Setup & Configuration
Vercel is a frontend hosting and deployment platform used for web applications.
Secureframe scans Vercel projects as cloud resources and automatically surfaces evidence for compliance-related tests.
To integrate Vercel with Secureframe, navigate to Integrations and search for “Vercel” on the “Available Integrations” page. (If you have the Custom Integration feature, click on "Add native connection"). Click “Connect” and follow the steps in the connection form.
Note: When generating the Vercel API token, use access that can list the team and projects you want synced. A token scoped only to a single project can fail during connect when Secureframe lists teams (often as a 403). For all projects, choose Full Account when creating the token.
Permissions, Fields, Controls, and Automated Tests
Click the provided link or navigate to the “Integration” page.
Select the “Available” tab.
Search for the integration.
Click “View Details”.
Frequently Asked Questions (FAQ)
What if I only want to sync certain projects?
Create a separate connection for each project you want to sync, or select Full Account when generating an API token to sync all projects. Use a token that can list the team and the target projects. A project-only token can fail connect with a 403 when Secureframe lists teams.
Why do some tests not list projects under the Evidence tab?
These tests are automatically pass based on Vercel's default configurations. No further action is required.
Connect fails with 403 when listing teams, or the token looks wrong. What should I use?
Generate the Vercel API token with access that can list the team and the projects you want synced. A token scoped only to a single project can fail during connect when Secureframe lists teams (often as a 403). For all projects, choose Full Account when creating the token. To limit scope, use a token that still has team/project list access, or create separate connections per project. Then reconnect and sync.
