Integrations
Fits where you work.
BrokenApp integrates with your source control, CI/CD pipeline, auth provider, and AI tooling. One CLI, every workflow.
Available now
10 integrations. Zero config overhead.
GitHub
Source controlAuto-create issues from findings. Comment on PRs with new vulnerabilities. Export SARIF for Code Scanning. Issues auto-close when findings resolve.
Supabase
Auth providerNative GoTrue auth flow testing. Login, session persistence, token refresh, logout invalidation, expired token rejection. Zero custom code.
Firebase
Auth providerIdentity Toolkit integration. Same five-test suite as Supabase. Point at your Firebase config and BrokenApp handles the rest.
GraphQL
API protocolPer-operation endpoint detection. Automatically splits POST /graphql into individual queries and mutations for targeted scanning.
GitHub Actions
CI/CDRun BrokenApp in your CI pipeline. Exit codes for pass/fail gating. JSON output for custom processing. One-line workflow setup.
GitLab CI
CI/CDSame CLI, same flags, same output. Add brokenapp scan to your .gitlab-ci.yml and gate deployments on scan results.
MCP Server
AI toolingModel Context Protocol server for AI coding tools. Claude Code, Codex, and any MCP-compatible client can trigger scans and read reports.
Webhooks
NotificationsPOST scan results to any URL. Trigger Slack, Discord, PagerDuty, or custom automation when new findings are detected.
PDF / CSV / Markdown
ExportGenerate branded reports in multiple formats. Executive summaries, finding details with evidence, remediation guidance, and compliance mappings.
SARIF 2.1.0
StandardsExport findings as SARIF for GitHub Code Scanning, VS Code SARIF Viewer, or any SARIF-compatible tool. Full rule metadata included.
Coming soon
On the roadmap.
Jenkins
SoonPipeline step integration. Run scans as part of your Jenkins build. Parse JSON output for custom quality gates.
GitLab Issues
SoonSame auto-create, auto-close, and fingerprint deduplication as GitHub — for GitLab projects.
Need an integration we don't have?
We ship integrations based on demand. Tell us what you need.
Request an integrationArchitecture
CLI-native. Not plugin-dependent.
Scan locally
BrokenApp runs on your machine or CI runner. No cloud dependency. The CLI produces structured JSON output that any integration can consume.
Push results
Use built-in commands to push findings to GitHub, export to SARIF/PDF/CSV, or POST to webhooks. You control where data goes.
Automate the loop
Set up CI gates, scheduled rescans, and auto-triage. New findings trigger notifications. Resolved findings close issues. The feedback loop runs itself.
One tool. Every workflow.
Install the CLI and connect it to everything you already use.