vendor- The Enum of the vendor product you want to connect to.credentials- The specific credential body for the vendor you are connecting to, this is not required for Oauth based connections.options- (Optional) Any additional options you want to pass to the connection, each vendor has different options available.
VMS Connections
Tenable
Tenable
Qualys
Qualys
InsightVM
InsightVM
MS Defender VMS
MS Defender VMS
Admin consent — the customer authorizes Leen’s Microsoft Defender app. The response carries an
Or the customer’s own app registration. All three values are required together, and the response
carries no More info on both flows can be found here
oauth2_authorize_url to send them to.oauth2_authorize_url — the connection is active immediately.SentinelOne VMS
SentinelOne VMS
CrowdStrike Spotlight
CrowdStrike Spotlight
AWS Inspector2
AWS Inspector2
Direct access
Direct access
Leen Role
Leen Role
Role Chaining
Role Chaining
Wiz VMS
Wiz VMS
EDR Connections
MS Defender Endpoint
MS Defender Endpoint
Admin consent — the customer authorizes Leen’s Microsoft Defender app. The response carries an
Or the customer’s own app registration. All three values are required together, and the response
carries no More info on both flows can be found here
oauth2_authorize_url to send them to.oauth2_authorize_url — the connection is active immediately.SentinelOne Endpoint
SentinelOne Endpoint
CrowdStrike Falcon
CrowdStrike Falcon
AppSec Connections
Snyk
Snyk
Both routes below take Or a Snyk API token, from a service account with the Org Admin role. The response carries no
More info on both flows can be found here
base_url, which selects the Snyk region. It must be one of
https://app.snyk.io (US-01, the default), https://app.us.snyk.io (US-02) or
https://app.eu.snyk.io (EU-01). Use the app hostname, not the API one. On the OAuth route it
also decides which region the returned oauth2_authorize_url points at, so send it whenever the
customer is not on US-01.OAuth — the customer authorizes Leen’s Snyk app. The response carries an
oauth2_authorize_url to send them to.oauth2_authorize_url — the connection is active immediately.Semgrep
Semgrep
Aikido
Aikido
Wiz Code
Wiz Code
Checkmarx
Checkmarx
Mend.io
Mend.io
IDP Connections
Okta
Okta
MS Entra
MS Entra
OAuth2
OAuth2
Secret
Secret
TPRM Connections
Black Kite
Black Kite
BitSight
BitSight
SecurityScorecard
SecurityScorecard
ProcessUnity
ProcessUnity