---
title: GitHub Actions Integration
description: "Discover how to seamlessly integrate Pentest-Tools.com with GitHub Actions to automatically trigger vulnerability assessments and surface results directly within your CI/CD workflows. This integration enables security testing to run as part of your development pipeline, helping your team catch risks earlier and remediate issues before code reaches production.\nBy embedding pentest validation and vulnerability scanning into your GitHub Actions workflows, you can enforce security gates, fail builds on critical findings, and maintain continuous visibility into your application’s security posture. Ideal for DevSecOps teams, this setup reduces manual coordination, accelerates secure releases, and ensures every deployment is backed by up-to-date security insights—making your development process faster, safer, and more reliable."
---

[Skip to content](https://support.pentest-tools.com/github-action-integration#main-content)

[![flat ptt\_logo\_RGB\_alpha](https://support.pentest-tools.com/hubfs/flat%20ptt_logo_RGB_alpha.svg)](https://support.pentest-tools.com/)

Open main navigation

Close main navigation

- [Raise a ticket](https://share.hsforms.com/1iXO7OCiAQV67C-9QIn-4Dgbqmk4)

[Raise a ticket](https://share.hsforms.com/1iXO7OCiAQV67C-9QIn-4Dgbqmk4)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [Support Center](https://support.pentest-tools.com/)
2. [Integrations](https://support.pentest-tools.com/integrations)

February 17, 2026

# GitHub Actions Integration

## Automate security scanning in your CI/CD pipeline with Pentest-Tools.com

#### **Getting started with the GitHub Actions integration for the first time is simple.**

The Pentest-Tools.com GitHub Action allows you to run automated security scans directly in your CI/CD pipeline.

Whether you're testing on every commit, protecting pull requests, or running scheduled security audits, this integration helps you catch vulnerabilities before they reach production.

###### **What you can do:**

- Run **light scans** (free, no API key required, but recommended in order to see the scans in the platform) for quick vulnerability checks
- Run **deep scans** (requires API key) for comprehensive security testing
- Automatically **fail builds** based on vulnerability severity
- Get results in **JSON or text format** for easy processing
- Configure **flexible scanning** on commits, pull requests, or schedules

#### **How to Access the Configuration Tool**

Head over to the[Integrations](https://app.pentest-tools.com/integrations) section and click the **GitHub Actions** button.

![1-2](https://support.pentest-tools.com/hs-fs/hubfs/1-2.jpg?width=670&height=363&name=1-2.jpg)

As you fill in the details, the code snippet on the right side will automatically update to reflect your configuration.   
This makes it easy to create your GitHub Action workflow without having to write any YAML code manually!

![image (1)-1](https://support.pentest-tools.com/hs-fs/hubfs/image%20(1)-1.png?width=670&height=319&name=image%20(1)-1.png)

**Configuration options:**

1. **Action name**: Give your action a descriptive name (e.g., `Security Scan`)
2. **Target**: Enter the URL you want to scan (e.g., `https://example.com`)
3. **Secret name**: Specify the name of your GitHub secret containing the API key (e.g., `PTT_API_KEY`)
4. **Output format**: Choose between:  
      - **text**: Human-readable format, ideal for logs  
      - **json**: Structured format, perfect for parsing and automation
5. **Fail condition**: Select when the action should fail your build:  
      - **None**: Never fail, always return success  
      - **Low**: Fail if any vulnerability with low risk or higher is found  
      - **Medium**: Fail if vulnerabilities with medium risk or higher are found  
      - **High**: Fail if high-risk or critical vulnerabilities are found  
      - **Critical**: Fail only if critical vulnerabilities are found
6. **Scan type**: Choose your scan depth:  
      - **Light**: Quick scan (1-15 minutes)  
      - **Deep**: Comprehensive scan (60-120 minutes)

Once you've configured all the options, the generated code on the right will be ready to use!

⚠️ **Note**: You will need to set up your GitHub Actions secret in your repository (see Step 3 below).

### **Step 2: Copy and create your workflow file**

After configuring your settings in the integration page:

1. **Copy the generated code** from the right panel
2. In your GitHub repository, create a new file at `.github/workflows/security-scan.yml`
3. **Paste the generated code** into this file
4. Optionally, add trigger conditions (see examples below for `on:` configuration)
5. Commit the file to your repository

###### **Example with trigger conditions:**

`yaml`  
`name: Security Scan`

`on:`  
  `push:`  
    `branches: [ main, develop ]`  
  `pull_request:`  
    `branches: [ main ]`

`jobs:`  
  `# Paste your generated job configuration here`  
  `test_deep_scan:`  
    `runs-on: ubuntu-latest`  
    `steps:`  
      `- name: Actual test`  
        `uses: pentesttoolscom/pentesttools-github-action@master`  
        `id: ptt`  
        with:  
          `target: https://pentest-ground.com`  
          `format: json`  
          `fail: high`  
          `type: deep`  
          `key: $`  
      `- name: Check the output`  
        `run: echo "The report $"`

Once you commit this file, the action will run automatically based on your trigger configuration!

### **Step 3: Set up your API key in GitHub Secrets**

If you're using deep scans, you'll need to add your Pentest-Tools.com API key to GitHub:

1. **Get your API key:** 
     1. Click on **Generate REST API key** button
     2. Define a profile name
     3. Set the profile expiration time
     4. Save the API key provided
2. **Add it to GitHub Secrets:** 
     1. In your GitHub repository, go to **Settings** → **Secrets and variables** → **Actions**
     2. Click **New repository secret**
     3. Name it `PTT_API_KEY` (or whatever you specified in the configuration tool)
     4. Paste your API key as the value
     5. Click **Add secret**

That's it! Your GitHub Action is now configured and ready to run.

- [Getting started](https://support.pentest-tools.com/getting-started#main-content)

    - [Tips & Tricks](https://support.pentest-tools.com/getting-started#tips-tricks)
    - [First Steps](https://support.pentest-tools.com/getting-started#first-steps)
- [Tools and Scans](https://support.pentest-tools.com/tools-and-scans#main-content)

    - [Network Infrastructure Testing](https://support.pentest-tools.com/tools-and-scans#network-infrastructure-testing)
    - [Authenticated Scanning](https://support.pentest-tools.com/tools-and-scans#authenticated-scanning)
    - [Frequently Asked Questions (FAQ)](https://support.pentest-tools.com/tools-and-scans#frequently-asked-questions-faq)
    - [Offensive Tools](https://support.pentest-tools.com/tools-and-scans#offensive-tools)
    - [Web Application Testing](https://support.pentest-tools.com/tools-and-scans#web-application-testing)
    - [Reconnaissance](https://support.pentest-tools.com/tools-and-scans#reconnaissance)
- [Account and Billing](https://support.pentest-tools.com/account-and-billing#main-content)

    - [Billing and Payment](https://support.pentest-tools.com/account-and-billing#billing-and-payment)
    - [Account Management](https://support.pentest-tools.com/account-and-billing#account-management)
- [Assets, Targets & Workspaces](https://support.pentest-tools.com/assets-targets-workspaces#main-content)

    - [Workspaces](https://support.pentest-tools.com/assets-targets-workspaces#workspaces)
    - [Assets & Targets](https://support.pentest-tools.com/assets-targets-workspaces#assets-targets)
- [Reporting and Vulnerability Management](https://support.pentest-tools.com/reporting-and-vulnerability-management#main-content)

    - [Notifications](https://support.pentest-tools.com/reporting-and-vulnerability-management#notifications)
    - [Attack Surface](https://support.pentest-tools.com/reporting-and-vulnerability-management#attack-surface)
    - [Reporting](https://support.pentest-tools.com/reporting-and-vulnerability-management#reporting)
    - [Findings](https://support.pentest-tools.com/reporting-and-vulnerability-management#findings)
- [VPN Profiles](https://support.pentest-tools.com/vpn-profiles)
- [Integrations](https://support.pentest-tools.com/integrations)
- [Automation](https://support.pentest-tools.com/automation#main-content)

    - [Scheduler](https://support.pentest-tools.com/automation#scheduler)
    - [Scan Groups](https://support.pentest-tools.com/automation#scan-groups)
    - [Pentest Robots](https://support.pentest-tools.com/automation#pentest-robots)
- [Change Log](https://support.pentest-tools.com/change-log)
- [Data Security](https://support.pentest-tools.com/data-security)

[![Chill listening crop-3](https://support.pentest-tools.com/hs-fs/hubfs/Logo%20negru.png?width=109&height=40&name=Logo%20negru.png "Chill listening crop-3")](http://Pentest-Tools.com)

[Go to Pentest-Tools.com](https://pentest-tools.com/)

<https://www.linkedin.com/company/pentesttools> <https://www.youtube.com/c/PentestToolscom> <https://www.reddit.com/r/pentest_tools_com/>

Copyright © 2026 PentestTools S.A.