Admin** access to the Semgrep AppSec Platform. Only admins can create API tokens.
* Repositories already scanned by Semgrep, if you want agents to read existing findings.

***

## Setup

<Steps>
  <Step title="Create an API token">
    In the [Semgrep AppSec Platform](https://semgrep.dev/login), go to **Settings → Tokens → API tokens** and click **Create new token**.
  </Step>

  <Step title="Set the scope and copy the token">
    Under **Token scopes**, select **Web API**, name it `cloudthinker`, and copy the **Secrets value**. Semgrep shows it only once. Click **Save**.
  </Step>

  <Step title="Add the connection in CloudThinker">
    Navigate to **Connections → Semgrep**, paste the token into **SEMGREP\_APP\_TOKEN**, and click **Connect**. CloudThinker shows a **Connected** status.
  </Step>
</Steps>

<Note>
  **Connected** does not prove the token works. Semgrep checks it the first time an agent reads platform findings, so run the verify prompt below.
</Note>

***

## Connection details

| Field | Description | Example |
| - | - | - |
| **SEMGREP\_APP\_TOKEN** | Semgrep API token | `<your-api-token>` |

***

## Required permissions

| Token scope | Works with CloudThinker |
| - | - |
| **Web API** | Yes. Use this scope |
| **Agent (CI)** | No. It cannot read platform findings |

<Tip>
  Use a token only for CloudThinker, so you can revoke it without breaking your CI scans.
</Tip>

***

## Agent capabilities

| Capability | Description |
| - | - |
| **Code scans** | Scan files with a rule set, such as `p/python` |
| **Custom rules** | Write a rule and test it against files |
| **Platform findings** | Open code and supply chain findings, filtered by repository, severity, or status |
| **Language support** | Languages Semgrep can scan |

Agent scans analyze one function at a time. For cross-file results from your CI scans, ask agents to read platform findings.

### Verify the connection

```text theme={null}
Check Semgrep: list the supported languages and show a few open findings from the platform
```

### Example prompts

```text theme={null}
Scan app.py and server.ts with Semgrep and summarize any security findings
List open high and critical Semgrep findings for the payments repository
Write a Semgrep rule that flags use of eval, then test it against config.py
```

***

## Troubleshooting

<Accordion title="Platform findings fail to load">
  The token is wrong, revoked, or has the **Agent (CI)** scope. Create a **Web API** token and update the connection.
</Accordion>

<Accordion title="A scan returns no findings">
  The rule set may not match the file's language. Ask the agent to use a rule set for that language, such as `p/python`.
</Accordion>

***

## Security

* **Least privilege** — grant only the permissions the agents need for your use case; start read-only and widen later.
* **Read-only by default** — use read-only credentials unless you want agents to make changes through this connection.
* **Rotate credentials** — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
* **Revoke on offboarding** — remove the credential at the provider when you delete a connection or a teammate leaves.

- **Revoke when done** — Semgrep API tokens do not expire. Revoke the token under **Settings → Tokens** when you remove the connection.

***

## Related

<CardGroup cols={2}>
  <Card title="GitGuardian Connection" icon="https://mintcdn.com/cloudthinker/tTYzPaZv-jtM39C4/images/icons/gitguardian.svg?fit=max&auto=format&n=tTYzPaZv-jtM39C4&q=85&s=b89a979a6dd2d28506ae7517286d83e4" href="/guide/connections/gitguardian" width="24" height="24" data-path="images/icons/gitguardian.svg">
    Secrets detection and incident triage
  </Card>

  <Card title="SonarQube Connection" icon="https://mintcdn.com/cloudthinker/aLd-ttc-SCW-aFky/images/icons/sonarqube.svg?fit=max&auto=format&n=aLd-ttc-SCW-aFky&q=85&s=b667e04fbb28aa908d4777071a5a7414" href="/guide/connections/sonarqube" width="24" height="24" data-path="images/icons/sonarqube.svg">
    Code quality and security scanning
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.