Connect a repository
1
Get your credentials
You need two values: your Flint AI instance URL and a Flint AI API token.
- Instance URL. The Setup tab shows the exact URL to use. Copy it from there.
- API token. Use an existing token, or create one now if you don’t have one. Tokens are managed under Settings, then API Keys, and the Setup tab has a Create one now shortcut.
2
Install the GitLab CI/CD component
Install
flintai-codescan-workflow
from the GitLab CI/CD Catalog and include it in your project’s .gitlab-ci.yml:3
Store your token as a GitLab CI/CD variable
In your project or group settings, go to Settings, then CI/CD, then Variables,
and add a variable named
FLINTAI_TOKEN with the token from the first step. Enable the
Mask variable toggle to keep it out of job logs.Scanning more than one repository? Define this variable at the group level so it is shared
across projects.4
Enable LLM-based scanning
The scanner calls an LLM from the pipeline to analyze your code, so this step is required.
- Add your LLM provider’s API key as a masked CI/CD variable. Name it for your provider,
one of
OPENAI_API_KEY,GOOGLE_API_KEY, orANTHROPIC_API_KEY, then reference that same variable through thellm_api_keyinput. The example above usesllm_api_key: $ANTHROPIC_API_KEYto match itsanthropicmodel. - Choose the model with the
llm_modelinput, inprovider:modelform.
Restrict to the default branch (optional)
Use therules input to control when the scan runs, for example only on the default branch:
Target a specific runner (optional)
The component adds a scan job namedflintai-inventory-scan. If a particular runner supports
docker:dind, override that job with the appropriate tags:
The Scans tab
Open the Scans tab to see each connected repository with the time of its most recent scan. A fresh timestamp means results arrived.Next steps
Discover your agents
Set up a repository scan end to end, from workflow file to first results
Read your discovery results
Work out what needs attention first, whether a finding is real, and when it’s resolved

