FlawPilot
Integrations

Connect a repo, FlawPilot scans the source

FlawPilot now also scans your source code, not just your live site. Connect GitHub, GitLab, or Bitbucket, choose which repositories to track, and assign each one a project and branch so it's ready to scan.

OAuth is the fastest way to connect, or use a Personal Access Token. Self-hosted GitLab support is coming soon.

What connecting a repo gives you

Two ways to connect

OAuth is a one-click redirect and the recommended default. An access token works anywhere OAuth isn't an option; tokens are stored encrypted and never echoed back once saved.

You choose what's tracked

The repository picker lists everything your token or OAuth grant can see, but nothing is tracked until you select it. A broad-access token won't dump hundreds of repos into your dashboard.

One view per connection

See the login, auth method, status, and last-synced time for every connected account. Sync re-pulls the repo list; disconnect is immediate, with a confirmation dialog first.

Supported providers

Connect as many accounts as you need - one org on GitHub, a GitLab group, and a Bitbucket workspace can all live side by side.

GitHub

OAuth or a Personal Access Token. GitHub.com and GitHub Enterprise.

GitLab

OAuth or a Personal Access Token, for GitLab.com. Self-hosted GitLab support is coming soon.

Bitbucket

OAuth or an access token, across your workspaces.

How it works

01

Connect an account

Choose GitHub, GitLab, or Bitbucket, then connect with OAuth or an access token. You can connect multiple accounts per provider.

02

Pick repositories to track

From the repository picker, select the repos you actually want FlawPilot to know about. Everything else the grant can see stays out of view.

03

Assign project and branch

For each tracked repo, assign it to a project and choose a branch from a searchable picker (the current branch is pinned first). Scans run against whichever branch is set here.

Good to know

  • A repo becomes scannable only once it has a project and a branch assigned.
  • If a credential goes invalid, expires, or is revoked, the connection shows 'Reconnect needed' immediately, along with the failure reason.
  • Visibility (public/private) and last-synced time are shown per tracked repo.

Frequently asked questions

GitHub, GitLab, and Bitbucket. Self-hosted GitLab support is coming soon.

Ready when you are

Connect your first repository

Pick a provider, choose the repos to track, and they're ready for a source-code scan.

Connect a repository