Connect an account
Choose GitHub, GitLab, or Bitbucket, then connect with OAuth or an access token. You can connect multiple accounts per provider.
FlawPilot now also scans your source code, not just your live site. Connect GitHub, GitLab, or Bitbucket, choose which repositories to track, and assign each one a project and branch so it's ready to scan.
OAuth is the fastest way to connect, or use a Personal Access Token. Self-hosted GitLab support is coming soon.
OAuth is a one-click redirect and the recommended default. An access token works anywhere OAuth isn't an option; tokens are stored encrypted and never echoed back once saved.
The repository picker lists everything your token or OAuth grant can see, but nothing is tracked until you select it. A broad-access token won't dump hundreds of repos into your dashboard.
See the login, auth method, status, and last-synced time for every connected account. Sync re-pulls the repo list; disconnect is immediate, with a confirmation dialog first.
Connect as many accounts as you need - one org on GitHub, a GitLab group, and a Bitbucket workspace can all live side by side.
OAuth or a Personal Access Token. GitHub.com and GitHub Enterprise.
OAuth or a Personal Access Token, for GitLab.com. Self-hosted GitLab support is coming soon.
OAuth or an access token, across your workspaces.
Choose GitHub, GitLab, or Bitbucket, then connect with OAuth or an access token. You can connect multiple accounts per provider.
From the repository picker, select the repos you actually want FlawPilot to know about. Everything else the grant can see stays out of view.
For each tracked repo, assign it to a project and choose a branch from a searchable picker (the current branch is pinned first). Scans run against whichever branch is set here.
Pick a provider, choose the repos to track, and they're ready for a source-code scan.