Skip to main content
Use this page to see what Semgrep needs from your source code manager (SCM): roles, token scopes, and GitHub App permissions for each feature. It is the canonical permissions reference.
Before you configureConfirm organizational readiness using the Pre-deployment checklist, which covers permission details and includes links to setup guides.

Permissions

The following tables list SCM roles and token or app scopes required for each Semgrep feature. Unless noted otherwise, pull request (PR) or merge request (MR) refers to a proposed set of code changes in your SCM. The Configure column links to setup guides for each feature.

GitHub permissions

Semgrep recommends connecting GitHub with a GitHub App. Some organizations use a personal access token (PAT) instead. Use the tabs below for the method that applies to you.

Next steps