Overview

The Snyk integration monitors your application security platform: projects, vulnerabilities, licenses, and dependencies. LowerPlane uses read-only access via an API Token to collect compliance evidence automatically.

Prerequisites

You need Snyk Organization Admin permissions to generate an API token with read access.

How to Get Your Credentials

1

Log in to Snyk

Log in to your Snyk Dashboard.
2

Generate an API token

Follow the Snyk documentation to generate your API token. Set the permission to Full Access :: Read.
3

Find your region

Check your browser address bar when logged into Snyk. Your region is determined by the URL prefix (e.g., app.snyk.io for US, app.eu.snyk.io for EU).

Connecting in LowerPlane

  1. Go to Settings > Integrations in LowerPlane
  2. Find Snyk under Security Tools
  3. Enter your API Token
  4. Select your Region
  5. Click Connect

What LowerPlane Monitors

Projects

Monitored projects, scan configurations, and test frequency.

Vulnerabilities

Open vulnerabilities, severity distribution, and fix availability.

Licenses

License compliance across all dependencies.

Dependencies

Dependency trees and outdated package tracking.

Frameworks Supported

FrameworkWhat It Proves
SOC 2Vulnerability management and security testing are in place
ISO 27001Application security and patch management are enforced
PCI-DSSVulnerability scanning and remediation are maintained