Skip to main content
Serval’s Socket integration lets you automate software supply-chain security: vet open-source dependencies, monitor supply-chain alerts, run and gate on dependency scans, triage findings, and export SBOMs. The integration connects via a Socket organization API token.

What is Socket?

Socket analyzes open-source packages (npm, PyPI, Maven, Go, and more) for supply-chain risk — malware, typosquats, risky install scripts, hijacked maintainers, known CVEs, and license issues — and scores every package’s health. Organizations connect Socket to their repositories and enforce security policies on the dependencies entering their code.

What Serval can do once connected

Socket meters API usage in hourly quota units that vary by plan (Free 500/hr, Team 2,500/hr, Business 10,000/hr). Alert listing costs 10 units per request and batch package lookups cost 100, so schedule polling workflows accordingly.

Configure Socket

Prerequisites

  • A Socket organization you can administer
  • Permission to create an organization API token

Create an API token

  1. In Socket, open Settings → API Tokens
  2. Click Create API Token
  3. Configure the token:
    • Name: e.g. Serval Integration
    • Scopes: enable the scopes below
  4. Create the token and copy the value — it is only shown once

Suggested scopes


Serval Configuration

  1. In Serval, go to Integrations → All integrations → Socket → Connect
  2. Enter:
  3. Click Save
Serval validates the connection and runs healthchecks for authentication, organization access, repository listing, and alert listing. Once verified, the integration shows Healthy on the Integrations page.

Managing access later

  • Rotate token — Rotate the token in Socket (Settings → API Tokens), then update the token in Serval’s integration settings
  • Disconnect — Remove the integration from Serval; revoke the token in Socket

Need help? Contact support@serval.com for assistance with your Socket integration.