> ## Documentation Index
> Fetch the complete documentation index at: https://docs.switchagents.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs moved from docs.flintai.dev to docs.switchagents.ai. Use docs.switchagents.ai for every link and request.
> To search these docs from an AI tool, connect the MCP server at https://docs.switchagents.ai/mcp. The page index is at https://docs.switchagents.ai/llms.txt.

# GitLab

> Scan a GitLab repository for agents and add them to your inventory

GitLab is a code-repository data source. Switch Trust scans your repository's source for AI
agents and reports the models, tools, and MCP servers behind them, along with any security
issues it finds. The scan runs as a GitLab CI/CD component inside your own pipeline, so there
is no credential to store in Switch Trust. You authenticate the component with a Switch Trust API key.

GitLab is a separate data source from GitHub so that results found on each are recorded and
shown apart. Agents discovered on GitLab trace back to their GitLab repository.

To open this page, go to **Settings**, then **Data sources**, select **GitLab**, and open the
**Setup** tab.

## Connect a repository

<Steps>
  <Step title="Get your credentials">
    You need two values: your Switch Trust instance URL and a Switch Trust API token.

    * **Instance URL.** The **Setup** tab shows the exact URL to use. Copy it from there.
    * **API token.** Use an existing token, or create one now if you don't have one. Tokens are
      managed under **Settings**, then **API Keys**, and the **Setup** tab has a
      **Create one now** shortcut.
  </Step>

  <Step title="Install the GitLab CI/CD component">
    Install [`flintai-codescan-workflow`](https://gitlab.com/explore/catalog/sandboxaq/flintai-codescan-workflow)
    from the GitLab CI/CD Catalog and include it in your project's `.gitlab-ci.yml`:

    ```yaml theme={null}
    include:
      - component: $CI_SERVER_FQDN/sandboxaq/flintai-codescan-workflow/inventory-scan@1.0.0
        inputs:
          flintai_instance: https://app.flintai.dev   # use the URL from your Setup tab
          flintai_token: $FLINTAI_TOKEN
          llm_model: anthropic:claude-opus-4-8
          llm_api_key: $ANTHROPIC_API_KEY   # the variable you create in step 4
    ```

    <Tip>
      Unlike GitHub Actions, a GitLab CI/CD component cannot read your CI/CD variables by itself.
      Pass `$VARIABLE` references explicitly in your `.gitlab-ci.yml` so GitLab expands them at
      runtime. Only the token needs to be masked. Your instance URL is not sensitive, so pass it
      to the component's `flintai_instance` input as a plain value.
    </Tip>
  </Step>

  <Step title="Store your token as a GitLab CI/CD variable">
    In your project or group settings, go to **Settings**, then **CI/CD**, then **Variables**,
    and add a variable named `FLINTAI_TOKEN` with the token from the first step. Enable the
    **Mask variable** toggle to keep it out of job logs.

    Scanning more than one repository? Define this variable at the group level so it is shared
    across projects.
  </Step>

  <Step title="Enable LLM-based scanning">
    The scanner calls an LLM from the pipeline to analyze your code, so this step is required.

    * Add your LLM provider's API key as a masked CI/CD variable. Name it for your provider,
      one of `OPENAI_API_KEY`, `GOOGLE_API_KEY`, or `ANTHROPIC_API_KEY`, then reference that same
      variable through the `llm_api_key` input. The example above uses
      `llm_api_key: $ANTHROPIC_API_KEY` to match its `anthropic` model.
    * Choose the model with the `llm_model` input, in `provider:model` form.

    Supported providers are OpenAI, Google (Gemini), and Anthropic.
  </Step>
</Steps>

Once the pipeline runs and reports its first scan, the **GitLab** card reads **Connected**.

### Restrict to the default branch (optional)

Use the `rules` input to control when the scan runs, for example only on the default branch:

```yaml theme={null}
    rules:
      - if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
```

### Target a specific runner (optional)

The component adds a scan job named `flintai-inventory-scan`. If a particular runner supports
`docker:dind`, override that job with the appropriate tags:

```yaml theme={null}
flintai-inventory-scan:
  tags:
    - dind
```

## The Scans tab

Open the **Scans** tab to see each connected repository with the time of its most recent
scan. A fresh timestamp means results arrived.

<Warning>
  Check the **Scans** tab, not the **Connected** status, to confirm results are landing. The
  card status does not yet reflect a live connection check, so it can read **Connected** before
  your first scan has run.
</Warning>

## Next steps

<CardGroup cols={2}>
  <Card title="Discover your agents" icon="radar" href="/switch-trust/getting-started/discover">
    Set up a repository scan end to end, from workflow file to first results
  </Card>

  <Card title="Read your discovery results" icon="triangle-exclamation" href="/switch-trust/discovery/results">
    Work out what needs attention first, whether a finding is real, and when it's resolved
  </Card>
</CardGroup>
