About Semgrep
Iru calls Semgrep’s Web API for findings, projects, and policies. Tokens must include the Web API scope - Agent/CI-only tokens return 404s on web endpoints. Team or Enterprise tier is typically required for API access.How It Works
| Detail | Value |
|---|---|
| Category | Application security |
| Authentication | Bearer (Web API scope) |
Prerequisites
- Admin or Owner on the Semgrep org.
Connect Semgrep to Iru
- Semgrep
- Iru Compliance
Complete this tab before you connect the source in Compliance.
Sign in to Semgrep
Open the Semgrep AppSec Platform and sign in with an Admin or Owner for the organization Iru should read.
Open Tokens
Navigate to Tokens, then API tokens (wording may read API Tokens or Personal access tokens).
Enable Web API scope
Enable the Web API scope (required for this connector). Remove any write scopes your security team does not want for evidence-only use.
Continue on the Iru Compliance tab.
Troubleshooting
Nothing opens when you turn the source on
Nothing opens when you turn the source on
Check pop-up blocker settings for the Iru site and try again.
404 on API
404 on API
Recreate token with Web API scope.
No API features
No API features
Upgrade to a tier that includes API access.
Related Articles
Sources Management
Browse and manage every Compliance source.
Getting Started With Compliance
Frameworks, actions, and Artifacts.
Iru Overview
How Endpoint, Compliance, and Identity fit together.
Artifacts Management
Upload, review, and organize evidence from sources and actions.
