Supported providers
Argus scans 16 connectors across four categories, each with a read-only authentication method. This page is the complete catalog. You do not need an account to see what Argus can scan; the same list drives the Connect account wizard on the Accounts page.
Every connector authenticates read-only. Nothing is installed in the scanned environment and Argus never gets write access. For AWS, the recommended credential is an assumed role scoped by a per-workspace External ID, so no long-lived keys are stored; see Connect an AWS account. What a connection grants and what the service keeps is set out in Trust & data handling.
Cloud (IaaS)
Infrastructure-as-a-Service accounts, subscriptions, projects and tenancies.
| Provider | Identified by | Auth methods |
|---|---|---|
| Amazon Web Services | Account ID (12 digits) | Assume role, Static keys, AWS Organizations (many accounts at once, Pro) |
| Microsoft Azure | Subscription ID | Service principal |
| Google Cloud | Project ID | Service-account key, OAuth refresh token |
| Oracle Cloud | Tenancy OCID | API signing key |
| Alibaba Cloud | Account ID | Static keys, RAM role |
| OpenStack | Cloud name | clouds.yaml |
Container
Clusters and images, scanned from their config or reference.
| Provider | Identified by | Auth methods |
|---|---|---|
| Kubernetes | Cluster name | Kubeconfig |
| Container image | Image reference | Public image (no credentials) |
SaaS / Identity
Managed platforms and identity providers, scanned over their APIs.
| Provider | Identified by | Auth methods |
|---|---|---|
| Microsoft 365 | Tenant domain | Certificate, Client secret |
| Google Workspace | Primary domain | Service account + delegation |
| GitHub | Organization / user | Personal access token, OAuth token, GitHub App |
| Okta | Okta org URL | Private-key JWT |
| Vercel | Team / user | API token |
| Cloudflare | Account ID | API token, Key + email |
| MongoDB Atlas | Organization ID | API key pair |
Infrastructure as Code
Scan a repository of IaC templates for misconfigurations before they ship.
| Provider | Identified by | Auth methods |
|---|---|---|
| Infrastructure as Code | Repository | Git repository |
Connect one
Open Accounts and click Connect account, then pick a provider and its auth method. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. Every connector has its own step-by-step guide with what to set up on the provider side, the accepted auth methods, and the fields the wizard asks for: click the provider's name in the tables above, or open it from the Connect accounts section in the sidebar.