Skip to main content
Customer release versions and version lookup
Customer release versions. Image releases on customer channels now carry a simple customer-facing version (1.1, 1.2, …) minted once per pushed image. Each version maps to exactly one git SHA and image digest, so “you are on 1.1” is always an exact, pinnable statement.Look up a release by version. New endpoint: GET /releases/{channel}/{version} resolves a version to its release. The path version matches either the customer release version (for example 1.1) or the Gecko scanner version (for example 1.1.0), and the response includes the digest-pinned image_ref to pull.
GitLab token expiry reminders and rotation API
GitLab token expiry reminders. Gecko now checks your GitLab token’s expiration date daily and emails team admins 7 days before it expires and again when it has expired or been revoked, so the integration never goes dark by surprise. See Token expiry and rotation.Rotate the GitLab token via the API. New v1 endpoints: GET /integrations/gitlab returns the connection state including the token expiry date, and PATCH /integrations/gitlab swaps in a fresh token, built for secret managers and rotation scripts. New tokens are validated against your instance, including the required api scope, before they’re stored.
AI agents, MCP server, and API v1 redesign
Connect your AI tools. Gecko now hosts a remote MCP server at https://app.gecko.security/api/mcp. Connect Claude, Claude Code, ChatGPT, Codex, Cursor, and other MCP clients via OAuth or an API key, with role-capped scopes, packaged security prompts, and per-team consent. See Connect AI tools. Manage connections under Settings > Integrations > Agents.Redesigned v1 API. Consistent response envelope, cursor pagination, tier-aware rate limits, idempotency keys, and request IDs, plus new endpoints for triaging vulnerabilities, updating repository settings, scan schedules, and outbound webhook events with HMAC-signed deliveries. The API is self-describing: live OpenAPI spec, interactive docs, and a machine-readable changelog at /api/v1/changelog.API keys are now visible to the whole team with owner attribution and per-request usage logging, and can be sent as Authorization: Bearer.Connected accounts. Settings > Authentication now shows your identities across GitHub, GitLab, Slack, Linear, and Jira, with suggested matches you can confirm or remove. GitLab identities are tracked per instance.
Docs refresh
Reworked the docs navigation to add top-level Guides, API Reference, and Changelog tabs.Added a Gecko-specific Okta SAML onboarding guide and refreshed local preview instructions.