Snyk Integration
Connect Snyk to let agents read your vulnerability posture during investigations, remediation runs, and release reviews. Snyk continuously scans your projects and keeps an inventory of known vulnerabilities; this integration lets agents read that inventory:
- The org-wide list of issues (vulnerabilities) with severity, type, and the exact fix / upgrade path.
- The projects Snyk monitors and which repo owns each.
- Per-project SBOMs (the dependency inventory).
Instead of opening the Snyk dashboard to judge risk, an agent can pull the worst fixable issues, see which service owns each, and use the fix guidance as the input for a remediation that a human reviews.
Used by: Vulnerability Remediation, Incident Response, and custom agents.
Read-only. Every call is a GET against the Snyk REST API. Autoheal reads your Snyk
issues, projects, and SBOMs; it never ignores issues, edits policies, or changes project
settings — there is no write path to Snyk. Any fix to your code happens as a pull
request in your own repository that a human reviews.
Capabilities
Once connected, agents can:
| Capability | Description |
|---|---|
| List issues | Read the org-wide vulnerability inventory — each issue's effective_severity_level, type, CVE/CWE (problems), CVSS severities, exploit maturity, and the fix signal in coordinates (is_fixable_*, is_upgradeable, remedies, reachability). Filter by severity and type; scope to one project. |
| Issue detail | Read one issue's full detail — the remediation input for a fix |
| List projects | Enumerate monitored projects with their type, owning repo (target), and latest issue counts by severity |
| Project SBOM | Export a project's Software Bill of Materials (CycloneDX / SPDX) — the exact dependency inventory (Snyk Enterprise plan) |
| List organizations | Enumerate the organizations the token can access (to find your Organization ID or target another org) |
Prerequisites
- A Snyk account with at least one monitored project
- A service-account token (recommended over a personal token — see below)
- Your Organization ID and the region your Snyk tenant is hosted in
Authentication
Autoheal authenticates with a Snyk service-account token. A service account (rather than a personal token) keeps access working when a person leaves and lets you scope least-privilege, read-only access.
| Field | What you provide |
|---|---|
| Region | The Snyk region hosting your tenant: us (SNYK-US-01, api.snyk.io), us-02 (SNYK-US-02, api.us.snyk.io), eu (SNYK-EU-01, api.eu.snyk.io), or au (SNYK-AU-01, api.au.snyk.io). Tokens are region-bound — a token created in one region returns 401 against another region. |
| Organization ID | Your Snyk Organization ID, a UUID (Snyk → Settings → General → Organization ID). Scopes the reads. |
| API Token | The service-account token value, created in the same region and shown only once. |
Setup
In Snyk, go to your Organization Settings → Service accounts → Create a service account. Give it a name (e.g. "Autoheal") and a read-only role (for example Org Admin (read only) or Viewer). Copy the token — it is shown only once.
Create the service account in the same region your organization lives in; tokens do not work across regions.
In Snyk, go to Settings → General and copy the Organization ID (a UUID). Note which region your tenant is on (from the Snyk URL / your account's data residency).
- Go to Integrations in Autoheal and click Snyk.
- Enter a name (e.g. "Production Snyk").
- Region: select the region your tenant is hosted in.
- Organization ID: paste the UUID.
- API Token: paste the service-account token.
Click Test Connection to verify the token and region, then Save.
Required Permissions
Autoheal only reads. A read-only service-account role covering the organization's projects and issues is sufficient:
| Snyk resource | Access | Why it's needed |
|---|---|---|
| Organizations | read | Resolve and enumerate the org(s) the token can see |
| Projects | read | Enumerate monitored projects and their owning targets |
| Issues | read | The vulnerability inventory and per-issue fix guidance |
| SBOM export | read | Per-project dependency inventory (requires a Snyk Enterprise plan) |
Example Queries
Once connected, you can ask an agent questions like:
What are our 10 worst fixable vulnerabilities right now, and which service owns each?
List the critical and high vulnerabilities in the payments-service project that have an upgrade path.
For issue <id>, what version fixes it and is it reachable?
Which projects have critical vulnerabilities, and which repo owns each?
Troubleshooting
401 Unauthorized
- The most common cause is a region mismatch — the token was created in a different region than the one selected. Snyk tokens are region-bound; re-select the region or create a token in the right region.
- Confirm the token was copied in full (it is shown only once) and has not been revoked.
No issues or projects returned
- Confirm the Organization ID is correct and the service account has read access to that organization's projects.
- A service-account token is typically scoped to a single organization; to read another org, pass its id explicitly or use a token with access to it.
403 Forbidden on SBOM export
- SBOM export requires a Snyk Enterprise plan. On other plans the other tools still work; SBOM export returns 403.