Skip to main content

Overview

Arnica is a code security posture management (CSPM) platform focused on developer-centric risk signals: hardcoded secrets, risky code changes, overprivileged tokens, and supply chain threats. The Pwnbook integration pulls Arnica findings into your organization for consolidated review.

Prerequisites

  • An Arnica account
  • An Arnica API token with read access
  • Your Arnica organization ID
  • Admin or Owner access in Pwnbook to configure the integration

Credentials required

Setup

1

Generate an Arnica API token

  1. Log in to your Arnica account.
  2. Go to Settings → Integrations → API Access.
  3. Click Generate Token.
  4. Give the token a descriptive name (e.g., pwnbook).
  5. Assign Read permissions.
  6. Copy the token.
2

Find your organization ID

Your Arnica organization ID is displayed in the URL or in Settings → Organization Details.
3

Configure the integration in Pwnbook

  1. Go to Organization Settings → Marketplace → Arnica.
  2. Click Configure.
  3. Enter your API Token and Organization ID.
  4. Click Save & Test.

What gets synced

Viewing findings in Pwnbook

Arnica findings appear under Security Findings → Arnica in your organization. You can filter by severity, finding type, and repository. Findings can be tracked through remediation and assigned to tasks.

Disconnecting

To remove the Arnica integration:
  1. Go to Organization Settings → Marketplace → Arnica.
  2. Click Disconnect.
  3. Confirm.