Skip to main content
All integrations are configured in Settings. Connect source control first; it’s what makes the rest of the workflow click into place.

Source control

GitHub

GitHub App for GitHub.com, plus GitHub Enterprise Server via token.

GitLab

GitLab.com via access token, with MR comments and fix MRs.

Self-managed GitLab

Self-managed and GitLab Dedicated via a service account and PAT.

Issue trackers

Push validated findings into the tool your team already plans in. Each tracker supports an auto-create option to file work for findings after every scan.

Jira

Project, board, sprint, issue type, assignee, and status mapping.

Linear

Team, project, assignee, labels, and severity-to-priority mapping.

ClickUp

Space and list targeting with auto-created tasks.

Shortcut

Route findings into Shortcut stories by group.

Notifications

Slack

Scan notifications routed per repository, filtered by severity.

AI agents

Connect AI tools to Gecko’s MCP server so they can read findings, triage, and file tickets, scoped to your team and capped by your role. Manage connected tools under Settings > Integrations > Agents.

Claude & Claude Desktop

Custom connector with OAuth, no API key needed.

Claude Code

One CLI command, then authenticate in the browser.

Codex

CLI, IDE, and Codex Cloud via an API key.

ChatGPT

Custom connector with OAuth, no API key needed.

Cursor, Devin & other clients

One-click Cursor install, plus a generic MCP config.

Vulnerability management

Export findings one-way into a security platform, where they stay in sync as scans run. Triage in Gecko remains the source of truth.

GitLab vulnerability export

Surface findings in GitLab’s native Security Dashboard.

DefectDojo

Push findings into DefectDojo for centralized vulnerability management.
Most issue-tracker integrations connect over OAuth; Shortcut uses an API token. Connecting requires the Admin or Manager role. See Teams & permissions.