Vercel
Front-end projects accumulate third parties fast — analytics, error tracking, a headless CMS. Urengi reads the team's projects and their configured integrations, so the services in front of your users are on the vendor list.
- Category
- Engineering
- Auth method
- Access token
- Direction
- Read-only
- Sync frequency
- Daily
- Scopes requested
- 3
- Available on
- Growth and Enterprise
- Maintained by
- Urengi
What the Vercel integration does
Three reads over the infrastructure your users actually hit.
Projects and their regions
Each project is listed with the regions it deploys to, which is the data-residency answer an auditor will ask for.
Installed integrations are vendors
Marketplace integrations attached to a project are third parties with access to your build. Each one queues for intake.
New projects get reviewed
A project created outside the usual process still appears here, so the review does not depend on someone remembering to mention it.
Exactly what Urengi can see
Three read-only scopes on the team you select. Deployments cannot be triggered or changed.
Urengi reads
- Project names and deployment regions
- Installed integration names
- Team member display names and emails
Urengi writes
- Nothing — this connection is read-only
Urengi never touches
- Environment variables or secrets
- Source code, builds or deployment logs
- Domains, DNS or certificate config
- Anything after you revoke the token
Connect it in four steps
One authorisation, one field mapping, and a test sync you run yourself.
01
Authorise the connection
Open Vercel from this page and approve the scopes listed above — OAuth in a browser tab, or a scoped API key you paste. An admin approves them once.
02
Choose what syncs
Pick the projects, spaces or accounts Urengi should watch. Narrow is fine to start with; widening it later does not re-authorise anything.
03
Map your fields
Match owners, cost centres and tiers to what Urengi already tracks. Defaults arrive pre-filled from the first sync, so most teams change nothing.
04
Run a test sync
Pull one record and check it landed on the right review. The audit entry confirms the mapping before a real vendor is touched.
Your token, your rules.
Urengi stores the Vercel token encrypted at rest under a per-tenant key and never replays it outside the scopes you approved. Revoke the app in Vercel and every Urengi write stops within seconds — the audit log keeps the history, the connection simply ends.
Read the security statement- SOC 2 Type II
- audited annually
- Per-tenant keys
- no shared secrets
- Revocable in Vercel
- one click, no ticket
- EU or US residency
- chosen at signup