Connect a MuleSoft instance to SSPM to detect posture risks.
For SSPM to detect posture risks in your MuleSoft instance, you must onboard your
MuleSoft instance to SSPM. Through the onboarding process, SSPM connects to an
Anypoint Platform API and, through the API, scans your MuleSoft instance for
misconfigured settings and account risks.
SSPM gets access to your MuleSoft instance through an OAuth 2.0 application that you
create. In the Anypoint Platform, an OAuth 2.0 application is called a
Connected App. During onboarding, you supply SSPM with the
application credentials (Client ID and Client Secret) for your Connected App. SSPM
uses these credentials to access the Anypoint Platform API.
SSPM scans are supported for all MuleSoft paid plans.
To access your MuleSoft instance, SSPM requires the following information, which you
will specify during the onboarding process.
| Item | Description |
|
Hosted Region
|
MuleSoft operates multiple independent regional sites worldwide.
This infrastructure ensures that your account metadata, API
designs, and user settings reside only within the region you
specify when you create your MuleSoft account.
Because these regional environments are entirely separate from
one another, you must provide SSPM with the region where
MuleSoft hosts your data. You can determine your region from the
Mulesoft URL displayed in your browser's address bar.
|
|
Client ID
|
SSPM will access an Anypoint Platform API through a Connected App
that you create in the Anypoint Platform. The Anypoint Platform
generates the Client ID to uniquely identify this Connected App.
|
|
Client Secret
|
SSPM will access an Anypoint Platform API through a Connected App
that you create in the Anypoint Platform. The Anypoint Platform
generates the Client Secret, which SSPM uses to authenticate to
the API through the Connected App.
|
To onboard your MuleSoft instance, you complete the following actions: