Overview
Aikido Security is a continuous security scanning platform that covers code vulnerabilities, exposed secrets, open source dependencies, container images, and cloud misconfigurations. The Pwnbook integration imports Aikido findings into your organization for unified triage and remediation tracking.Prerequisites
- An Aikido Security account
- An Aikido API token
- Admin or Owner access in Pwnbook to configure the integration
Credentials required
Setup
1
Generate an Aikido API token
- Log in to your Aikido account at app.aikido.dev.
- Go to Settings → API Access.
- Click Generate API Key.
- Copy the key — Aikido shows it only once.
2
Configure the integration in Pwnbook
- Go to Organization Settings → Marketplace → Aikido Security.
- Click Configure.
- Enter your API Token.
- Click Save & Test to verify the connection.
What gets synced
Aikido findings pulled into Pwnbook include:Finding categories
Aikido findings are organized into categories in Pwnbook:- Vulnerabilities — Code-level security flaws
- Secrets — Exposed credentials and API tokens in source code
- Supply Chain — Vulnerable open source dependencies
- Container — Image and base OS vulnerabilities
- Cloud — AWS/GCP/Azure misconfigurations (if cloud scanning is enabled in Aikido)
Viewing findings in Pwnbook
Synced Aikido findings appear under Security Findings → Aikido in your organization. You can:- Browse findings by severity, category, and repository
- View full finding detail including CVSS vectors and remediation
- Select multiple findings for bulk operations (assign to task, mark resolved)
Refreshing findings
To pull the latest data from Aikido:- Go to Security Findings → Aikido.
- Click Refresh.
Disconnecting
To remove the Aikido integration:- Go to Organization Settings → Marketplace → Aikido Security.
- Click Disconnect.
- Confirm.