Skip to main content

Vercel

Written by Brady Price

Setup & Configuration

Vercel is a frontend hosting and deployment platform used for web applications.

Secureframe scans Vercel projects as cloud resources and automatically surfaces evidence for compliance-related tests.

To integrate Vercel with Secureframe, navigate to Integrations and search for “Vercel” on the “Available Integrations” page. (If you have the Custom Integration feature, click on "Add native connection"). Click “Connect” and follow the steps in the connection form.

Note: When generating the Vercel API token, use access that can list the team and projects you want synced. A token scoped only to a single project can fail during connect when Secureframe lists teams (often as a 403). For all projects, choose Full Account when creating the token.


Permissions, Fields, Controls, and Automated Tests

  1. Click the provided link or navigate to the “Integration” page.

  2. Select the “Available” tab.

  3. Search for the integration.

  4. Click “View Details”.


Frequently Asked Questions (FAQ)

What if I only want to sync certain projects?

  • Secureframe connects per Vercel team, not per project. The narrowest supported scope is a token created for a single Vercel team with All Projects selected, so create one connection for each team you want synced.

  • Tokens scoped to a single project are not supported. Vercel introduced project scoped tokens on July 30, and these tokens can't read team information. The connection will fail with a 403 error when Secureframe lists teams.

  • Full Account also works and syncs every team, but only if your Vercel team does not enforce SAML. The non SAML warning shown in Vercel indicates this.

When I create a new project in Vercel, will it show up in Secureframe, and will it be in scope?

  • Yes. Each sync pulls every project the team token can see, so a new Vercel project appears on the next sync (daily, or sooner if you sync manually). New projects default to in scope because frameworks include an "All cloud resources" rule. Projects you already unchecked stay unchecked. Syncs do not undo that. To keep new Vercel projects out of scope automatically, edit the framework Scoping Rules so they only match the projects you want. Do that for each framework.

Why do some tests not list projects under the Evidence tab?

  • These tests are automatically pass based on Vercel's default configurations. No further action is required.

    Connect fails with 403 when listing teams, or the token looks wrong. What should I use?

    • Generate the Vercel API token with access that can list the team and the projects you want synced. A token scoped only to a single project can fail during connect when Secureframe lists teams (often as a 403). For all projects, choose Full Account when creating the token. To limit scope, create a separate connection for each Vercel team, using a token scoped to that team with All Projects selected. Scoping a token down to a single project is not supported.

    Can I use a Vercel token scoped to a single project?

    • Vercel’s project-scoped tokens can only access that project. They can’t list the team, which Secureframe needs during connect, so those tokens return a 403. Use a team-scoped token with All Projects selected (or Full Account if your team does not enforce SAML). To limit what Secureframe evaluates, connect at the team level and control which projects are in scope in Secureframe, rather than narrowing the Vercel token to one project.

Did this answer your question?