Linking Infisical as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
The Infisical connector syncs audit logs, projects, identities, and more into the PostHog data warehouse, so you can analyze them alongside your product data.
Prerequisites
Credentials that can read the data you want to sync. PostHog only reads data, so read access is enough.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
Connect an Infisical machine identity to pull your organization's audit logs, projects, identities, and memberships. Secret values are never synced.
In Infisical, create a machine identity under Organization settings > Access control > Identities, add a Universal Auth method to it, and grant it read permissions for the data you want to sync (audit logs, projects, identities, and memberships). Note that audit log access is plan-gated on Infisical Cloud.
- Base URL:
https://app.infisical.com(US cloud),https://eu.infisical.com(EU cloud), or your self-hosted URL. - Organization ID: found in your Infisical URL after
/org/, or in organization settings. - Client ID / Client secret: from the identity's Universal Auth configuration.
You'll be asked for:
- Base URL: for example
https://app.infisical.com. - Organization ID: for example
00000000-0000-0000-0000-000000000000. - Client ID
- Client secret
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
All Infisical tables are full refresh. Each sync replaces the contents of the table.
Configuration
| Option | Type | Required |
|---|---|---|
Base URL | text | Yes |
Organization ID | text | Yes |
Client ID | text | Yes |
Client secret | password | Yes |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
audit_logs | The first sync fetches your plan's full retained history | Incremental, Full refresh | createdAt | — |
projects | Projects (workspaces) in the organization, including their environments and settings. | Full refresh | — | — |
identities | Machine identity memberships in the organization: each machine identity with its organization role and last login details. | Full refresh | — | — |
organization_memberships | User memberships in the organization: each member with their role, status, and last login details. | Full refresh | — | — |
project_memberships | User memberships per project: which users belong to which project and the roles they hold there. One row per user-project membership across every project the machine identity can read. | Full refresh | — | — |
organization_roles | Organization roles: the built-in admin, member, and no-access roles plus any custom roles. Resolves the role and roleId columns on organization_memberships, identities, and groups. | Full refresh | — | — |
project_roles | Project roles per project: the built-in roles plus any custom roles. Resolves the roles on project_memberships and project_group_memberships. Built-in roles get a new id on every sync, so join on projectId and slug. | Full refresh | — | — |
groups | User groups in the organization, with the organization role each group grants its members. | Full refresh | — | — |
group_members | Members of each group: one row per user or machine identity in a group. | Full refresh | — | — |
project_group_memberships | Groups attached to each project and the project roles they grant. One row per group-project membership across every project the machine identity can read. | Full refresh | — | — |
secret_scanning_findings | Leaked credentials found by secret scanning in connected data sources such as GitHub, GitLab, or Bitbucket repositories. One row per finding across every secret scanning project the machine identity can read. The secret value itself is not included. | Full refresh | — | — |
project_environments | Environments (e.g. dev, staging, prod) in each project. Use it to resolve the environment IDs and slugs that audit logs, secret syncs, and other tables reference. | Full refresh | — | — |
project_identity_memberships | Machine identity memberships per project: which machine identities can access which project and the roles they hold there. One row per identity-project membership across every project the machine identity can read. | Full refresh | — | — |
secret_syncs | Secret syncs that push a project's secrets to an external destination such as AWS Secrets Manager, GitHub, or Vercel, with the status of their last sync, import, and remove jobs. One row per sync across every secrets management project the machine identity can read. Secret values are not included. | Full refresh | — | — |
Troubleshooting
- If the connection fails with an authorization error, the client secret is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
- If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.