Fix merge conflicts

This commit is contained in:
Tuan Dang
2025-05-02 13:06:18 -07:00
233 changed files with 8799 additions and 1213 deletions

View File

@@ -0,0 +1,4 @@
---
title: "Available"
openapi: "GET /api/v1/app-connections/hashicorp-vault/available"
---

View File

@@ -0,0 +1,8 @@
---
title: "Create"
openapi: "POST /api/v1/app-connections/hashicorp-vault"
---
<Note>
Check out the configuration docs for [Hashicorp Vault Connections](/integrations/app-connections/hashicorp-vault) to learn how to obtain the required credentials.
</Note>

View File

@@ -0,0 +1,4 @@
---
title: "Delete"
openapi: "DELETE /api/v1/app-connections/hashicorp-vault/{connectionId}"
---

View File

@@ -0,0 +1,4 @@
---
title: "Get by ID"
openapi: "GET /api/v1/app-connections/hashicorp-vault/{connectionId}"
---

View File

@@ -0,0 +1,4 @@
---
title: "Get by Name"
openapi: "GET /api/v1/app-connections/hashicorp-vault/connection-name/{connectionName}"
---

View File

@@ -0,0 +1,4 @@
---
title: "List"
openapi: "GET /api/v1/app-connections/hashicorp-vault"
---

View File

@@ -0,0 +1,8 @@
---
title: "Update"
openapi: "PATCH /api/v1/app-connections/hashicorp-vault/{connectionId}"
---
<Note>
Check out the configuration docs for [Hashicorp Vault Connections](/integrations/app-connections/hashicorp-vault) to learn how to obtain the required credentials.
</Note>

View File

@@ -0,0 +1,4 @@
---
title: "Create"
openapi: "POST /api/v1/secret-syncs/hashicorp-vault"
---

View File

@@ -0,0 +1,4 @@
---
title: "Delete"
openapi: "DELETE /api/v1/secret-syncs/hashicorp-vault/{syncId}"
---

View File

@@ -0,0 +1,4 @@
---
title: "Get by ID"
openapi: "GET /api/v1/secret-syncs/hashicorp-vault/{syncId}"
---

View File

@@ -0,0 +1,4 @@
---
title: "Get by Name"
openapi: "GET /api/v1/secret-syncs/hashicorp-vault/sync-name/{syncName}"
---

View File

@@ -0,0 +1,4 @@
---
title: "Import Secrets"
openapi: "POST /api/v1/secret-syncs/hashicorp-vault/{syncId}/import-secrets"
---

View File

@@ -0,0 +1,4 @@
---
title: "List"
openapi: "GET /api/v1/secret-syncs/hashicorp-vault"
---

View File

@@ -0,0 +1,4 @@
---
title: "Remove Secrets"
openapi: "POST /api/v1/secret-syncs/hashicorp-vault/{syncId}/remove-secrets"
---

View File

@@ -0,0 +1,4 @@
---
title: "Sync Secrets"
openapi: "POST /api/v1/secret-syncs/hashicorp-vault/{syncId}/sync-secrets"
---

View File

@@ -0,0 +1,4 @@
---
title: "Update"
openapi: "PATCH /api/v1/secret-syncs/hashicorp-vault/{syncId}"
---

View File

@@ -45,6 +45,10 @@ description: "Learn how to configure Auth0 OIDC for Infisical SSO."
3.2. For configuration type, select **Discovery URL**. Then, set **Discovery Document URL**, **JWT Signature Algorithm**, **Client ID**, and **Client Secret** from step 2.1 and 2.2.
![OIDC auth0 paste values into Infisical](../../../images/sso/auth0-oidc/org-update-oidc.png)
<Info>
Currently, the following JWT signature algorithms are supported: RS256, RS512, HS256, and EdDSA
</Info>
Once you've done that, press **Update** to complete the required configuration.
</Step>

View File

@@ -44,7 +44,9 @@ Prerequisites:
To configure OIDC via the custom endpoints, set the **Configuration Type** field to **Custom** and input the required endpoint fields.
![OIDC general custom config](../../../images/sso/general-oidc/custom-oidc-form.png)
2.3. Optionally, you can define a whitelist of allowed email domains.
2.3. Select the appropriate JWT signature algorithm for your IdP. Currently, the supported options are RS256, RS512, HS256, and EdDSA.
2.4. Optionally, you can define a whitelist of allowed email domains.
Finally, fill out the **Client ID** and **Client Secret** fields and press **Update** to complete the required configuration.

View File

@@ -72,6 +72,10 @@ description: "Learn how to configure Keycloak OIDC for Infisical SSO."
3.2. For configuration type, select Discovery URL. Then, set the appropriate values for **Discovery Document URL**, **JWT Signature Algorithm**, **Client ID**, and **Client Secret**.
![OIDC keycloak paste values into Infisical](/images/sso/keycloak-oidc/create-oidc.png)
<Info>
Currently, the following JWT signature algorithms are supported: RS256, RS512, HS256, and EdDSA
</Info>
Once you've done that, press **Update** to complete the required configuration.
</Step>

View File

@@ -35,6 +35,10 @@ Infisical supports these and many other identity providers:
If your required identity provider is not shown in the list above, please reach out to [team@infisical.com](mailto:team@infisical.com) for assistance.
<Info>
For enhanced security, Infisical enforces PKCE (Proof Key for Code Exchange) with the OAuth 2.0-based SSO providers and OIDC. This provides additional protection against authorization code interception attacks and strengthens your authentication flow security.
</Info>
## FAQ
<AccordionGroup>

View File

@@ -0,0 +1,192 @@
---
title: "Microsoft Teams Integration"
description: "Learn how to setup the Microsoft Teams integration"
---
import MicrosoftTeamsWorkflowIntegration from '/snippets/documentation/platform/workflow-integrations/microsoft-teams-integration.mdx';
This guide will provide step by step instructions on how to configure Microsoft Teams integration for your Infisical projects.
## Setting up Microsoft Teams integration in your projects
<Tabs>
<Tab title="Infisical Cloud">
<MicrosoftTeamsWorkflowIntegration />
</Tab>
<Tab title="Self-hosted setup">
### Configure Azure Resources
To create a Microsoft Teams bot, you must first create an Azure Bot from the Azure Marketplace, an app registration, and a Microsoft Teams app. The steps below document in detail how to create and configure these resources.
<Steps>
<Step title="Create Microsoft Teams app">
Navigate to the [Microsoft Teams Developer Portal](https://dev.teams.microsoft.com/).
Once you're on the Microsoft Teams Developer Portal, press the "Create a new app" button on the overview page. Give the bot a name and press the "Add" button.
![microsoft-dev-portal](/images/platform/workflow-integrations/microsoft-teams-integration/teams-dev-portal-create-app.png)
</Step>
<Step title="Create a Microsoft Teams bot">
After creating the Microsoft Teams app, you'll need to create a Microsoft Teams bot.
Navigate to the app's bot settings page and click "Create a new bot".
![microsoft-dev-portal-create-bot](/images/platform/workflow-integrations/microsoft-teams-integration/teams-dev-portal-bot-app-feature.png)
![microsoft-dev-portal-create-bot-2](/images/platform/workflow-integrations/microsoft-teams-integration/teams-dev-portal-create-a-new-bot.png)
After clicking the "Create a new bot" button, you'll be navigated to the Teams Developer Portal for bot management. Press the "New bot" button, and enter the name of the bot.
Please keep in mind that the name of the bot can only contain alphanumeric characters, dashes, and underscores.
![microsoft-dev-portal-create-bot-3](/images/platform/workflow-integrations/microsoft-teams-integration/teams-dev-portal-create-bot.png)
</Step>
<Step title="Add a message endpoint to the bot">
After creating the bot, you'll need to add a message endpoint to the bot. Navigate to the "Configure" tab, and input the following endpoint under "Endpoint address":
`https://<your-infisical-instance-url>/api/v1/workflow-integrations/microsoft-teams/message-endpoint`
Replace `<your-infisical-instance-url>` with the URL of your Infisical instance.
Press the "Save" button to save the changes.
![microsoft-dev-portal-create-bot-4](/images/platform/workflow-integrations/microsoft-teams-integration/teams-dev-portal-add-bot-endpoint.png)
</Step>
<Step title="Find the bot in Azure App Registrations">
When you create a bot through the Teams Developer Portal, an Azure App Registration is also created.
Open your [Azure Portal](https://portal.azure.com/) and navigate to the "App Registrations" section to find the newly created app registration.
The name of the app registration will be the same as the name of the bot you created in the previous step.
Press the app registration to open the app registration overview page.
![azure-app-registrations](/images/platform/workflow-integrations/microsoft-teams-integration/azure-app-registrations-bot.png)
</Step>
<Step title="Add API Permissions to the App Registration">
Navigate to the "API Permissions" section of the app registration, and add the following permissions:
- `AppCatalog.Read.All`
- `ChannelSettings.Read.All`
- `MultiTenantOrganization.Read.All`
- `Organization.Read.All`
- `Team.ReadBasic.All`
- `TeamsAppInstallation.Read.All`
After adding the API permissions, press the "Grant admin consent" button to grant the permissions.
![azure-app-registration-api-permissions](/images/platform/workflow-integrations/microsoft-teams-integration/azure-app-registration-api-permissions.png)
</Step>
<Step title="Add a new web application to the App Registration">
Navigate to the "Authentication" section of the App Registration, and press the "Add a platform" button. Select the "Web" platform and enter the following redirect URI:
`https://<your-infisical-instance-url>/organization/settings/oauth/callback`. Replace `<your-infisical-instance-url>` with the URL of your Infisical instance.
![azure-app-registration-register-callback](/images/platform/workflow-integrations/microsoft-teams-integration/azure-app-registration-register-callback.png)
</Step>
<Step title="Get App Registration Client ID and Client Secret">
Next we need to get the application client ID and create a new client secret. **Save these values for later, as they're required to configure the Microsoft Teams integration in Infisical.**
**Get the Application (Client) ID**
To get the Application (Client) ID, press the "Copy" button next to the "Application (client) ID" field.
![copy-client-id](/images/platform/workflow-integrations/microsoft-teams-integration/azure-app-registration-copy-client-id.png)
**Create a new client secret**
Create a new client secret within the app registration. Navigate to the "Certificates & Secrets" section of the app registration, and press the "New client secret" button.
![create-client-secret](/images/platform/workflow-integrations/microsoft-teams-integration/azure-app-registration-create-client-secret.png)
<Warning>
Remember to rotate your client secret before it expires. Consider setting up a reminder or automated process to replace the secret and update your Infisical configuration before expiration.
</Warning>
</Step>
<Step title="Get the Microsoft Teams App ID">
Navigate back to the [Microsoft Teams Developer Portal](https://dev.teams.microsoft.com/), and press the "Apps" tab and select the app you created earlier.
Here you can find the Microsoft Teams App ID in the overview page, which you need to copy and save for later.
![microsoft-teams-app-id](/images/platform/workflow-integrations/microsoft-teams-integration/teams-dev-portal-copy-app-id.png)
</Step>
<Step title="Link the Microsoft Teams App to the bot">
You need to link the Microsoft Teams App with the bot/app registration you created earlier.
Inside the [Microsoft Teams Developer Portal](https://dev.teams.microsoft.com/), navigate to the "Bot" tab and select the bot you created earlier. Navigate to the "App Features" section, and press the "Bot" button.
Under the "What can your bot do?" section, enable `Only send notifications (one-way conversations)`.
Under the "Select the scopes where people can use your bot" section, select `Personal`, `Team`, and `Group Chat`.
Finally, press the "Save" button to save the changes.
![microsoft-teams-app-features](/images/platform/workflow-integrations/microsoft-teams-integration/teams-dev-portal-bot-app-feature.png)
![microsoft-teams-configure-bot](/images/platform/workflow-integrations/microsoft-teams-integration/teams-dev-portal-configure-bot.png)
</Step>
<Step title="Run an app validation test (Recommended)">
To ensure that the Microsoft Teams App is working correctly, you can run an app validation test. This step is optional, but recommended to ensure the app is working correctly.
You should expect to see two errors related to sending welcome messages, because we haven't configured the Microsoft Teams App inside Infisical yet, which is required for proactive messages.
![microsoft-teams-app-validation-test](/images/platform/workflow-integrations/microsoft-teams-integration/teams-dev-portal-app-validation.png)
<Note>
You may see manifest validation errors. Before running an app validation test, you must ensure that your app has all errors resolved, such as having a description and a valid name.
</Note>
![microsoft-teams-app-validation-test-results](/images/platform/workflow-integrations/microsoft-teams-integration/teams-dev-portal-app-validation-result.png)
<Note>
If you see two errors for bot welcome messages, you can ignore them. This is expected until you configure the Microsoft Teams App inside Infisical.
</Note>
</Step>
<Step title="Download the App Package">
Once the Microsoft Teams App is working correctly, you can download the app package by navigating to the "Publish to Store" page, and pressing the "Download app package" button.
![microsoft-teams-download-app-package](/images/platform/workflow-integrations/microsoft-teams-integration/teams-dev-portal-download-app-package.png)
</Step>
</Steps>
### Configure Microsoft Teams Bot in Infisical
After creating the Microsoft Teams App and Bot, you are ready to configure the Microsoft Teams integration in Infisical.
Please note that you must be an instance admin in order to configure the Microsoft Teams instance-wide settings.
<Steps>
<Step title="Navigate to the Integrations tab in your Server Admin Console settings">
![server-admin-console-tab](/images/platform/workflow-integrations/microsoft-teams-integration/infisical-server-admin-console-tab.png)
![infisical-instance-configure-microsoft-teams](/images/platform/workflow-integrations/microsoft-teams-integration/infisical-instance-configure-microsoft-teams.png)
Enter the values you saved from the earlier steps into the respective fields.
- **Application (Client) ID**: The Client ID of the App Registration from the previous steps.
- **Client Secret**: The Client Secret of the App Registration from the previous steps.
- **Microsoft Teams App ID**: The App ID of the Microsoft Teams App from the previous steps.
Once completed, press the "Save" button to save your changes.
</Step>
</Steps>
<MicrosoftTeamsWorkflowIntegration />
</Tab>
</Tabs>
## Troubleshooting
<Accordion title="Notifications are not being sent to Microsoft Teams even though the integration is configured">
If you recently added the Microsoft Teams app to your tenant, **it may take up to 24 hours for Microsoft Teams to propagate the changes.**
A common indication of propagation issues is that the workflow integration is shown as "Installed", and you're able to view the teams and channels when configuring the workflow integration on your project, but no notification is being sent.
</Accordion>
<Accordion title="Workflow Integration is stuck on 'Pending' status">
The workflow integration can get stuck on Pending if you created the workflow integration before the Infisical Microsoft Teams bot was installed in the tenant.
To resolve this, make sure you have installed the Infisical Microsoft Teams app in your tenant.
You can manually recheck the installation status by pressing the "Check Installation Status" button in the workflow organization settings.
![microsoft-teams-check-installation-status](/images/platform/workflow-integrations/microsoft-teams-integration/microsoft-teams-check-installation-status.png)
</Accordion>

View File

@@ -1,6 +1,6 @@
---
title: "Slack integration"
description: "Learn how to setup Slack integration"
title: "Slack Integration"
description: "Learn how to setup the Slack integration"
---
This guide will provide step by step instructions on how to configure Slack integration for your Infisical projects.

Binary file not shown.

After

Width:  |  Height:  |  Size: 400 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 312 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 237 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 495 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 275 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 230 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 643 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 726 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 399 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 209 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 407 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 380 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 361 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 407 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 140 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 608 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 736 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.1 MiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.1 MiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.1 MiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 141 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 770 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 868 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 140 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 641 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 753 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 545 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 599 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 230 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 259 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 125 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 299 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 292 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 156 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 787 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 139 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 194 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 206 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 83 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 206 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 152 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 192 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 154 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 207 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 137 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 421 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 74 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 230 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 687 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 655 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 634 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 656 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 662 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 626 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 535 KiB

After

Width:  |  Height:  |  Size: 673 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 475 KiB

After

Width:  |  Height:  |  Size: 581 KiB

View File

@@ -0,0 +1,214 @@
---
title: "Hashicorp Vault Connection"
description: "Learn how to configure a Hashicorp Vault Connection for Infisical."
---
<Note>
Infisical is compatible with Vault Self-hosted, HCP Vault Dedicated, and HCP Vault Enterprise deployments. Please note that HCP Generic Secrets are currently not supported.
</Note>
Infisical supports two methods for connecting to Hashicorp Vault.
<Tabs>
<Tab title="App Role (Recommended)">
<Steps>
<Step title="Navigate to Vault Access">
![Vault Access](/images/app-connections/hashicorp-vault/vault-access.png)
</Step>
<Step title="Enable New Method">
In the **Authentication Methods** tab, click on **Enable new method**.
![Vault Enable Method](/images/app-connections/hashicorp-vault/vault-authentication-methods.png)
</Step>
<Step title="Select AppRole">
![Vault AppRole](/images/app-connections/hashicorp-vault/vault-approle.png)
</Step>
<Step title="Enable Method">
You may change the name of the method, but we suggest keeping it as `approle`.
![Vault Enable Method](/images/app-connections/hashicorp-vault/vault-enable-method.png)
</Step>
<Step title="Navigate to Vault Policies">
From the home page, navigate to **Policies**.
![Vault Policies Navigate](/images/app-connections/hashicorp-vault/vault-policies-navigate.png)
</Step>
<Step title="Create ACL Policy">
![Vault Policies Page](/images/app-connections/hashicorp-vault/vault-policies-page.png)
</Step>
<Step title="Create Policy">
You may name your policy whatever you want, but remember the name as it will be used in future steps.
Depending on your use case, you may have different policy configurations:
<Tabs>
<Tab title="Secret Sync">
```hcl
path "demo_mount/data/*" {
capabilities = [ "create", "read", "update" ]
}
path "sys/mounts" {
capabilities = ["read"]
}
```
- **demo_mount**: The name of the target secrets engine (e.g., 'secret', 'kv').
- **data/\***: The path within the secrets engine used for storing secrets. The wildcard (*) grants access to all secrets within this mount point.
<Note>
Make sure to replace the policy path with the specific path where you intend to sync your secrets. For better security and control, it's recommended to use a more granular path instead of a wildcard (*). You can also specify a path that doesn’t yet exist—Infisical will automatically create it for you during the sync process.
</Note>
</Tab>
</Tabs>
![Vault Create Policy](/images/app-connections/hashicorp-vault/vault-create-policy.png)
</Step>
<Step title="Run Shell Commands">
**Open Vault Shell**
![Vault Shell](/images/app-connections/hashicorp-vault/vault-shell.png)
<Note>
If you used custom approle or policy names in previous steps, you'll need to customize the following commands.
</Note>
**Create Infisical Role**
```hcl
vault write auth/approle/role/infisical token_policies="infisical-policy" token_ttl=30s token_max_ttl=2m
```
**Read RoleID**
```hcl
vault read auth/approle/role/infisical/role-id
```
**Generate New SecretID**
```hcl
vault write -force auth/approle/role/infisical/secret-id
```
Your shell output should look similar to the image below. Save the RoleID and SecretID values for later steps.
![Vault Shell Output](/images/app-connections/hashicorp-vault/vault-shell-output.png)
</Step>
</Steps>
</Tab>
<Tab title="Access Token">
## Get a Hashicorp Vault Access Token
Open your profile dropdown and click **Copy token**. This token will be used in later steps.
![Vault Profile Copy Token](/images/app-connections/hashicorp-vault/vault-profile-token.png)
</Tab>
</Tabs>
## Getting Vault Instance URL
<Tabs>
<Tab title="Self Hosted">
For self-hosted instances, locate and copy your vault's base URL (for example: `https://vault.example.com`).
Save the URL for later steps.
</Tab>
<Tab title="Hashicorp Cloud Platform">
On HCP instances, you may need to navigate to **Cluster Overview** to see your cluster URL. Save this value for later steps.
![Vault Cluster URLs](/images/app-connections/hashicorp-vault/vault-cluster-urls.png)
<Note>
Cluster Overview is found in the HCP dashboard, not in your cluster's web UI.
</Note>
</Tab>
</Tabs>
## Setup Vault Connection in Infisical
<Tabs>
<Tab title="Infisical UI">
<Steps>
<Step title="Navigate to App Connections">
In your Infisical dashboard, go to **Organization Settings** and select the **App Connections** tab.
![App Connections Tab](/images/app-connections/general/add-connection.png)
</Step>
<Step title="Add Connection">
Click the **+ Add Connection** button and select the **Hashicorp Vault Connection** option.
![Select Vault Connection](/images/app-connections/hashicorp-vault/vault-infisical-connect-page.png)
</Step>
<Step title="Configure Connection">
Configure your Vault Connection using the Instance URL and credentials from the steps above. **Depending on if you chose to authenticate with an Access Token or AppRole, you may need to input different information.**
![Vault Configure Connection](/images/app-connections/hashicorp-vault/vault-infisical-connect-modal.png)
<Tabs>
<Tab title="App Role">
- **Name**: The name of the connection being created. Must be slug-friendly.
- **Description**: An optional description to provide details about this connection.
- **Instance URL**: The URL of your Hashicorp Vault instance.
- **Namespace (optional)**: The namespace within your vault. Self-hosted and enterprise clusters may not use namespaces.
- **Role ID**: The Role ID generated in the steps above.
- **Secret ID**: The Secret ID generated in the steps above.
</Tab>
<Tab title="Access Token">
- **Name**: The name of the connection being created. Must be slug-friendly.
- **Description**: An optional description to provide details about this connection.
- **Instance URL**: The URL of your Hashicorp Vault instance.
- **Namespace (optional)**: The namespace within your vault. Self-hosted and enterprise clusters may not use namespaces.
- **Access Token**: The Access Token generated in the steps above.
</Tab>
</Tabs>
</Step>
<Step title="Connection Created">
Your Vault Connection is now available for use.
![Vault Connection Created](/images/app-connections/hashicorp-vault/vault-infisical-connect-success.png)
</Step>
</Steps>
</Tab>
<Tab title="API">
To create a Vault Connection, make an API request to the [Create Hashicorp Vault
Connection](/api-reference/endpoints/app-connections/hashicorp-vault/create) API endpoint.
### Sample request
```bash Request
curl --request POST \
--url https://app.infisical.com/api/v1/app-connections/hashicorp-vault \
--header 'Content-Type: application/json' \
--data '{
"name": "my-vault-connection",
"method": "app-role",
"credentials": {
"instanceUrl": "https://vault.example.com",
"roleId": "4797c4fa-7794-71f0-c8b1-7c87759df5bf",
"secretId": "ad24df93-19c8-c865-9997-6b8513253d3a"
}
}'
```
### Sample response
```bash Response
{
"appConnection": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "my-vault-connection",
"version": 1,
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2025-04-01T05:31:56Z",
"updatedAt": "2025-04-01T05:31:56Z",
"app": "hashicorp-vault",
"method": "app-role",
"credentials": {
"instanceUrl": "https://vault.example.com",
"roleId": "4797c4fa-7794-71f0-c8b1-7c87759df5bf"
}
}
}
```
</Tab>
</Tabs>

View File

@@ -4,158 +4,5 @@ description: "How to sync secrets from Infisical to HashiCorp Vault"
---
<Note>
Infisical connects to Vault via the AppRole auth method.
Currently, each Infisical project can only point and sync secrets to one Vault cluster / namespace
but with unlimited integrations to different paths within it.
This tutorial makes use of Vault's UI but, in principle, instructions can executed via
Vault CLI or API call.
Lastly, you should note that we provide a simple use-case and, in practice, you should adapt and extend it to your own Vault use-case and follow best practices, for instance when defining fine-grained ACL policies.
The Hashicorp Vault Native Integration will be deprecated in 2026. Please migrate to our new [Hashicorp Vault Sync](../secret-syncs/hashicorp-vault).
</Note>
Prerequisites:
- Set up and add envars to [Infisical Cloud](https://app.infisical.com)
- Have experience with [HashiCorp Vault](https://www.vaultproject.io/).
## Navigate to your project's integrations tab
![integrations](../../images/integrations.png)
## Prepare Vault
This section mirrors the latter parts of the [Vault quickstart](https://developer.hashicorp.com/vault/tutorials/cloud/getting-started-intro) provided by HashiCorp and uses sample names/values for demonstration.
To begin, navigate to the cluster / namespace that you want to sync secrets to in Vault; we'll use the default `admin` namespace (in practice, we recommend creating a namespace and not using the default `admin` namespace).
### Enable KV Secrets Engine
In Secrets, enable a KV Secrets Engine at a path for Infisical to sync secrets to; we'll use the path `kv`.
![integrations hashicorp vault secrets engine](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-engine-1.png)
![integrations hashicorp vault secrets engine](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-engine-2.png)
![integrations hashicorp vault secrets engine](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-engine-3.png)
### Enable the AppRole auth method
In Access > Auth Methods, enable the AppRole auth method.
![integrations hashicorp vault access](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-access-1.png)
![integrations hashicorp vault access](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-access-2.png)
![integrations hashicorp vault access](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-access-3.png)
### Create an ACL Policy
Now in Policies, create a new ACL policy scoped to the path(s) you wish Infisical to be able to sync secrets to.
We'll call the policy `test` and have it grant access to the `dev` path in the KV Secrets Engine where we will be syncing secrets to from Infisical.
```console
path "kv/data/dev" {
capabilities = [ "create", "read", "update" ]
}
path "sys/namespaces/*" {
capabilities = [ "create", "read", "update", "delete", "list" ]
}
```
<Note>
`kv` comes from the path of the KV Secrets Engine that we enabled and `dev` is the chosen path within it
that we want to sync secrets to.
</Note>
![integrations hashicorp vault policy](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-policy-1.png)
![integrations hashicorp vault policy](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-policy-2.png)
![integrations hashicorp vault policy](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-policy-3.png)
### Create a role with the policy attached
We now create a `infisical` role with the generated token's time-to-live (TTL) set to 1 hour and can be renewed for up to 4 hours from the time of its creation.
1. Click the Vault CLI shell icon (`>_`) to open a command shell in the browser.
![integrations hashicorp vault shell](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-shell.png)
2. Copy the command below.
```console
vault write auth/approle/role/infisical token_policies="test" token_ttl=1h token_max_ttl=4h
```
3. Paste the command into the command shell in the browser and press the enter button.
### Generate a RoleID and SecretID
Finally, we need to generate a **RoleID** and **SecretID** (like a username and password) that Infisical can use
to authenticate with Vault.
1. Click the Vault CLI shell icon (>_) again to open a command shell.
2. Read the RoleID.
```console
vault read auth/approle/role/infisical/role-id
```
Example output:
```console
Key Value
role_id b6ccdcca-183b-ce9c-6b98-b556b9a0edb9
```
3. Generate a new SecretID of the `infisical` role.
```console
vault write -force auth/approle/role/infisical/secret-id
```
Example output:
```console
Key Value
secret_id 735a47cc-7a98-77cc-0128-12b1e96a4157
secret_id_accessor 3ab305d1-1eab-df4b-4079-ef7135635c49
...snip...
```
Great. We're now ready to connect Infisical to Vault!
## Enter your Vault instance and authentication details
Back in Infisical, press on the HashiCorp Vault tile and input your Vault instance and `infisical` role RoleID and SecretID.
![integrations hashicorp vault authorization](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-auth.png)
For additional details on each field:
- Vault Cluster URL: The address of your cluster, either HCP or self-hosted.
If using HCP, you can copy your Cluster URL in the Cluster Overview:
![integrations hashicorp vault cluster URL](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-cluster-url.png)
- Vault Namespace: The Vault namespace you wish to connect to.
- Vault RoleID: The RoleID previously created for the `infisical` role.
- Vault SecretID: The SecretID previously created for the `infisical` role.
## Start integration
Select which Infisical environment secrets you want to sync to Vault.
For additional details on each field:
- Vault KV Secrets Engine Path: the path at which you enabled the intended KV Secrets Engine; in this demonstration, we used `kv`.
- Vault Secret(s) Path: the path in the KV Secrets Engine that you wish to sync secrets to.
Press create integration to start syncing secrets to Vault.
![integrations hashicorp vault](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault-create.png)
![integrations hashicorp vault](../../images/integrations/hashicorp-vault/integrations-hashicorp-vault.png)

View File

@@ -0,0 +1,160 @@
---
title: "Hashicorp Vault Sync"
description: "Learn how to configure a Hashicorp Vault Sync for Infisical."
---
**Prerequisites:**
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
- Create a [Hashicorp Vault Connection](/integrations/app-connections/hashicorp-vault)
<Tabs>
<Tab title="Infisical UI">
<Steps>
<Step title="Add Sync">
Navigate to **Project** > **Integrations** and select the **Secret Syncs** tab. Click on the **Add Sync** button.
![Secret Syncs Tab](/images/secret-syncs/general/secret-sync-tab.png)
</Step>
<Step title="Select Hashicorp Vault">
![Select Hashicorp Vault](/images/secret-syncs/hashicorp-vault/select-option.png)
</Step>
<Step title="Configure Source">
Configure the **Source** from where secrets should be retrieved, then click **Next**.
![Configure Source](/images/secret-syncs/hashicorp-vault/sync-source.png)
- **Environment**: The project environment to retrieve secrets from.
- **Secret Path**: The folder path to retrieve secrets from.
<Tip>
If you need to sync secrets from multiple folder locations, check out [secret imports](/documentation/platform/secret-reference#secret-imports).
</Tip>
</Step>
<Step title="Configure Destination">
Configure the **Destination** to where secrets should be deployed.
![Configure Destination](/images/secret-syncs/hashicorp-vault/sync-destination.png)
- **Hashicorp Vault Connection**: The Vault Connection to authenticate with.
- **Secrets Engine Mount**: The secrets engine to sync secrets with (e.g., 'secret', 'kv').
- **Path**: The specific path within the secrets engine where secrets will be stored.
After configuring these parameters, click the **Next** button to continue to the Sync Options step.
<Note>
If the **path** you provide does not exist in Vault, it will be created.
</Note>
</Step>
<Step title="Configure Sync Options">
Configure the **Sync Options** to specify how secrets should be synced, then click **Next**.
![Configure Options](/images/secret-syncs/hashicorp-vault/sync-options.png)
- **Initial Sync Behavior**: Determines how Infisical should resolve the initial sync.
- **Overwrite Destination Secrets**: Removes any secrets at the destination endpoint not present in Infisical.
- **Import Secrets (Prioritize Infisical)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Infisical over Hashicorp Vault when keys conflict.
- **Import Secrets (Prioritize Hashicorp Vault)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Hashicorp Vault over Infisical when keys conflict.
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
</Step>
<Step title="Configure Details">
Configure the **Details** of your Hashicorp Vault Sync, then click **Next**.
![Configure Details](/images/secret-syncs/hashicorp-vault/sync-details.png)
- **Name**: The name of your sync. Must be slug-friendly.
- **Description**: An optional description for your sync.
</Step>
<Step title="Review Configuration">
Review your Hashicorp Vault Sync configuration, then click **Create Sync**.
![Confirm Configuration](/images/secret-syncs/hashicorp-vault/sync-review.png)
</Step>
<Step title="Sync Created">
If enabled, your Hashicorp Vault Sync will begin syncing your secrets to the destination endpoint.
![Sync Created](/images/secret-syncs/hashicorp-vault/sync-created.png)
</Step>
</Steps>
</Tab>
<Tab title="API">
To create an **Hashicorp Vault Sync**, make an API request to the [Create Hashicorp Vault Sync](/api-reference/endpoints/secret-syncs/hashicorp-vault/create) API endpoint.
### Sample request
```bash Request
curl --request POST \
--url https://app.infisical.com/api/v1/secret-syncs/hashicorp-vault \
--header 'Content-Type: application/json' \
--data '{
"name": "my-vault-sync",
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"description": "an example sync",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment": "dev",
"secretPath": "/",
"isEnabled": true,
"syncOptions": {
"initialSyncBehavior": "overwrite-destination"
},
"destinationConfig": {
"mount": "secret",
"path": "dev/nested"
}
}'
```
### Sample response
```bash Response
{
"secretSync": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "my-vault-sync",
"description": "an example sync",
"isEnabled": true,
"version": 1,
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"syncStatus": "succeeded",
"lastSyncJobId": "123",
"lastSyncMessage": null,
"lastSyncedAt": "2023-11-07T05:31:56Z",
"importStatus": null,
"lastImportJobId": null,
"lastImportMessage": null,
"lastImportedAt": null,
"removeStatus": null,
"lastRemoveJobId": null,
"lastRemoveMessage": null,
"lastRemovedAt": null,
"syncOptions": {
"initialSyncBehavior": "overwrite-destination"
},
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"connection": {
"app": "hashicorp-vault",
"name": "my-vault-connection",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"environment": {
"slug": "dev",
"name": "Development",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"folder": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"path": "/"
},
"destination": "hashicorp-vault",
"destinationConfig": {
"mount": "secret",
"path": "dev/nested"
}
}
}
```
</Tab>
</Tabs>

View File

@@ -0,0 +1,60 @@
---
title: "Bug bounty program"
description: " Learn about our bug bounty program and how to report vulnerabilities."
---
The Infisical Bug Bounty Program is our way of recognizing and rewarding the work of security researchers who help keep our platform secure. By reporting vulnerabilities or potential risks, you help us protect secrets, infrastructure, and the organizations who rely on us.
We value reports that help identify vulnerabilities that affect the integrity of secrets, prevent unauthorized access to environments, or expose flaws in our authentication or authorization flows.
### How to Report
- Send reports to **security@infisical.com** with clear steps to reproduce, impact, and (if possible) a proof-of-concept.
- We will acknowledge receipt within 3 business days.
- We'll provide an initial assessment or next steps within 5 business days.
### What's in Scope?
- Vulnerabilities in our cloud-hosted platform (e.g., `app.infisical.com`, `eu.infisical.com`)
- Security issues in the open source Infisical codebase, as maintained in our official GitHub repository
- Authentication bypass, privilege escalation, or access to secrets/data without authorization
### Reward Guidelines
Bounties are based on severity, impact, and exploitability, as well as whether the report introduces a new vulnerability class or helps improve an existing fix.
| Severity | Examples | Typical Reward (USD currency) |
| --- | --- | --- |
| **Critical** | Full unauthorized access to secrets, authentication bypass, cross-tenant access, RCE, full compromise, etc | $2,000 - $5,000 |
| **High** | Privilege escalation, project-level access without authorization, persistent DoS | $750 - $2,000 |
| **Medium** | Info disclosure, scoped DoS (e.g. ReDoS with auth), or minor access control issues | $250 - $1,000 |
| **Low / Informational** | Missing headers, CSP warnings, theoretical flaws, self-hosting misconfigurations | Recognition only |
We may award lower amounts for:
- Duplicate class vulnerabilities already under review
- Patch bypasses of previously rewarded issues
- Vulnerabilities requiring unrealistic attacker conditions
All final reward amounts are determined at Infisical's discretion based on impact, report quality, and how actionable the issue is.
### Out of Scope
- Social engineering or phishing
- Rate limiting issues on non-sensitive endpoints
- Denial-of-service attacks that require authentication and don't impact core service availability
- Findings based on outdated or forked code not maintained by the Infisical team
- Vulnerabilities in third-party dependencies unless they result in a direct risk to Infisical users
### Responsible Disclosure
We ask that researchers:
- Avoid accessing data that isn't yours
- Do not publicly disclose without coordination
- Use testing accounts where possible
- Give us a reasonable window to investigate and patch before going public
Researchers can also spin up our [self-hosted version of Infisical](/self-hosting/overview) to test for vulnerabilities locally.

View File

@@ -118,8 +118,6 @@ It should be noted that, even on Infisical Cloud, it is physically impossible fo
Please email security@infisical.com if you have any specific inquiries about employee data and security policies.
## Get in touch
If you have any concerns about Infisical or believe you have uncovered a vulnerability, please get in touch via the e-mail address security@infisical.com. In the message, try to provide a description of the issue and ideally a way of reproducing it. The security team will get back to you as soon as possible.
Note that this security address should be used for undisclosed vulnerabilities. Please report any security problems to us before disclosing it publicly.
## Bug Bounty Program
We run a [Bug Bounty Program](/internals/bug-bounty) to recognize and reward security researchers who help make Infisical more secure.
If you've found a vulnerability, please review the program details for scope, disclosure guidelines, and reward tiers.

View File

@@ -228,7 +228,8 @@
{
"group": "Workflow Integrations",
"pages": [
"documentation/platform/workflow-integrations/slack-integration"
"documentation/platform/workflow-integrations/slack-integration",
"documentation/platform/workflow-integrations/microsoft-teams-integration"
]
},
{
@@ -443,6 +444,7 @@
"integrations/app-connections/databricks",
"integrations/app-connections/gcp",
"integrations/app-connections/github",
"integrations/app-connections/hashicorp-vault",
"integrations/app-connections/humanitec",
"integrations/app-connections/ldap",
"integrations/app-connections/mssql",
@@ -470,6 +472,7 @@
"integrations/secret-syncs/databricks",
"integrations/secret-syncs/gcp-secret-manager",
"integrations/secret-syncs/github",
"integrations/secret-syncs/hashicorp-vault",
"integrations/secret-syncs/humanitec",
"integrations/secret-syncs/teamcity",
"integrations/secret-syncs/terraform-cloud",
@@ -1073,6 +1076,18 @@
"api-reference/endpoints/app-connections/github/delete"
]
},
{
"group": "Hashicorp Vault",
"pages": [
"api-reference/endpoints/app-connections/hashicorp-vault/list",
"api-reference/endpoints/app-connections/hashicorp-vault/available",
"api-reference/endpoints/app-connections/hashicorp-vault/get-by-id",
"api-reference/endpoints/app-connections/hashicorp-vault/get-by-name",
"api-reference/endpoints/app-connections/hashicorp-vault/create",
"api-reference/endpoints/app-connections/hashicorp-vault/update",
"api-reference/endpoints/app-connections/hashicorp-vault/delete"
]
},
{
"group": "Humanitec",
"pages": [
@@ -1285,6 +1300,20 @@
"api-reference/endpoints/secret-syncs/github/remove-secrets"
]
},
{
"group": "Hashicorp Vault",
"pages": [
"api-reference/endpoints/secret-syncs/hashicorp-vault/list",
"api-reference/endpoints/secret-syncs/hashicorp-vault/get-by-id",
"api-reference/endpoints/secret-syncs/hashicorp-vault/get-by-name",
"api-reference/endpoints/secret-syncs/hashicorp-vault/create",
"api-reference/endpoints/secret-syncs/hashicorp-vault/update",
"api-reference/endpoints/secret-syncs/hashicorp-vault/delete",
"api-reference/endpoints/secret-syncs/hashicorp-vault/sync-secrets",
"api-reference/endpoints/secret-syncs/hashicorp-vault/import-secrets",
"api-reference/endpoints/secret-syncs/hashicorp-vault/remove-secrets"
]
},
{
"group": "Humanitec",
"pages": [
@@ -1554,6 +1583,7 @@
},
"internals/components",
"internals/security",
"internals/bug-bounty",
"internals/service-tokens"
]
},

View File

@@ -0,0 +1,100 @@
### Create Microsoft Teams workflow integration
<Steps>
<Step title="Install the Infisical Microsoft Teams App in Microsoft Teams tenant">
Currently, Infisical requires you to install a custom Microsoft Teams app into your Microsoft Teams tenant.
You can download the Infisical Microsoft Teams app package here:
- [Infisical Microsoft Teams app package](https://infisical-microsoft-teams-app.s3.us-east-1.amazonaws.com/Infisical.zip)
<Note>
**Important for self-hosted users:**
If you're self-hosting Infisical, you can skip the download step. Instead you should use the app package file you downloaded from the Microsoft Teams Developer Portal when you followed the Self-hosted guide.
</Note>
Once you've downloaded the app package, you can install the app in your Microsoft Teams tenant by navigating to the **Apps** > **Upload a custom app** page, and selecting the "Upload an app" button.
![microsoft-teams-install-app](/images/platform/workflow-integrations/microsoft-teams-integration/microsoft-teams-install-app.png)
![microsoft-teams-submit-app](/images/platform/workflow-integrations/microsoft-teams-integration/microsoft-teams-submit-app.png)
Once the app has been submitted, your Microsoft Teams tenant admin will need to approve the app in the [Microsoft Teams Admin Center](https://admin.teams.microsoft.com/policies/manage-apps).
<Warning>
After the app has been approved, it can take a few hours _(up to 24 hours in some cases)_ for Microsoft Teams to reflect the new app. During this period, the Infisical app will not be visible in Microsoft Teams, and won't be usable.
</Warning>
Once the app has been approved, you will be able to use the Infisical Microsoft Teams integration in your projects.
</Step>
<Step title="Add the Infisical Microsoft Teams app to your Microsoft Teams teams">
Once the app has been approved and installed in your Microsoft Teams tenant, you can add the app to your Microsoft Teams teams.
![microsoft-teams-add-app](/images/platform/workflow-integrations/microsoft-teams-integration/microsoft-teams-add-app.png)
Navigate to **Apps** > **Built for your org**, select the "Infisical" app, and press the "Add" button to select the teams and channels you wish to add the app to.
<Info>
This can also be done later through the [Microsoft Teams Admin Center](https://admin.teams.microsoft.com/policies/manage-apps), or through the Microsoft Teams client itself by navigating to the individual team's app settings.
</Info>
Once the app has been added to the team, you will be able to use the Infisical Microsoft Teams integration in the team.
</Step>
<Step title="Navigate to the Workflow Integrations tab in your organization settings">
After installing the Microsoft Teams app, you are now ready to configure the Microsoft Teams integration within Infisical.
Navigate to the **Workflow Integrations** tab in your organization settings, and press the "Add" button.
![org-integrations-overview](/images/platform/workflow-integrations/microsoft-teams-integration/infisical-org-overview.png)
</Step>
<Step title="Create a Microsoft Teams workflow integration">
In order to use the Infisical Microsoft Teams integration, you will need to grant admin consent to the app. Once the consent is granted, the Microsoft Teams workflow integration will be created in your Infisical organization.
Press the "Add" button and select the "Microsoft Teams" platform option.
![add-microsoft-teams-integration](/images/platform/workflow-integrations/microsoft-teams-integration/infisical-org-add-microsoft-teams-integration.png)
Select the Microsoft Teams integration you wish to configure, and press the "Configure" button.
Here you will be prompted to enter an alias, tenant ID, and an optional description for your workflow integration.
The tenant ID is the ID of the Microsoft 365 / Azure AD tenant that you installed the Infisical Microsoft Teams app in, in the previous steps.
![configure-microsoft-teams-integration](/images/platform/workflow-integrations/microsoft-teams-integration/infisical-org-microsoft-teams-integration-modal.png)
Press the "Create Microsoft Teams Integration" button, and you'll be navigated to the Azure AD consent page.
![microsoft-consent-page](/images/platform/workflow-integrations/microsoft-teams-integration/microsoft-consent-page.png)
<Note>
Please note that you must be a privileged administrator user of your Microsoft 365 / Azure AD tenant in order to grant admin consent to the app.
</Note>
Once you've granted admin consent, you'll be navigated back to the Infisical organization settings, where you can now select the Microsoft Teams integration you just created.
![microsoft-teams-workflow-integration-created](/images/platform/workflow-integrations/microsoft-teams-integration/microsoft-teams-workflow-integration-created.png)
</Step>
</Steps>
### Configure project to use Microsoft Teams workflow integration
<Steps>
<Step title="Navigate to the Workflow Integrations tab in the project settings">
To add a new Microsoft Teams workflow integration, navigate to **Project Settings** > **Workflow Integrations** and press the "Add".
![project-settings-workflow-integrations](/images/platform/workflow-integrations/microsoft-teams-integration/infisical-project-settings.png)
Select the "Microsoft Teams" option from the list of available workflow integrations.
</Step>
<Step title="Configure the Microsoft Teams workflow integration">
Your project will send notifications to the connected Microsoft Teams team of the
selected Microsoft Teams integration when the configured events are triggered.
Press the "Save" button to save your Microsoft Teams workflow integration.
![infisical-project-microsoft-teams-integration-save](/images/platform/workflow-integrations/microsoft-teams-integration/infisical-project-microsoft-teams-integration-save.png)
</Step>
</Steps>
Once you've created the project Microsoft Teams workflow integration, you will now receive Access Requests and Secret Approval Requests notifications in Microsoft Teams according to your configuration.