Skip to main content

Snyk Integration

Connect Snyk to let agents read your vulnerability posture during investigations, remediation runs, and release reviews. Snyk continuously scans your projects and keeps an inventory of known vulnerabilities; this integration lets agents read that inventory:

  • The org-wide list of issues (vulnerabilities) with severity, type, and the exact fix / upgrade path.
  • The projects Snyk monitors and which repo owns each.
  • Per-project SBOMs (the dependency inventory).

Instead of opening the Snyk dashboard to judge risk, an agent can pull the worst fixable issues, see which service owns each, and use the fix guidance as the input for a remediation that a human reviews.

Used by: Vulnerability Remediation, Incident Response, and custom agents.

note

Read-only. Every call is a GET against the Snyk REST API. Autoheal reads your Snyk issues, projects, and SBOMs; it never ignores issues, edits policies, or changes project settings — there is no write path to Snyk. Any fix to your code happens as a pull request in your own repository that a human reviews.

Capabilities​

Once connected, agents can:

CapabilityDescription
List issuesRead the org-wide vulnerability inventory — each issue's effective_severity_level, type, CVE/CWE (problems), CVSS severities, exploit maturity, and the fix signal in coordinates (is_fixable_*, is_upgradeable, remedies, reachability). Filter by severity and type; scope to one project.
Issue detailRead one issue's full detail — the remediation input for a fix
List projectsEnumerate monitored projects with their type, owning repo (target), and latest issue counts by severity
Project SBOMExport a project's Software Bill of Materials (CycloneDX / SPDX) — the exact dependency inventory (Snyk Enterprise plan)
List organizationsEnumerate the organizations the token can access (to find your Organization ID or target another org)

Prerequisites​

  • A Snyk account with at least one monitored project
  • A service-account token (recommended over a personal token — see below)
  • Your Organization ID and the region your Snyk tenant is hosted in

Authentication​

Autoheal authenticates with a Snyk service-account token. A service account (rather than a personal token) keeps access working when a person leaves and lets you scope least-privilege, read-only access.

FieldWhat you provide
RegionThe Snyk region hosting your tenant: us (SNYK-US-01, api.snyk.io), us-02 (SNYK-US-02, api.us.snyk.io), eu (SNYK-EU-01, api.eu.snyk.io), or au (SNYK-AU-01, api.au.snyk.io). Tokens are region-bound — a token created in one region returns 401 against another region.
Organization IDYour Snyk Organization ID, a UUID (Snyk → Settings → General → Organization ID). Scopes the reads.
API TokenThe service-account token value, created in the same region and shown only once.

Setup​

1
Create a service account in Snyk

In Snyk, go to your Organization Settings → Service accounts → Create a service account. Give it a name (e.g. "Autoheal") and a read-only role (for example Org Admin (read only) or Viewer). Copy the token — it is shown only once.

Create the service account in the same region your organization lives in; tokens do not work across regions.

2
Find your Organization ID and region

In Snyk, go to Settings → General and copy the Organization ID (a UUID). Note which region your tenant is on (from the Snyk URL / your account's data residency).

3
Add the Integration in Autoheal
  1. Go to Integrations in Autoheal and click Snyk.
  2. Enter a name (e.g. "Production Snyk").
4
Configure Credentials
  • Region: select the region your tenant is hosted in.
  • Organization ID: paste the UUID.
  • API Token: paste the service-account token.
5
Test and Save

Click Test Connection to verify the token and region, then Save.

Required Permissions​

Autoheal only reads. A read-only service-account role covering the organization's projects and issues is sufficient:

Snyk resourceAccessWhy it's needed
OrganizationsreadResolve and enumerate the org(s) the token can see
ProjectsreadEnumerate monitored projects and their owning targets
IssuesreadThe vulnerability inventory and per-issue fix guidance
SBOM exportreadPer-project dependency inventory (requires a Snyk Enterprise plan)

Example Queries​

Once connected, you can ask an agent questions like:

What are our 10 worst fixable vulnerabilities right now, and which service owns each?
List the critical and high vulnerabilities in the payments-service project that have an upgrade path.
For issue <id>, what version fixes it and is it reachable?
Which projects have critical vulnerabilities, and which repo owns each?

Troubleshooting​

401 Unauthorized
  • The most common cause is a region mismatch — the token was created in a different region than the one selected. Snyk tokens are region-bound; re-select the region or create a token in the right region.
  • Confirm the token was copied in full (it is shown only once) and has not been revoked.
No issues or projects returned
  • Confirm the Organization ID is correct and the service account has read access to that organization's projects.
  • A service-account token is typically scoped to a single organization; to read another org, pass its id explicitly or use a token with access to it.
403 Forbidden on SBOM export
  • SBOM export requires a Snyk Enterprise plan. On other plans the other tools still work; SBOM export returns 403.