Documentation
Get Tenzai running in your repository
Setup takes under five minutes. This guide covers repository authorization, reviewing your first scan, and connecting to your CI pipeline.
Quickstart
Get your first scan result in under five minutes by following these steps.
Create an account
Sign up at gotenzai.com/register. Free plan, no credit card required.
Authorize a repository
From your dashboard, select your repository host (GitHub, GitLab, or Bitbucket) and authorize Tenzai with read access to the repos you want to scan.
Trigger your first scan
Tenzai starts an initial scan automatically after authorization. You can also trigger a scan manually from your repository dashboard.
Review findings and fix proposals
Each finding includes an AI-generated fix proposal. Review the proposal, apply it to your branch, and mark the finding resolved.
Connecting repositories
Tenzai supports GitHub, GitLab, and Bitbucket. From your dashboard, navigate to Repositories and click Add repository. You will be directed to the OAuth authorization flow for your chosen provider.
Tenzai requests read access to repository contents and metadata. It does not request write access and does not commit code to your repository. Pull request comment posting uses a separate, narrower token scope.
Your first scan
After authorization, Tenzai starts an initial full scan automatically. Full scan duration depends on repository size and language, typically between three and fifteen minutes. You will receive a notification when results are ready.
Subsequent scans run incrementally on each push. The incremental scan evaluates changed files and their dependency tree, not the entire codebase, so they complete in under two minutes for most repositories.
Scan types
Tenzai performs three types of analysis on each authorized repository.
- SAST (Static Analysis)
- Parses your codebase and builds a call graph to identify insecure patterns, taint flows, and injection points. Runs on the current branch without executing code.
- DAST (Dynamic Analysis)
- Tests running application endpoints with crafted payloads to surface runtime vulnerabilities. Requires a staging URL to be configured in your repository settings.
- Dependency Analysis
- Cross-references your dependency manifest against CVE databases, including transitive dependencies. Reachability analysis filters out CVEs in dependencies your code never calls.
Severity levels
Tenzai assigns each finding one of four severity levels based on exploitability, impact, and reachability.
- Critical
- Directly exploitable in production with high impact. Blocks CI checks when severity gating is enabled at Critical or above.
- High
- Significant risk with a realistic attack path. Included in CI gating by default.
- Medium
- Exploitable under specific conditions or with limited impact. Included in scan reports and notifications.
- Low
- Informational or low-impact findings. Not included in CI gating by default.
Fix proposals
Every confirmed finding includes a fix proposal generated by Tenzai's AI engine. Each proposal includes:
- A unified diff scoped to the affected function
- A confidence score (0.0 to 1.0) indicating model certainty
- A plain-language explanation of why the fix is correct
Fix proposals are advisory. A developer reviews and applies the change. Tenzai does not commit code to your repository.
CI/CD integration
Tenzai integrates with CI pipelines through a webhook your pipeline calls after each build. Configure the webhook URL from your repository settings in the Tenzai dashboard.
To add a severity gate to your pipeline, install the Tenzai CLI tool in your CI environment and add a step that blocks the build when findings exceed your configured threshold.
npx tenzai check --repo $TENZAI_REPO_ID --threshold high
The --threshold flag accepts critical, high, medium, or low. The check exits non-zero when any finding meets or exceeds the specified level.
Notifications
Tenzai can route findings to Slack or Microsoft Teams as well as posting them directly on pull requests as review comments.
- Slack
- Connect a Slack workspace from Integrations in your account settings. Configure which severity levels trigger a notification and which channel receives them.
- Microsoft Teams
- Add a Tenzai connector to a Teams channel using the incoming webhook URL. Paste the URL into the Teams integration field in your account settings.
- Pull request comments
- Tenzai posts a review comment on the pull request for every new finding it detects. Each comment includes the finding summary and the proposed fix diff.
API overview
The Tenzai REST API allows you to retrieve scan results, trigger scans programmatically, and push finding status updates from your own tooling.
Base URL:
https://api.gotenzai.com/v1
Authentication
All API requests require an Authorization header with a Bearer token. You can generate API tokens from your account settings.
Authorization: Bearer tnz_live_xxxxxxxxxxxxxxxxxxxx
Scans
/repos/{repo_id}/scans
List all scans for a repository. Returns scan id, status, timestamp, and finding counts.
/repos/{repo_id}/scans
Trigger a new scan for the specified repository. Returns the scan id and initial status.
/scans/{scan_id}
Retrieve full scan details including status, duration, and finding breakdown by severity.
Findings
/scans/{scan_id}/findings
List all findings for a scan. Includes severity, type, file location, and fix proposal status.
/findings/{finding_id}
Retrieve a single finding with its full fix proposal diff, confidence score, and explanation.
/findings/{finding_id}/resolve
Mark a finding as resolved. Accepts an optional resolution note. Returns updated finding status.