Zelix Security Technical Documentation
Complete guides, integration walkthroughs, and REST API specifications for autonomous non-human identity governance.
1. Quickstart Guide
Zelix connects to your SaaS estate agentlessly via official cloud provider APIs. Follow these steps to trigger your initial discovery scan:
POST /api/scans/trigger. Discovery completes in ~5 seconds.2. SaaS Platform Connectors
Zelix requires minimal read-only permissions to audit machine identities. You never grant full write or super-admin credentials during discovery:
Application.Read.All•
Directory.Read.AllUsed to evaluate enterprise application consent grants and client secret expirations.
admin.directory.user.readonly•
iam.serviceAccounts.listUncovers service accounts with Domain-Wide Delegation (DWD) granted.
members:read•
administration:readMonitors organization deploy keys with write permissions, PATs, and GitHub Apps.
apps:read•
users:readFlags bot tokens authorized for private channel history and file reading.
3. Zero-Day Real-Time Ingestion Webhooks
Don't wait for scheduled daily scans to detect rogue credentials. Configure event webhooks in your SaaS platforms to ingest new deploy keys, PATs, and OAuth grants the instant they are created:
POST https://zelixsec.com/api/webhooks/github
Content-Type: application/json
X-Hub-Signature-256: sha256=...
{
"action": "created",
"key": {
"id": 8941029,
"key": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5...",
"title": "ci-runner-deploy-key",
"read_only": false
},
"repository": { "full_name": "acme/prod-core" },
"sender": { "login": "devops-admin" }
}4. Autopilot Governance & CISO Whitelists
Autopilot enables autonomous containment without human intervention for high-risk threats, while providing flexible CISO waivers for critical legacy systems:
5. REST API Reference
All dashboard capabilities are accessible via standard REST endpoints with bearer token authentication:
| Method | Endpoint | Description |
|---|---|---|
| GET | /api/identities | Filter & list all discovered machine identities |
| POST | /api/scans/trigger | Trigger instant multi-SaaS discovery scan |
| POST | /api/remediation/execute | Execute quarantine, revoke, or scope trim |
| POST | /api/compliance/generate | Generate DORA / NIS2 / Insurance passport (R2) |
| POST | /api/billing/checkout | Initialize Stripe Checkout subscription session |