diff --git a/backend/src/services/app-connection/gitlab/gitlab-connection-enums.ts b/backend/src/services/app-connection/gitlab/gitlab-connection-enums.ts
index 3bd01d147..f409a61cf 100644
--- a/backend/src/services/app-connection/gitlab/gitlab-connection-enums.ts
+++ b/backend/src/services/app-connection/gitlab/gitlab-connection-enums.ts
@@ -5,5 +5,6 @@ export enum GitLabConnectionMethod {
export enum GitLabAccessTokenType {
Project = "project",
- Personal = "personal"
+ Personal = "personal",
+ Group = "group"
}
diff --git a/docs/images/app-connections/gitlab/gitlab-group-access-token-created.png b/docs/images/app-connections/gitlab/gitlab-group-access-token-created.png
new file mode 100644
index 000000000..f5a7383f2
Binary files /dev/null and b/docs/images/app-connections/gitlab/gitlab-group-access-token-created.png differ
diff --git a/docs/images/app-connections/gitlab/gitlab-group-access-token-form-secret-sync.png b/docs/images/app-connections/gitlab/gitlab-group-access-token-form-secret-sync.png
new file mode 100644
index 000000000..04dee5a5c
Binary files /dev/null and b/docs/images/app-connections/gitlab/gitlab-group-access-token-form-secret-sync.png differ
diff --git a/docs/images/app-connections/gitlab/gitlab-group-access-token-list.png b/docs/images/app-connections/gitlab/gitlab-group-access-token-list.png
new file mode 100644
index 000000000..e29df0418
Binary files /dev/null and b/docs/images/app-connections/gitlab/gitlab-group-access-token-list.png differ
diff --git a/docs/integrations/app-connections/gitlab.mdx b/docs/integrations/app-connections/gitlab.mdx
index 4f7223d93..c9af952a7 100644
--- a/docs/integrations/app-connections/gitlab.mdx
+++ b/docs/integrations/app-connections/gitlab.mdx
@@ -187,31 +187,92 @@ Infisical supports two methods for connecting to GitLab: **OAuth** and **Access
-
- ## Setup GitLab Access Token Connection in Infisical
+
+ Group access tokens provide access to all projects within a GitLab group, offering group-level control.
-
-
- Navigate to the **App Connections** page in the desired project.
- 
-
-
- Select the **GitLab Connection** option from the connection options modal.
- 
-
-
- Select the **Access Token** method, paste your GitLab access token in the provided field, and select the appropriate token type.
+
+
+ Go to your GitLab group and navigate to Settings > Access Tokens. Click **Add new token** to create a new group access token.
+ 
+
+
+ Fill in the token details:
+ - **Token name**: A descriptive name for the token
+ - **Expiration date**: Set an appropriate expiration date
+ - **Select role and scopes**: Depending on your use case, add the required role and one or more of the following scopes:
- 
+
+
+ For Secret Syncs, the required role depends on your sync destination:
+ - **Project variables**: Requires **Maintainer** role or higher
+ - **Group variables**: Requires **Owner** role
- Click **Connect** to establish the connection.
-
-
- Your **GitLab Connection** is now available for use.
- 
-
-
+ Your token will require the `api` scope.
+
+ 
+
+ Click **Create group access token** to create the token.
+
+
+ Use the **Owner** role if you need to sync to group-level variables. The **Maintainer** role is sufficient only for project-level variables.
+
+
+
+ To set up Secret Scanning, the required permissions depend on the data source level:
+ - **Project-level data source:** Requires **Maintainer** role or higher
+ - **Group-level data source:** Requires **Owner** role
+
+ Your token will require the `api` scope.
+
+ 
+
+ Click **Create group access token** to create the token.
+
+
+
+
+ Group Access Token connections require manual token rotation when your GitLab access token expires or is regenerated. Monitor your connection status and update the token as needed.
+
+
+
+ Copy the generated token immediately as it won't be shown again.
+ 
+
+ Keep your access token secure and do not share it. Anyone with access to this token can access all projects within your GitLab group.
+
+
+
+
+
+
+
+
+## Setup GitLab Access Token Connection in Infisical
+
+
+
+ Navigate to the **App Connections** page in the desired project.
+ 
+
+
+ Select the **GitLab Connection** option from the connection options modal.
+ 
+
+
+ Select the **Access Token** method, paste your GitLab access token in the provided field, and select the appropriate token type.
+
+ 
+
+ Click **Connect** to establish the connection.
+
+
+
+
+ Your **GitLab Connection** is now available for use.
+ 
+
+
diff --git a/frontend/src/hooks/api/appConnections/gitlab/types.ts b/frontend/src/hooks/api/appConnections/gitlab/types.ts
index 0d8d9baf0..7d2699c75 100644
--- a/frontend/src/hooks/api/appConnections/gitlab/types.ts
+++ b/frontend/src/hooks/api/appConnections/gitlab/types.ts
@@ -10,5 +10,6 @@ export type TGitLabGroup = {
export enum GitLabAccessTokenType {
Personal = "personal",
- Project = "project"
+ Project = "project",
+ Group = "group"
}