Integrations

DAST integrations that work where your team works

Teams now ship faster than any separate security console can keep up. NightVision works inside the pipelines, ticketing systems, and coding agents you already use.

The Shape of It

One coordinated workflow, delivered where your work already happens

Every integration below carries the same work order, not another alert: a finding tested against the running application, with HTTP evidence retained on request-level findings and file and line added on supported source-discovered API findings. One workflow, one finding format, every surface.

Applications built by finance, HR, engineering, and coding agents flow through one NightVision security check
CI/CD

CI/CD DAST integrations

Setup is a token and a step: onboarding a target takes 6-12 clicks, and the same CLI drives every pipeline below.

GitHub Actions

Run a scan as a workflow step and return findings to the pull request and GitHub Security Alerts. Docs

GitLab

Run scans in GitLab CI and export in GitLab's native DAST report format, straight into the Vulnerability Report. Docs

Jenkins

Add a scan stage with the NightVision CLI and pull SARIF into your existing reporting. Docs

Azure DevOps

Run NightVision inside Azure Pipelines and publish scan results alongside your build output. Docs

Bitbucket

Trigger scans from Bitbucket Pipelines with the same CLI commands. Docs

Code & Findings

Findings that land in the developer's world

Request-level findings retain HTTP evidence; supported source-discovered API findings can add file and line context through Code Traceback.

SARIF export

Every scan exports standard SARIF, so findings flow into any tool in your stack that already reads it. CLI docs

GitHub Security Alerts + Code Traceback

Findings upload to GitHub Security Alerts; on supported source-discovered API scans, Code Traceback adds the file and line behind the finding. Docs

VS Code extension

Developers run scans from the editor using shared project configuration, no security expertise required to kick one off. Docs

Ticketing & Chat

Route findings to the people who fix them

These integrations move findings into the queue your team actually works from, evidence attached.

Jira

File findings as Jira issues automatically, evidence and fix location included, with status kept in sync. Docs

Slack

Send scan and finding notifications to the channels your team already watches. Docs

Microsoft Teams

The same notifications, delivered to Microsoft Teams. Docs

Email

SMTP notifications for teams that route alerts through email. Docs

Coding Agents

Agent-ready by design

NightVision is the deterministic, source-linked evidence layer your coding agents consume, and a human still approves what ships. Determinism on the finding, agents on the fix, humans on the merge.

A coding agent uses NightVision MCP tools to launch a scan, read evidence, and verify a fix before human review

MCP server

The open-source MCP server exposes targets, scans, and findings to any MCP-capable agent, with the same evidence a human reviewer sees. Docs

Claude Code skills

Installable skills let Claude Code discover APIs and run authenticated scans in a coding session; the open skills standard travels to other agents too. See NightVision for coding agents

Infrastructure & Enterprise Controls

Scan where apps run. Govern who can act.

Reach private environments, connect build artifacts, and plug access management into the identity stack you already run.

Terraform modules

Deploy scanning inside your own AWS VPC with maintained Terraform modules. Docs

Smart Proxy

Reach applications on private networks without agents, appliances, or routing changes. Docs, or see the private network scanning use case.

JFrog Artifactory

Attach DAST evidence and generated OpenAPI specs to the artifacts they describe in Artifactory, so security context travels with the build. Docs

SSO via WorkOS

Single sign-on through WorkOS supports any SAML or OIDC identity provider, including Okta, Microsoft Entra ID, and Google. Docs

SCIM directory sync

Directory sync provisions and deprovisions accounts from your identity provider. Docs

REST API + tokens

Use scoped tokens and the REST API to automate NightVision workflows. Docs

See it running in your pipeline.

Connect a repo, add the workflow step, and get findings as SARIF with HTTP evidence retained. Onboarding is 6-12 clicks, under a minute.