The Socket integration enables Drata to import security alerts and repository data from Socket. This integration provides visibility into dependency, code, configuration, license, and supply chain risks across your repositories.
Key capabilities
Import open security alerts from Socket across all repositories in your organization.
Import Socket repositories as repository resources in Drata.
Map Socket alert severity, state, and category values to Drata’s unified security data model.
Support both AppSec issues and Vulnerability Findings data models.
Prerequisites and data access
Before you begin, make sure you have the following:
Access to the correct Socket organization.
Permission to create API tokens in Socket.
Access to the Connections page in Drata.
Your Socket organization slug.
The integration uses read-only API access to retrieve alert and repository data. Create an API token with only the permissions required for the integration:
Permission | Why it’s needed | Data accessed |
| Lists repositories in the Socket organization. | Repository data |
| Retrieves security alerts. | Security alert data |
Set up the Socket integration
Step 1: Generate a Socket API token
Log in to your Docket dashboard.
If you belong to multiple organizations, select the organization you want to connect from the organization switcher.
Go to Settings > API Keys.
Select Create API Token.
Enter a name for the token, such as
Drata integration.Under Scopes, select:
repo:listalerts:list
Select Create.
Copy the API token and store it securely.
The API token is shown only when it is created. If you close the dialog before saving it, create a new token.
Step 2: Find your Socket organization slug
In Socket, navigate to your organization’s page.
Find the organization slug in the page URL:
https://socket.dev/dashboard/org/{org-slug}/Copy the value represented by
{org-slug}.
Step 3: Enter the Socket credentials in Drata
In Drata, go to Connections.
Select the Available tab.
Search for Socket and select Connect.
Enter the following configuration values:
Field | Value |
API Token | The API token you generated in Step 1. |
Org Slug | The organization slug you copied in Step 2. |
Create and test the connection.
Step 4: Validate the connection
Confirm that the Socket connection shows as active in Drata.
Verify that Socket security alerts are available in Drata.
Verify that repositories from the connected Socket organization appear as repository resources.
