About Obsidian Security
Obsidian Security is a SaaS security posture management (SSPM) platform that monitors your connected cloud applications, generates security intelligence alerts, and tracks posture and compliance state. Connecting it to Serval lets workflows read intelligence alerts, query accounts and entities, list connected services, search activity events, read posture and compliance data, and perform write operations such as updating alert status. Authentication: API token (bearer). You pick the regional API endpoint that matches your Obsidian Security tenant and paste an API access token created in Obsidian Security. Serval stores the token server-side and attaches it to requests for you - it is never exposed to workflow code, and it is only ever sent to Obsidian’s own regional API domains. Data sync: On demand. There is no background sync or scheduled ingestion - workflows, actions, and health checks call the Obsidian Security API at the moment they run, and nothing is pulled into Serval on a schedule.What the Obsidian Security integration enables
Get your credentials
Serval connects with an API access token created in your Obsidian Security tenant, plus the regional API endpoint your tenant is hosted on. Obsidian documents token creation in its API Access Tokens guide.Open API Access Tokens in Obsidian Security
Create a token
Grant the token read access
Copy the token immediately
Confirm your tenant's region
Connect in Serval
Region (required)
API Token (required)
Save and verify
Verifying the connection
The Obsidian Security integration ships four health checks: Validate Obsidian Security API connection - verifies the configured token can reach the Obsidian Security API by querying the API version.- Success: “Successfully connected to Obsidian Security API.”
- Failure: “Unable to connect to the Obsidian Security API. Verify that the API token is valid and the selected region matches your tenant.”
- Success: “Successfully retrieved [number] connected service(s) from Obsidian Security.”
- Failure: “Unable to list connected services. Verify the API token has read access to the Obsidian Security service catalog.”
- Success: “Successfully read accounts from Obsidian Security (returned [number] record(s)).”
- Failure: “Unable to read accounts from Obsidian Security. The API token may lack permission to query the entity catalog.”
- Success: “Successfully read intelligence from Obsidian Security (returned [number] alert(s)).”
- Failure: “Unable to read intelligence alerts. The API token may lack permission to query intelligence, or no alerts exist yet.”
Gotchas and troubleshooting
The connection is green but a workflow fails with a permission error
The connection is green but a workflow fails with a permission error
Region must exactly match your tenant
Region must exactly match your tenant
The intelligence health check fails on a brand-new tenant
The intelligence health check fails on a brand-new tenant
It's a GraphQL-only API
It's a GraphQL-only API
Connections are named by region, not tenant
Connections are named by region, not tenant
Need help? Contact support@serval.com for assistance with your Obsidian Security integration.

