Skip to main content
Secure Code Scanning

Snyk Code

Connect Snyk Code to Guard to import SAST findings as vulnerabilities alongside your other application security data.

The Snyk Code integration allows Guard to ingest static analysis findings from your Snyk group, surfacing them as vulnerabilities in the platform.

How it works

Snyk Code findings are pulled using the same ingestion pipeline as other vulnerability integrations. Once imported, findings appear in the vulnerability table and are subject to the same triage, risk-scoring, and ticketing capabilities available to all Guard vulnerabilities.

Prerequisites

Before connecting, ensure you have:

  • A Snyk account with Snyk Code enabled.
  • A Snyk API token with read access to the target group.
  • Your Snyk Group ID and the data center Region your Snyk account is hosted in.

Connect Snyk Code to Guard

  1. In Guard, navigate to Integrations > Secure Code Scanning > Snyk Code.
  2. Enter your Snyk Group ID.
  3. Enter your Snyk API Token.
  4. Select your Snyk Region (US, US-02, EU, or AU).
  5. Save the configuration.

Guard will begin importing findings from the organisations in your Snyk group. New findings discovered by Snyk in subsequent scans are picked up automatically on the next sync.

Imported data

Snyk concept

Guard representation

Snyk Code finding

Vulnerability

Severity

Mapped to Guard risk score

Affected file / rule

Visible in vulnerability detail

Working with imported findings

Imported Snyk Code vulnerabilities support the full Guard remediation workflow:

  • Triage — set status, assign owners, and add notes.
  • Ticketing — create or link tickets via configured ticketing integrations (e.g., Jira).
  • Risk scoring — findings are scored consistently with other vulnerability sources.

Troubleshooting

No findings appear after connecting

  • Confirm the API token has read access to the specified group.
  • Verify that Snyk Code scans have run and produced results in your Snyk group before the sync.

Authentication errors

  • Regenerate your Snyk API token and update the credential in Integrations > Secure Code Scanning > Snyk Code.
  • Confirm the Region matches the data center your Snyk account is hosted in.
  • Ensure the Group ID matches the Snyk group associated with the token.

Still need help? Ask the team