Skip to main content
Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor’s documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.
This article explains how to use the integration for Apiiro. For configuration instructions, see Configuring the integration for Apiiro. For instructions on connecting Apiiro to entities, see Connecting entities to Apiiro.

Viewing Apiiro risks on an entity

You can view Apiiro risks on an entity’s details page and in the entity’s sidebar. You can also use CQL to query for Apiiro risks.

Entity’s details page

On an entity’s overview, risks are listed under the Code & security block. Within this block, issues and vulnerabilities are grouped by severity: Critical, High, Medium, and Low. Click into any of these to open a list of all applicable issues and vulnerabilities.
The Code & security block only appears if the entity has at least one risk. If the entity is connected but has no risks, the block doesn’t appear.

Entity’s left sidebar

In an entity’s left sidebar, expand Security, then select Apiiro to view risks.

Scorecards and CQL

With the Apiiro integration, you can create Scorecard rules and write CQL queries based on Apiiro risks. See more examples in the CQL Explorer in Cortex.
List all risks for an entity’s connected Apiiro repositories and applications.Definition: apiiro.risks()ExampleA Scorecard’s top level might include a rule to ensure that entities have a low number of Apiiro risks:
Check if the entity is connected to Apiiro.Definition: apiiro != nullExampleAn initial level in a security Scorecard might include a rule to make sure entities are connected to Apiiro. Without a connection, Cortex can’t pull in the entity’s risks.

Viewing Apiiro integration logs

This feature is available in Cortex cloud.
While viewing an integration’s settings page, select the Error logs tab to view errors from the last 7 days. You can filter the logs list by configuration and by operation (for example, you could filter to view errors surfaced only via Scorecards).
The 'Logs' tab on an integration's settings page shows error information over the past 7 days.
Click into a row to get more information, including time stamp, status code, full error, and request path.

Troubleshooting and FAQ

See frequently asked questions below.
  • Check that the repository path in the entity’s x-cortex-git block exactly matches the path in Apiiro, including capitalization.
  • If the repository was added to Apiiro recently, wait for the nightly refresh at 10 p.m. UTC.
  • If the entity has an x-cortex-apiiro block, check that the IDs or paths match the values in Apiiro, and that the block lists every repository you want connected. A manual mapping turns off automatic matching.
  • Check that every entry in the block has an alias that matches an Apiiro configuration in Cortex, and that each repository entry has exactly one of repositoryId or repositoryPath. If any entry is invalid, Cortex ignores the whole block.
  • Check the integration’s error logs. See Viewing Apiiro integration logs for instructions.
The entity’s Apiiro repositories or applications might not have any open risks. In that case, the Code & security block doesn’t appear on the entity’s overview, and Security > Apiiro shows an empty state. If you expect risks, check the following:
  • The API key has the Risks > Read permission. Look for 401 or 403 errors in the integration logs, or click Test connection on the configuration.
  • The repository and application IDs in the entity’s YAML still exist in Apiiro. Cortex returns no risks for IDs that no longer exist, without showing an error.
Last modified on September 30, 2026