All integrations
Aikido logo
// Data Integration · Application Security

Cracken + Aikido

Aikido replaces a shelf of point scanners with a single issue list spanning SAST, SCA, secrets, IaC, and containers. Cracken takes that list into an operation. It proves which entries an attacker can reach from outside your application.

Get started
// 01

Connecting Aikido

Connect with

An Aikido API key from a dedicated API credential granted read-only permissions: issues:read, clouds:read, repositories:read, containers:read, basics:read.

Cadence

Syncs on a schedule — every 6 hours by default for a hosted connection.

Requires

Access to Aikido's API settings and permission to create an API credential.

// 02

What Cracken gets from Aikido

  • AppSec Issues (the Data tab's own label) arriving as vulnerability findings with name, description, severity and state

  • A cve[] list plus cvss_base_score, cvss_vector and cvss_version on each finding

  • first_seen, last_seen and state_updated_at, plus patchable and a solution string

  • category, vendor_severity and Aikido's own vendor_id kept alongside Cracken's normalized severity

  • The resource{} and device{} object each finding is attached to

  • In the Cybergraph: a Finding node, a cve: Vulnerability node it CONTAINS, and — when the finding carries a package — a File node with name, version and ecosystem

// 03

What Aikido does not do

Aikido is read-only: Cracken can only list findings. It never launches an Aikido scan and never writes back a state, an ignore or a comment. Filtering by rule or by file happens on Cracken's side, not inside Aikido.

// 04

How Cracken uses Aikido

  1. 01

    Connect Aikido

  2. 02

    Sync the issue list

  3. 03

    Prove what is reachable

  4. 04

    Confirm it connected

// 05

Frequently asked questions

Does connecting Aikido give Cracken access to my source code?

No; Aikido only gives Cracken its existing issues through an API token, and source access needs a separate GitHub or GitLab integration you connect.

How often does Cracken sync findings from Aikido?

Cracken syncs Aikido issues about every six hours, and can also query Aikido directly for current issues during an operation.

“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”

Cybersecurity Engineer · test-and-measurement manufacturer

Attack with real Aikido context.

See how Cracken works what Aikido already knows into attack paths it proves end to end.