Poliogo

Connect GitLab

Connect your gitlab.com account and pick a project. Updates arrive as merge requests from Poliogo's own branch.

How it connects
Server-side OAuth
Setup time
Under 60 seconds
Access
api scope — see the table below

How the connection works

  1. AuthoriseApprove Poliogo on the provider's own screen. No password ever reaches us.
  2. Select projectYour repositories are listed for you — nothing to paste or misremember.
  3. Detection stays onScheduled scans re-read your live site and diff it against this scan, so a new tool becomes an update; approving one opens the merge request.

What it looks like once connected

An illustration of this connection inside your Poliogo dashboard — not live data.

Live site checks activeExample
acme-inc/acme-web · main

Detected in this project

  • Stripestripe in package.json
  • SupabaseSUPABASE_URL in .env.example
  • OpenAIfetch to api.openai.com — no SDK
  • PostHognew since your last scan
Last scan: 5 minutes ago3 documents up to date
Files are read in memory and dropped when the request ends. What persists is this list of service names.

Exact permissions requested

Every permission this connection asks for, named as GitLab names it on its own consent screen — so you can compare this table to what you are shown.

PermissionGrantWhat it is used for
apiWriteGitLab's full API scope — and we ask for it rather than read_api because installing pages commits a branch, opens a merge request and merges it. GitLab publishes no narrower write grant that also reaches your project list.
Project listingReadCovered by the same scope: list your projects so you can choose one.
Repository filesReadCovered by the same scope: read manifests and source to detect your stack.

Setting it up

What you do, and what you will be looking at while you do it.

  1. Authorise Poliogo on GitLab

    Press Connect GitLab below and approve on GitLab's own screen. The token is exchanged and held server-side; it is never shown to the browser.

  2. Know what you are approving

    GitLab's screen will say api, not read_api. That is deliberate and it is the smallest grant that works: installing your policy pages commits a branch, opens a merge request and merges it, and GitLab offers no narrower write scope that also reaches your project list. The scope table below spells out what each part is used for.

  3. Pick a project

    Your gitlab.com projects are listed for you — nothing to paste. Choose the one this product lives in.

  4. Check what it found

    Review the detected service list and correct anything before a clause is chosen.

  5. Merge the merge request

    Installs and updates arrive as merge requests from Poliogo's own poliogo/* branch. Changes reach your default branch only through a merge request you approve.

Poliogo · New projectExample

Choose how to scan your app

Pick one. We scan your code and settings to find the services your app uses — the scan keeps that list, not your files.

Git RepositoryRecommendedThe most accurate scan — we read the dependencies your app actually ships.Choose another way
GitHubGitLabBitbucket

Connect GitLab and pick a project — we read the manifests, never write.

Authorise on GitLab

apiWrite
Project listingRead
Repository filesRead

Granted on GitLab's own screen — this panel can show it, never widen it.

Connect GitLab

Select repositories

Find a repository (12)
acme-webPrivateacme-siteacme-docsAlready scanned
Choose which repositories Poliogo can read →Read my project
Tell us what you use instead
The Poliogo setup screen for GitLab, drawn from the same catalogue the app reads. An illustration — not live data, and nothing here is clickable.

What Poliogo detects from GitLab

The right-hand column is the part worth reading: it is what this connection cannot reach even if we wanted it to.

What it reads

  • Dependency manifests — package.json, requirements.txt, Cargo.toml, go.mod, composer.json, pubspec.yaml and the rest.
  • The endpoints your code actually calls. A raw fetch to api.openai.com is found even with no SDK installed.
  • Environment variable names in .env.example — STRIPE_SECRET_KEY proves Stripe without reading any secret.
  • Your framework and where its routes live, so generated policy pages land in the right folder.
  • Cookies and tracking scripts referenced anywhere in the source.

What it never reads

  • Repositories you did not select.
  • The value of any secret or environment variable.
  • Your default branch, except through a pull request you approve — updates arrive on a poliogo/* branch.

Ready to connect GitLab?

The free plan covers one project with no credit card. You approve everything before a single document is written.

Poliogo is a compliance management platform, not a law firm. What it produces is not legal advice. See exactly what each connection reads.