In this article, we explain how to integrate your Aikido account with Scrut.
What Does this Integration Do in Scrut?
Vulnerability Management: This integration imports vulnerability data from Aikido into Scrut's Third-Party Scans page, enabling you to track, assign, and remediate vulnerabilities directly in Scrut.
Prerequisites
Before setting up the integration, ensure you have:
An active Aikido account with permissions to set up an OAuth application
Admin access to Scrut (or Contributor with access to the Integration module)
Permissions and Access Requirements
Scrut requires the following permissions in your Aikido instance:
users: read
repositories: read
issues: read
Sync Frequency
Data is synced automatically once every 24 hours. You can also manually trigger a sync from the integration settings page when needed.
Integration Setup
Step 1: Generate Client ID & Client Secret in Aikido
Navigate to your Aikido tenant’s application management or developer portal (https://app.aikido.dev/login).
Log in to your tenant administrator account.
Click the Add Client button.

Enter the following basic details for your new application:
App Name: Enter a descriptive name for the application (e.g., Scrut Integration)
App Scopes: Set the following read-only scopes for the application:
users: read
repositories: read
issues: read

App Type: Select Public
Redirect URI: Enter the appropriate URL based on your Scrut instance region.
For Australia: https://app.au.scrut.io/settings/integration/aikido

Click Create Credentials to generate the Client ID & Client Secret.
Note:
The Client ID & Client Secret will not be shown again. So, make sure to save these details safely in a secure location.
Step 2: Navigate to Integrations in Scrut
Sign in to Scrut and click Integrations on the left navigation panel.
Go to the Integrations Library tab, and click Vulnerability Scanners in the Categories section.
Search for the Aikido tile, then click Integrate.

Enter the Client ID & Client Secret you fetched in the previous step.
Click Submit.

Watch for the “Connected” status flag that indicates a successful integration.
What Happens Next?
Initial sync
After integration, Scrut immediately starts syncing data from your Aikido instance. However, it might take several minutes for the initial sync to complete, depending on the volume of data in your Aikido instance.
View synced vulnerabilities in Scrut
Once the initial sync is over,
In Scrut, navigate to Vulnerabilities → Third-Party Scans.
Filter the data by Source: Aikido.
Confirm whether vulnerabilities are listed with names, severities, CVEs (where applicable), and affected assets.
Troubleshooting
Invalid credentials
Possible solutions: Verify Client ID and Client Secret are correct (no extra spaces). Confirm the client hasn’t been deleted in Aikido.
Insufficient permissions
Ensure the API client has the requisite permissions for the integration.
No vulnerabilities in Scrut
Wait for the sync to complete. Verify there are open issues in your Aikido account.
Client secret not available
Client secrets are only shown once. If you failed to copy it, create a new API client and repeat the integration steps.
If you face any issues while connecting Aikido with Scrut, please contact our support team at support@scrut.io.