OX Security is an Application Security Posture Management (ASPM) and software supply chain security platform that unifies SAST, SCA, secrets detection, IaC, container, API, and pipeline scanning with code-to-cloud attack path analysis, so you can detect, prioritize, and remediate the application risks that actually matter from a single console.
Torq enables quick and easy integration with OX Security, so you can automate anything and everything within moments. Torq's pre-built OX Security steps include:
Get Issues
Get Issue
Get Applications
Get Single Application Info
Get App Owners
Get All Tags
Get App Tags
Get API Security Items
Check Scan in Progress
Run GraphQL Query
+5 more...
If you don't see a step you need, you can create your own in various ways, such as using the Send an HTTP Request step or Torq's Step Builder, and share it across your organization.
Use OX Security to trigger workflows in Torq
Step One: Create an OX Security trigger integration in Torq
Navigate to integration: In Torq, go to Build > Integrations > Triggers > OX Security and click Add Instance.
Configure the integration:
Give the integration a unique and meaningful name.
Click Add.
Save information: Copy and save the webhook URL. You'll need it in OX Security.
Step Two: Add the webhook in OX Security
Navigate to workflows: In the OX Security console, go to Workflows > Regular Scan Workflows and click Create New Workflow.
Give the workflow a name and description, then click Create.
Select a trigger for when you want to send events to Torq.
In the left panel under Action > Notification, drag in the Webhook tile.
Configure the webhook:
Click Add.
Finalize: Ensure the workflow is active by selecting the toggle next to the workflow name.
Use OX Security steps in a Torq workflow
Step One: Generate an OX Security API key
Navigate to API keys: In the OX Security console, go to Settings > API Key and click Create API Key.
Create a key:
API Key Name: Give the key a unique and meaningful name.
API Key Type: Select API Integration.
Role: Assign a role that grants the permissions required for the steps you want to run. The key can only call the APIs its role allows.
Scope: Select Entire organization, or select Custom to limit the key to specific app owners and tags.
Expiration Date: Set an expiration date. The key stops authenticating after this date.
Finalize: Click to create the key.
Save information: Copy and save the API key. Be sure to save it somewhere, you cannot access it again after closing the dialog.
Step Two: Create an OX Security Steps integration in Torq
Navigate to integration: In Torq, go to Build > Integrations > Steps > OX Security and click Add Instance.
Set up integration:
Instance name: Give the integration a unique and meaningful name.
API Key: Paste the API key you copied earlier.
Finalize: Click Add to save.





