Skip to main content
Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor’s documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.
This article explains how to configure the integration for Apiiro. For instructions on connecting Apiiro to entities, see Connecting entities to Apiiro. For information on how to use the integration, see Using the integration for Apiiro.

Why use the integration for Apiiro

Apiiro is an application security posture management (ASPM) platform that surfaces risks across your applications and repositories. On its own, Apiiro tells you what is at risk. Connecting it to Cortex tells you who owns it and whether it meets your standards.
  • Connect risks to owners. Cortex maps Apiiro repositories and applications to your entities, so every risk is tied to a service and the team that owns it.
  • Put security context where engineers work. Risks appear on entity pages, grouped by severity, next to the rest of a service’s operational data. Developers don’t need to switch tools to see what needs attention.
  • Turn security goals into measurable standards. Use Scorecards to define rules, such as no open critical risks or every service registered in Apiiro, and track compliance across your catalog.
  • Prioritize by severity. Grouping risks as critical, high, medium, and low helps teams focus on the issues that matter most first.

Configuring Apiiro

Prerequisites

  1. Users with the Configure Integrations permission can configure Apiiro.
  2. In Apiiro, create an API key. Include the following permissions:
    • Risks > Read
    • Inventory management > Applications > Read
    • Inventory management > Repositories > Read

Configuring the integration in Cortex

  1. From the main sidebar, expand Integrations, then select Configurations.
  2. Locate Apiiro, then click Install. The Apiiro side panel opens.
    To add another configuration (for example, for a second Apiiro instance), click Settings, then click Add configuration.
  3. In the Apiiro side panel, do the following:
    • From the Category dropdown, select the types of data to import from Apiiro (required). The category field is set to Security by default.
    • Under Alias, enter the alias you’ll use in the alias field of an entity’s x-cortex-apiiro block (required).
    • Under API key, enter the API key you generated in Apiiro (required).
    • Optionally, under Host, enter the base URL of your Apiiro instance. If left blank, the default host is used.
  4. Click Test connection. A successful connection means your integration is configured correctly.
  5. Click Save.
To modify the integration configuration, see Modifying an existing integration configuration.
Last modified on September 30, 2026