Skip to main content

Supported providers

Argus scans 16 connectors across four categories, each with a read-only authentication method. This page is the complete catalog. You do not need an account to see what Argus can scan; the same list drives the Connect account wizard on the Accounts page.

Every connector authenticates read-only. Nothing is installed in the scanned environment and Argus never gets write access. For AWS, the recommended credential is an assumed role scoped by a per-workspace External ID, so no long-lived keys are stored; see Connect an AWS account. What a connection grants and what the service keeps is set out in Trust & data handling.

Cloud (IaaS)​

Infrastructure-as-a-Service accounts, subscriptions, projects and tenancies.

ProviderIdentified byAuth methods
Amazon Web ServicesAccount ID (12 digits)Assume role, Static keys, AWS Organizations (many accounts at once, Pro)
Microsoft AzureSubscription IDService principal
Google CloudProject IDService-account key, OAuth refresh token
Oracle CloudTenancy OCIDAPI signing key
Alibaba CloudAccount IDStatic keys, RAM role
OpenStackCloud nameclouds.yaml

Container​

Clusters and images, scanned from their config or reference.

ProviderIdentified byAuth methods
KubernetesCluster nameKubeconfig
Container imageImage referencePublic image (no credentials)

SaaS / Identity​

Managed platforms and identity providers, scanned over their APIs.

ProviderIdentified byAuth methods
Microsoft 365Tenant domainCertificate, Client secret
Google WorkspacePrimary domainService account + delegation
GitHubOrganization / userPersonal access token, OAuth token, GitHub App
OktaOkta org URLPrivate-key JWT
VercelTeam / userAPI token
CloudflareAccount IDAPI token, Key + email
MongoDB AtlasOrganization IDAPI key pair

Infrastructure as Code​

Scan a repository of IaC templates for misconfigurations before they ship.

ProviderIdentified byAuth methods
Infrastructure as CodeRepositoryGit repository

Connect one​

Open Accounts and click Connect account, then pick a provider and its auth method. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. Every connector has its own step-by-step guide with what to set up on the provider side, the accepted auth methods, and the fields the wizard asks for: click the provider's name in the tables above, or open it from the Connect accounts section in the sidebar.