
Cracken + Aikido
Aikido replaces a shelf of point scanners with a single issue list spanning SAST, SCA, secrets, IaC, and containers. Cracken takes that list into an operation. It proves which entries an attacker can reach from outside your application.
Connecting Aikido
- Connect with
An Aikido API key from a dedicated API credential granted read-only permissions: issues:read, clouds:read, repositories:read, containers:read, basics:read.
- Cadence
Syncs on a schedule — every 6 hours by default for a hosted connection.
- Requires
Access to Aikido's API settings and permission to create an API credential.
What Cracken gets from Aikido
AppSec Issues (the Data tab's own label) arriving as vulnerability findings with name, description, severity and state
A cve[] list plus cvss_base_score, cvss_vector and cvss_version on each finding
first_seen, last_seen and state_updated_at, plus patchable and a solution string
category, vendor_severity and Aikido's own vendor_id kept alongside Cracken's normalized severity
The resource{} and device{} object each finding is attached to
In the Cybergraph: a Finding node, a cve: Vulnerability node it CONTAINS, and — when the finding carries a package — a File node with name, version and ecosystem
What Aikido does not do
Aikido is read-only: Cracken can only list findings. It never launches an Aikido scan and never writes back a state, an ignore or a comment. Filtering by rule or by file happens on Cracken's side, not inside Aikido.
How Cracken uses Aikido
- 01
Connect Aikido
- 02
Sync the issue list
- 03
Prove what is reachable
- 04
Confirm it connected
Frequently asked questions
Does connecting Aikido give Cracken access to my source code?
No; Aikido only gives Cracken its existing issues through an API token, and source access needs a separate GitHub or GitLab integration you connect.
How often does Cracken sync findings from Aikido?
Cracken syncs Aikido issues about every six hours, and can also query Aikido directly for current issues during an operation.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
More integrations
GitHub Advanced Security
Cracken queries your GitHub repositories and their scanning and Dependabot alerts live.
GitLab
Cracken queries your GitLab projects and vulnerability findings mid-operation.
Snyk
Cracken attacks the running app to prove which Snyk findings are reachable.
Attack with real Aikido context.
See how Cracken works what Aikido already knows into attack paths it proves end to end.


