Heeler Secrets
You can connect OX to your Heeler instance to import its secrets findings. This lets you review exposed secrets and credentials alongside your other findings in the OX platform.
Heeler detects secrets, tokens, and other sensitive values exposed in your code. OX reads those results through the Heeler API, maps them to your applications, and presents them for triage, prioritization, and reporting.
After connecting, you see Heeler results on the Active issues page. Filter by Source tool > Heeler to focus on them.
What OX adds
Context and correlation: OX maps Heeler secrets findings to applications, repositories, and services to show impact and ownership.
Prioritization with severity factors: OX reprioritizes vendor severities when exploitability and environment context change the risk. Severity factors explain why the priority changed.
Unified queue: Heeler secrets findings appear as OX issues under Secret/PII Scan, so you triage exposed credentials next to results from your other scanners.
Terminology mapping
Heeler and OX use different labels for similar concepts. Use this map while you work.
Secrets
Exposed tokens, keys, and credentials in code
Issues (secrets)
Repositories, services
Scanned code units
Applications
Severity
Vendor severity rating
Issues with severity factors
Prerequisites
OX permissions: Permission to configure connectors.
Heeler API token: An API token from your Heeler account, from Step 1.
Step 1: Generate an API token [Heeler]
Heeler authenticates API requests with an API token generated from your Heeler account.
Sign in to Heeler at
https://app.heeler.com. Self-hosted deployments use your own instance URL.Go to your account or organization settings.
Generate an API token.
Copy the token and store it in a secure location.
Step 2: Determine your host URL
OX connects to Heeler at your instance base URL. Cloud tenants use https://app.heeler.com. Self-hosted deployments use their own instance URL. Confirm the value in your browser address bar while signed in to Heeler.
Step 3: Connect Heeler to OX [OX]
In OX, go to Connectors.
In the search box, enter
Heeler. The Heeler connector appears under Secret/PII Scan.Select the Heeler card to open the Configure your Heeler credentials dialog.

On the Token method, enter the following details.
Heeler Host URL
The base URL of your Heeler instance, for example https://app.heeler.com. Self-hosted deployments use your own instance URL.
API Token
The API token you created in Step 1.
Select Verify Connectivity to confirm the credentials, then select Connect.
Last updated
