Skip to main content
availability

Package: Invicti AppSec Core (on-demand), Invicti AppSec Enterprise (on-premise, on-demand)

4me Integration

4me is a cloud-based Enterprise Service Management (ESM) platform designed for collaborative service delivery between internal and external service providers. The Invicti AppSec integration with 4me enables security teams to create and track 4me requests or incidents from discovered vulnerabilities, and map vulnerability lifecycle states to 4me's issue statuses for automated synchronization.

Purpose in Invicti AppSec

4me is used in Invicti AppSec as an Issue Manager — a tool for creating, tracking, and syncing tickets with external service management systems.

Use CaseDescription
Ticket creation from vulnerabilitiesCreate 4me requests directly from vulnerability findings in Invicti AppSec
Status synchronizationMap Invicti AppSec vulnerability states (Open, In Progress, Closed, Unassigned, Pending) to 4me's native issue statuses
Remediation trackingTrack security issue remediation through 4me's service lifecycle

Where It Is Used

PageNavigation PathPurpose
Integrations — Issue ManagersIntegrations › Issue ManagersAdmin activation and global configuration
Project SettingsProject › Settings › Issue ManagersLink 4me to a specific project for automated ticket creation
Vulnerability ListProject › VulnerabilitiesManually create a 4me ticket for a specific vulnerability
Team Lead IntegrationsTeam Lead view › Integrations › Issue ManagersTeam leads activate instances delegated by admins

Prerequisites

Before activating the integration, gather the following credentials from your 4me account:

FieldDescriptionRequired
TokenA Personal Access Token or API token generated from your 4me accountYes
URLYour 4me instance URL (e.g., https://your-company.4me.com)Yes
InsecureEnable only if your instance uses a self-signed SSL certificateNo

Obtain Credentials (on the 4me Side)

API Token:

  1. Log in to your 4me account.
  2. Click your profile avatar in the top-right corner.
  3. Go to My ProfilePersonal Access Tokens.
  4. Click New Personal Access Token, give it a name (e.g., invicti-aspm), and select the required scopes.
  5. Copy the token — it will not be shown again after this page is closed.
  6. Ensure the token belongs to an account with access to create and manage requests.

Instance URL:

  1. Your 4me instance URL is visible in the browser address bar when logged in.
  2. Use only the base URL (e.g., https://acme.4me.com) without any path.

Activation Steps

Step 1: Navigate to Integrations

From the left sidebar, click Integrations.

Step 2: Open the Issue Managers Tab

On the Integrations page, click the Issue Managers tab.

Issue Manager tab

Step 3: Find and Activate 4me

Locate the 4me card.

  • If it is not yet activated, click Activate to open the settings drawer.
  • If it is already activated, click the gear icon to reconfigure.

Step 4: Fill In the Required Fields (Step 1 — Authentication)

The 4me integration uses a two-step setup process.

In the first step (Authentication), enter the required credentials:

FieldDescriptionRequired
TokenYour 4me Personal Access TokenYes
URLYour 4me instance base URLYes
InsecureEnable for self-signed SSL certificatesNo

Step 5: Test the Connection

Click Test Connection. A green "Connection successful" message confirms that Invicti AppSec can reach your 4me instance.

4me settings

Step 6: Configure Issue Status Mapping (Step 2)

Click Next to proceed to the Issue Status Mapping step. Map each Invicti AppSec vulnerability state to the corresponding 4me status:

Invicti AppSec StateDescription
When Opening4me status to set when a vulnerability ticket is first opened
When In Progress4me status to set when remediation is actively underway
When Closing4me status to set when the vulnerability is resolved
When Unassigned4me status for unassigned vulnerabilities
When Pending4me status for vulnerabilities pending review or action
info

The available statuses in each dropdown are loaded from your 4me instance after a successful connection.

Step 7: Save

Click Save to complete the activation.

Summary

StepAction
1Navigate to Integrations from the sidebar
2Select the Issue Managers tab
3Find 4me and click Activate (or the gear icon)
4Enter Token and URL in the Authentication step
5Click Test Connection — verify the success message
6Click Next and configure Issue Status Mapping
7Click Save

Troubleshooting

IssueResolution
Connection failedVerify that the Token and URL are correct and that the 4me instance is reachable from the Invicti AppSec network.
401 UnauthorizedThe Personal Access Token is invalid or expired. Regenerate the token in 4me and retry.
No statuses listed in Issue Status MappingThe token may lack the required permissions to read 4me statuses. Ensure the token has sufficient API access scopes.
URL invalidEnsure the URL contains the protocol (https://) and no trailing path. Use only the base URL.
SSL / certificate errorEnable the Insecure option for self-signed certificates, or add the certificate to your trust store.

Need help?

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?