Bright Security
Note: This capability may be in Early Access (EA) in your environment. Coordinate availability with your OX technical contact.
You can connect OX to your Bright Security instance to import Dynamic Application Security Testing (DAST) results. This lets you view DAST issues alongside other security findings in the OX platform.
Prerequisites
Bright Security Admin account.
Step 1: Get a Bright API key [Bright Security]
Bright Security (Bright DAST) utilizes API keys for authentication and integration purposes, as follows:
User Keys (Personal API Keys): These keys are created and managed within a user's personal settings in the Bright DAST platform. They are used for individual user-specific operations and integrations.
Project Keys: These keys are associated with specific projects within Bright DAST and are used for project-level integrations and operations.
Organization Keys: These keys provide access at the organizational level, often used for broader integrations and management across multiple projects.
For integration with OX, you need to create a Personal API Key.
Use a read-only key. If your organization prefers stricter scoping, create a dedicated service account and generate the key from that account.
To generate a Bright Security API key:
Sign in to Bright Security.
Access your personal settings by clicking on your profile in the upper-right corner of the screen and selecting User Settings.
Locate the MANAGE YOUR USER API KEYS section, and select + Create API key.
Define the token Name.
Select the scope(s) and action types (such as read or write), as follows:
projects:read
View available projects and project issues
Recommended minimum (read-only)
issues:read
View detected scan issues
Recommended minimum (read-only)
scans:read
View existing scans
(Optional) For richer evidence
(Optional) Set an Expiration Date.
Select Create. Copy the key and store it securely, you won’t be able to view it again after leaving the popup. Created keys (without full values) appear under Manage your organization API keys.
Step 2: Connect Bright to OX [OX]
In the OX platform, go to the Connectors page.
Select Add Connector and search for Bright.

In the Configure your Bright Security credentials box, provide the following details:
Bright Host URL
The base server URL Bright provides.
Token
The unrestricted API key (no products selected) you generated in Bright Security.
Select CONNECT.
To select specific Bright projects to import, click the gear icon next to the DELETE button.
Select the Bright projects and select SAVE.
When connected, OX starts pulling DAST data from Bright.
Last updated
