> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cortex.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Using the integration for Apiiro

<Info>
  Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor's documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.
</Info>

This article explains how to use the integration for Apiiro. For configuration instructions, see [Configuring the integration for Apiiro](/ingesting-data-into-cortex/integrations/apiiro). For instructions on connecting Apiiro to entities, see [Connecting entities to Apiiro](/ingesting-data-into-cortex/integrations/apiiro/connecting-entities-to-apiiro).

## Viewing Apiiro risks on an entity

You can view Apiiro risks on an entity's details page and in the entity's sidebar. You can also use CQL to query for Apiiro risks.

### Entity's details page

On an [entity's overview](/ingesting-data-into-cortex/entities-overview/entities/details), risks are listed under the **Code & security** block. Within this block, issues and vulnerabilities are grouped by severity: `Critical`, `High`, `Medium`, and `Low`. Click into any of these to open a list of all applicable issues and vulnerabilities.

<Note>
  The **Code & security** block only appears if the entity has at least one risk. If the entity is connected but has no risks, the block doesn't appear.
</Note>

### Entity's left sidebar

In an entity's left sidebar, expand **Security**, then select Apiiro to view risks.

### Scorecards and CQL

With the Apiiro integration, you can create Scorecard rules and write CQL queries based on Apiiro risks.

See more examples in the [CQL Explorer](https://app.getcortexapp.com/admin/cql-explorer) in Cortex.

<AccordionGroup>
  <Accordion title="List risks">
    List all risks for an entity's connected Apiiro repositories and applications.

    **Definition**: `apiiro.risks()`

    **Example**

    A Scorecard's top level might include a rule to ensure that entities have a low number of Apiiro risks:

    ```
    apiiro.risks().length < 3
    ```
  </Accordion>

  <Accordion title="Check if the entity is connected to Apiirot">
    Check if the entity is connected to Apiiro.

    **Definition:** `apiiro != null`

    **Example**

    An initial level in a security Scorecard might include a rule to make sure entities are connected to Apiiro. Without a connection, Cortex can't pull in the entity's risks.

    ```
    apiiro != null
    ```
  </Accordion>
</AccordionGroup>

## Viewing Apiiro integration logs

<Info>
  This feature is available in Cortex cloud.
</Info>

While viewing an integration's settings page, select the **Error logs** tab to view errors from the last 7 days. You can filter the logs list by configuration and by operation (for example, you could filter to view errors surfaced only via Scorecards).

<Frame>
  <img src="https://mintcdn.com/cortex-290c0c42/ovmDVVMNC2L6Yw7I/images/integration-error-logs.png?fit=max&auto=format&n=ovmDVVMNC2L6Yw7I&q=85&s=dffdc901a9ce0232aedd090bb3a4531c" alt="The 'Logs' tab on an integration's settings page shows error information over the past 7 days." title="Integration Error Logs" className="mr-auto" width="1532" height="203" data-path="images/integration-error-logs.png" />
</Frame>

Click into a row to get more information, including time stamp, status code, full error, and request path.

## Troubleshooting and FAQ

See frequently asked questions below.

<AccordionGroup>
  <Accordion title="An entity doesn't show any Apiiro data">
    * Check that the repository path in the entity's `x-cortex-git` block exactly matches the path in Apiiro, including capitalization.
    * If the repository was added to Apiiro recently, wait for the nightly refresh at 10 p.m. UTC.
    * If the entity has an `x-cortex-apiiro` block, check that the IDs or paths match the values in Apiiro, and that the block lists every repository you want connected. A manual mapping turns off automatic matching.
    * Check that every entry in the block has an `alias` that matches an Apiiro configuration in Cortex, and that each repository entry has exactly one of `repositoryId` or `repositoryPath`. If any entry is invalid, Cortex ignores the whole block.
    * Check the integration's error logs. See [Viewing Apiiro integration logs](#viewing-apiiro-integration-logs) for instructions.
  </Accordion>

  <Accordion title="The entity is connected, but no risks appear">
    The entity's Apiiro repositories or applications might not have any open risks. In that case, the **Code & security** block doesn't appear on the entity's overview, and **Security > Apiiro** shows an empty state. If you expect risks, check the following:

    * The API key has the `Risks > Read` permission. Look for 401 or 403 errors in the integration logs, or click **Test connection** on the configuration.
    * The repository and application IDs in the entity's YAML still exist in Apiiro. Cortex returns no risks for IDs that no longer exist, without showing an error.
  </Accordion>
</AccordionGroup>


## Related topics

- [Apiiro](/ingesting-data-into-cortex/integrations/apiiro.md)
- [Connecting entities to Apiiro](/ingesting-data-into-cortex/integrations/apiiro/connecting-entities-to-apiiro.md)
- [Using the integration for Kubernetes](/ingesting-data-into-cortex/integrations/kubernetes/using-the-integration-for-kubernetes.md)
