Poliogo

Connect Netlify

Connect your Netlify account to confirm your live address and detect services from variable names.

How it connects
OAuth — no scope parameter
Setup time
Under 60 seconds
Access
Account-wide — see the table below

Worth knowing: Netlify doesn't offer read-only access tokens, so connecting grants your account's full access. We only ever list your sites — revoke any time in Netlify under User settings → Applications.

How the connection works

  1. Connect accountApprove the integration on the provider's own screen.
  2. Select projectYour projects and their production URLs are listed for you.
  3. Detection stays onVariable names are re-read on each scan, so a new service is noticed.

What it looks like once connected

An illustration of this connection inside your Poliogo dashboard — not live data.

Live sync activeExample
acme-web · netlify.app

Detected in this project

  • STRIPE_SECRET_KEYname only — value never read
  • POSTHOG_API_KEYname only — value never read
  • SUPABASE_URLname only — value never read
  • OPENAI_API_KEYname only — value never read
Last scan: 8 minutes ago3 documents up to date
Variable names only. Poliogo never requests a value, and no table in the database has a column to keep one in.

Exact permissions requested

Every permission this connection asks for, named as Netlify names it on its own consent screen — so you can compare this table to what you are shown.

PermissionGrantWhat it is used for
Full account accessWriteNetlify's OAuth has no scope parameter, so the token carries whatever the authorising user can do. We only ever call GET /sites — but the grant itself is broader than that, and saying otherwise would be false.
Sites: ReadReadThe only thing we actually use: list your sites and their live addresses.

Setting it up

What you do, and what you will be looking at while you do it.

  1. Connect your Netlify account

    Press Connect Netlify below and approve on Netlify's own screen.

  2. Know what the token carries

    Netlify does not offer read-only access tokens and its OAuth accepts no scope parameter, so connecting grants whatever your account can do. Poliogo only ever calls GET /sites — but the grant is broader than the use, and we would rather you heard that here than discovered it later. Revoke any time under User settings → Applications.

  3. Pick a site

    Your sites and their live addresses are listed for you. Choose the one this project covers.

  4. Check what it found and generate

    Review the detected services and generate your documents.

  5. Want the deeper scan? Add the repo

    Connecting the repository Netlify builds from adds the source sweep on top of the variable names.

Poliogo · New projectExample

Choose how to scan your app

Pick one. We scan your code and settings to find the services your app uses — the scan keeps that list, not your files.

Hosting PlatformVercel, Netlify, Railway — connect your account. Cloudflare — paste a read-only token.Choose another way
VercelNetlifyRailwayCloudflare

Connect your Netlify account and pick a site — nothing to type.

Connect your Netlify account

Full account accessWrite
Sites: ReadRead

Granted on Netlify's own screen — this panel can show it, never widen it.

Connect Netlify

Pick a deployment

acme-webacme-web.netlify.app
acme-webacme-web.netlify.appacme-web-stagingacme-web-staging.netlify.appacme-docsacme-docs.netlify.app

Environment variables detected

STRIPE_SECRET_KEYStripe
POSTHOG_API_KEYPostHog
SUPABASE_URLSupabase

Names only. No value is requested, and no table in the database has a column to keep one in.

Project synced · 8 minutes agoRead my project
Tell us what you use instead
The Poliogo setup screen for Netlify, drawn from the same catalogue the app reads. An illustration — not live data, and nothing here is clickable.

What Poliogo detects from Netlify

The right-hand column is the part worth reading: it is what this connection cannot reach even if we wanted it to.

What it reads

  • Your project or site list, so you can pick the right one instead of typing an address.
  • The production URL, which is what your policies name as the service they cover.
  • Environment variable names — enough to prove which services you use.

What it never reads

  • Environment variable values. They are never requested and never stored.
  • Your source code — a hosting connection does not grant repository access.
  • Anything beyond GET /sites. That is the only call we make, despite the token Netlify issues.

Ready to connect Netlify?

The free plan covers one project with no credit card. You approve everything before a single document is written.

Poliogo is a compliance management platform, not a law firm. What it produces is not legal advice. See exactly what each connection reads.