> AI agents: this is one page from PostHog's docs. Full index of Markdown docs for LLMs: https://posthog.com/llms.txt

# Linking Snyk as a source - Docs

Copy page

# Linking Snyk as a source - Docs

![](https://res.cloudinary.com/dmukukwp6/image/upload/texture_tan_9608fcca70)

![](https://res.cloudinary.com/dmukukwp6/image/upload/texture_tan_dark_a92b0e022d)

Let AI connect your sources for you

Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

`npx @posthog/wizard warehouse`

[Learn more](/wizard.md)

![PostHog Wizard hedgehog](https://res.cloudinary.com/dmukukwp6/image/upload/wizard_3f8bb7a240.png)

![](https://res.cloudinary.com/dmukukwp6/image/upload/wizard_3f8bb7a240.png)Let AI connect your sources for you

**Alpha release**

This source is currently in **alpha**. The interface and available tables may change.

The Snyk connector pulls your organizations, projects, targets, and vulnerability issues into the PostHog Data warehouse, so you can track your security backlog, severity mix, and remediation trends alongside your product data.

## Prerequisites

You need a Snyk account with REST API access so you can generate an API token. The token can read every organization it has access to, so a service account token scoped to the organizations you want to sync works well.

## Adding a data source

1.  In PostHog, go to the [Sources tab](https://app.posthog.com/data-management/sources) of the data pipeline section.
2.  Click **\+ New source** and click **Link** next to this source.
3.  Enter your credentials (see [Configuration](#configuration) below) and click **Next**.
4.  Select the tables you want to sync, choose a sync method and frequency, then click **Import**.

Once the syncs are complete, you can start querying this data in PostHog.

When linking Snyk, you'll need:

-   **API token** – generate a personal token in your [Snyk account settings](https://app.snyk.io/account), or create a service account token in your organization or group settings.
-   **Region** – the region your Snyk account is hosted on (US, EU, or AU). Snyk's regional stacks are independent, and a token only works on its own region.
-   **Organization ID** (optional) – limit the sync to a single organization. Leave it blank to sync every organization the token can access. You can find the ID in your organization's settings page.

## Sync modes

Each table can be synced in one of several modes, depending on what the source supports:

-   **Webhook** (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
-   **Incremental** – only new or updated rows are synced on each run, using a cursor field (such as an `updated_at` timestamp). Cheaper than a full refresh, but deletes aren't captured.
-   **Append only** – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
-   **Full refresh** – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.

See [sync methods](/docs/cdp/sources.md#sync-methods) for a full explanation of how each mode works and how to choose between them.

The issues table supports incremental syncs on `updated_at` (recommended) or `created_at`. The other tables are full refresh only.

## Configuration

| Option | Type | Required |
| --- | --- | --- |
| API token | password | Yes |
| Region | select | Yes |
| Organization ID (optional) | text | No |

## Supported tables

| Table | Description | Sync method | Incremental field | Primary key |
| --- | --- | --- | --- | --- |
| organizations | A Snyk organization the API token can access. Organizations group projects, targets, and issues, and carry their own settings and membership. | Full refresh | — | — |
| projects | A project scanned by Snyk within an organization — one entry per manifest, container image, or IaC configuration monitored for vulnerabilities. | Full refresh | — | — |
| targets | A target is the scanned entity a project comes from — a code repository, container image, or other importable asset within an organization. | Full refresh | — | — |
| issues | A vulnerability, license, or configuration issue found by Snyk in an organization's projects — the core findings table for tracking security backlog, severity mix, and remediation over time. | Incremental, Full refresh | updated_at, created_at | — |

Tables scoped to an organization (projects, targets, and issues) include an `organization_id` column, so you can join them back to the organizations table.

## Troubleshooting

-   If you see an authentication error, your Snyk API token may be invalid or revoked. Generate a new token in your Snyk account settings, then reconnect.
-   If the connection fails with a valid token, check that the selected region matches where your Snyk account is hosted.
-   If an organization is missing from the sync, check that the token has access to it, or clear the organization ID field to sync everything the token can see.

If your sync is failing or data looks wrong, see the [Data warehouse troubleshooting guide](/docs/data-warehouse/troubleshooting.md). If that doesn't help, [contact support](https://us.posthog.com/#panel=support%3Asupport%3Adata_warehouse%3A%3Atrue) – we're happy to help.

### Was this page useful?

HelpfulCould be better