Skip to main content

Overview

Aikido Security is a continuous security scanning platform that covers code vulnerabilities, exposed secrets, open source dependencies, container images, and cloud misconfigurations. The Pwnbook integration imports Aikido findings into your organization for unified triage and remediation tracking.

Prerequisites

  • An Aikido Security account
  • An Aikido API token
  • Admin or Owner access in Pwnbook to configure the integration

Credentials required

Setup

1

Generate an Aikido API token

  1. Log in to your Aikido account at app.aikido.dev.
  2. Go to Settings → API Access.
  3. Click Generate API Key.
  4. Copy the key — Aikido shows it only once.
Store the key securely. If you lose it, you’ll need to regenerate a new one.
2

Configure the integration in Pwnbook

  1. Go to Organization Settings → Marketplace → Aikido Security.
  2. Click Configure.
  3. Enter your API Token.
  4. Click Save & Test to verify the connection.

What gets synced

Aikido findings pulled into Pwnbook include:

Finding categories

Aikido findings are organized into categories in Pwnbook:
  • Vulnerabilities — Code-level security flaws
  • Secrets — Exposed credentials and API tokens in source code
  • Supply Chain — Vulnerable open source dependencies
  • Container — Image and base OS vulnerabilities
  • Cloud — AWS/GCP/Azure misconfigurations (if cloud scanning is enabled in Aikido)

Viewing findings in Pwnbook

Synced Aikido findings appear under Security Findings → Aikido in your organization. You can:
  • Browse findings by severity, category, and repository
  • View full finding detail including CVSS vectors and remediation
  • Select multiple findings for bulk operations (assign to task, mark resolved)

Refreshing findings

To pull the latest data from Aikido:
  1. Go to Security Findings → Aikido.
  2. Click Refresh.
New or updated findings are merged with existing data; resolved findings are marked accordingly.

Disconnecting

To remove the Aikido integration:
  1. Go to Organization Settings → Marketplace → Aikido Security.
  2. Click Disconnect.
  3. Confirm.
Previously synced findings remain until manually deleted.