Start free trial

GitLab

EngineeringRead-onlyAPI key

The same dependency and group inventory as GitHub, and it works the same whether you run GitLab yourself or on theirs. A self-managed instance only needs the API reachable from your network, not opened to the internet.

Category
Engineering
Auth method
Project access token
Direction
Read-only
Sync frequency
Daily
Scopes requested
4
Available on
Growth and Enterprise
Maintained by
Urengi

What the GitLab integration does

Three reads, identical on SaaS and self-managed.

Dependencies become vendors

Manifests are read per project and the hosted services behind them queue for intake, exactly as they do on GitLab.com.

Advisories reopen a review

A published advisory against a dependency reopens that vendor's review with the affected projects attached.

Group settings as evidence

Enforced 2FA, owner membership and visibility defaults are recorded as evidence rather than screenshotted for the auditor.

Exactly what Urengi can see

Four read-only scopes on the groups you name. Source code is never read.

Urengi reads

  • Project and group names
  • Dependency manifests and lockfiles
  • Group membership and 2FA enforcement
  • Published security advisories

Urengi writes

  • Nothing — this connection is read-only

Urengi never touches

  • Source code, diffs or commit contents
  • Issues, merge requests or snippets
  • CI variables or job logs
  • Anything after you revoke the token

Connect it in four steps

One authorisation, one field mapping, and a test sync you run yourself.

01

Authorise the connection

Open GitLab from this page and approve the scopes listed above — OAuth in a browser tab, or a scoped API key you paste. An admin approves them once.

02

Choose what syncs

Pick the projects, spaces or accounts Urengi should watch. Narrow is fine to start with; widening it later does not re-authorise anything.

03

Map your fields

Match owners, cost centres and tiers to what Urengi already tracks. Defaults arrive pre-filled from the first sync, so most teams change nothing.

04

Run a test sync

Pull one record and check it landed on the right review. The audit entry confirms the mapping before a real vendor is touched.

Your token, your rules.

Urengi stores the GitLab token encrypted at rest under a per-tenant key and never replays it outside the scopes you approved. Revoke the app in GitLab and every Urengi write stops within seconds the audit log keeps the history, the connection simply ends.

Read the security statement
SOC 2 Type II
audited annually
Per-tenant keys
no shared secrets
Revocable in GitLab
one click, no ticket
EU or US residency
chosen at signup