Skip to content

Connector Prerequisites

XPosture connects to your existing security stack read-only. This page lists what each connector family needs from your side before its first scan. The guiding principle is the same everywhere: least privilege and read-only access — XPosture stores all connector credentials encrypted at rest and does not need write access to your tools.

The product shows the exact credential fields and click-path for each vendor when you add it (Integrations → select vendor → Configure Connection). Use this page for planning; use the in-product page as the authoritative field list.

Firewalls: Palo Alto & FortiGate

XPosture connects to Palo Alto (PAN-OS) and Fortinet FortiGate firewalls in more than one way — pick whichever suits your environment:

  • Configuration-file upload — export a configuration backup from the device and upload it. XPosture never connects to the device; it reads only the uploaded file. (Palo Alto: .xml export · FortiGate: .conf or .txt backup.)
  • Live API connection — connect XPosture directly to the firewall's management API with a read-only account, so it collects the configuration automatically on each scan.

Depending on your deployment and product version, additional connection options may be available for these firewalls — the team can confirm which methods fit your setup.

Support for additional network-device vendors (including Cisco device families and live SSH-based collection of network configurations) is in development — ask us about current availability.

Cloud & API connectors (read-only API credentials)

Each connector needs an API credential scoped to read access. The Integrations page in the product is the authoritative list of the connectors available in your version — vendor coverage grows release by release, so this page deliberately doesn't enumerate it.

Prerequisites we can state precisely today for commonly connected tools:

Tool Credential type Access needed
Cloudflare Scoped API token Zone: Read, Zone Settings: Read, Firewall Services: Read, Analytics: Read
Wiz OAuth2 client credentials read:resources, read:issues, read:vulnerabilities
Netskope API v2 token Read access to DLP/threat/web policy, alerts, incidents, clients
Okta API token Read-only administrator recommended
Cisco ASA Read-only admin account REST API over TCP/443
Microsoft products OAuth2 application registration Read-only permissions on the API each product integrates with
Active Directory LDAP/LDAPS bind account Read-only directory access

For any connector not listed here, ask us for the current permission requirements before creating the credential — grant what the connector needs and nothing more.

Network connectivity

  • SaaS deployments: outbound connectivity from XPosture to each connected vendor's API on that vendor's documented endpoint and port. No inbound access to your network is required.
  • On-premise deployments: the XPosture host needs outbound access to each source you configure, on that source's documented protocol and port (HTTPS for most cloud APIs; LDAP/LDAPS for on-premises Active Directory).