{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-guides/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["partial"]},"type":"markdown"},"seo":{"title":"Wiz Vulnerability Authentication Guide","siteUrl":"https://docs.synqly.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"creating-and-managing-a-service-account-in-the-wiz-console-for-vulnerabilities","__idx":0},"children":["Creating and Managing a Service Account in the Wiz Console for Vulnerabilities"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"1-introduction","__idx":1},"children":["1. Introduction"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The Wiz Vulnerability Provider uses OAuth 2.0 client credentials for authentication, and requires a Client ID and Client Secret generated from a Wiz service account, along with your tenant's API Endpoint URL."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2-prerequisites","__idx":2},"children":["2. Prerequisites"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before you begin, ensure you have:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Access to the Wiz console"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A Wiz user with Write (W) permission on service accounts. Project-scoped roles can create service accounts only on their own projects."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The API Endpoint URL for your Wiz tenant"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We recommend creating a dedicated service account for use with this integration."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"3-creating-a-service-account","__idx":3},"children":["3. Creating a Service Account"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"step-1-access-the-wiz-console","__idx":4},"children":["Step 1: Access the Wiz Console"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Log in to your Wiz console as a user with Write (W) permission on service accounts."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"step-2-add-a-service-account","__idx":5},"children":["Step 2: Add a Service Account"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings > Access Management > Service Accounts"]},", then select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add Service Account"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter a meaningful ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name"]}," for the account."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Set ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Type"]}," to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Custom Integration (GraphQL API)"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["(Optional) Limit access to specific projects by choosing up to 50 projects from the drop-down list. If you are not sure which projects to choose, leave this empty."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["(Optional) Set an ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Expiration date"]}," for the service account. We recommend leaving this empty."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Set the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API Scopes"]}," to the scopes listed in ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#required-scopes"},"children":["Required Scopes"]}," below."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add Service Account"]},". The secret credentials dialog shows the newly created ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client Secret"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client Secret"]}," to a secure place, such as a password management tool."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Finish"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"required-scopes","__idx":6},"children":["Required Scopes"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Grant ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["all"]}," scopes below. Wiz checks scopes on every API call — missing a scope means that operation is rejected as ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["not authorized"]}," (typically HTTP ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["403"]},")."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Scope"},"children":["Scope"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Required for"},"children":["Required for"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Without this scope"},"children":["Without this scope"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["read:vulnerabilities"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Querying vulnerability findings"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Cannot query vulnerabilities; returns not authorized."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"4-determining-your-api-endpoint-url","__idx":7},"children":["4. Determining Your API Endpoint URL"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The Wiz GraphQL API uses a single endpoint:"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.<TENANT_DATA_CENTER>.<ENVIRONMENT>/graphql"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["<TENANT_DATA_CENTER>"]}]}," is your Wiz regional data center (for example ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["us1"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["us2"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["eu1"]},", or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["eu2"]},")."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["<ENVIRONMENT>"]}]}," is one of ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["app.wiz.io"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["app.wiz.us"]},", or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["gov.wiz.io"]},", depending on your deployment:"]}]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Environment Type"},"children":["Environment Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Environment Value"},"children":["Environment Value"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Example"},"children":["Example"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Commercial (Standard)"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["app.wiz.io"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.us17.app.wiz.io/graphql"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Gov (FedRAMP)"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["app.wiz.us"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.us17.app.wiz.us/graphql"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Commercial AWS GovCloud"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["gov.wiz.io"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.us17.gov.wiz.io/graphql"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.us17.app.wiz.io/graphql"]}," is a sample endpoint for demonstration. In production, use your tenant's data center and environment."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To find your tenant data center:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the Wiz portal, select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["user icon"]}," (top right), then ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Tenant Info"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["On the left, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Data Center and Regions"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Tenant Data Center"]}," value and combine it with your environment using the format above."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Enter that full GraphQL URL as the integration's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API Endpoint URL"]},". You do not set data center or environment as separate fields. Synqly infers the OAuth token endpoint from the environment domain in the URL (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["app.wiz.io"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["app.wiz.us"]},", or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["gov.wiz.io"]},")."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"5-configure-the-integration","__idx":8},"children":["5. Configure the Integration"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create your integration by supplying the following configuration values."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Integration Parameter"},"children":["Integration Parameter"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["API Endpoint URL"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The GraphQL API endpoint for your Wiz tenant, in the form ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.<TENANT_DATA_CENTER>.<ENVIRONMENT>/graphql"]},". Example: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.us17.app.wiz.io/graphql"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client ID"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The Client ID shown when the service account was created in Step 2."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client Secret"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The Client Secret shown when the service account was created in Step 2."]}]}]}]}]}]},"headings":[{"value":"Creating and Managing a Service Account in the Wiz Console for Vulnerabilities","id":"creating-and-managing-a-service-account-in-the-wiz-console-for-vulnerabilities","depth":1},{"value":"1. Introduction","id":"1-introduction","depth":2},{"value":"2. Prerequisites","id":"2-prerequisites","depth":2},{"value":"3. Creating a Service Account","id":"3-creating-a-service-account","depth":2},{"value":"Step 1: Access the Wiz Console","id":"step-1-access-the-wiz-console","depth":3},{"value":"Step 2: Add a Service Account","id":"step-2-add-a-service-account","depth":3},{"value":"Required Scopes","id":"required-scopes","depth":3},{"value":"4. Determining Your API Endpoint URL","id":"4-determining-your-api-endpoint-url","depth":2},{"value":"5. Configure the Integration","id":"5-configure-the-integration","depth":2}],"frontmatter":{"slug":"guides/provider-configuration/wiz-vulnerability-setup","seo":{"title":"Wiz Vulnerability Authentication Guide"}},"lastModified":"2026-08-14T18:14:47.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/guides/provider-configuration/wiz-vulnerability-setup","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}