Connect Netlify
Connect your Netlify account to confirm your live address and detect services from variable names.
Worth knowing: Netlify doesn't offer read-only access tokens, so connecting grants your account's full access. We only ever list your sites — revoke any time in Netlify under User settings → Applications.
How the connection works
- Connect accountApprove the integration on the provider's own screen.
- Select projectYour projects and their production URLs are listed for you.
- Detection stays onVariable names are re-read on each scan, so a new service is noticed.
What it looks like once connected
An illustration of this connection inside your Poliogo dashboard — not live data.
Detected in this project
- STRIPE_SECRET_KEYname only — value never read
- POSTHOG_API_KEYname only — value never read
- SUPABASE_URLname only — value never read
- OPENAI_API_KEYname only — value never read
Exact permissions requested
Every permission this connection asks for, named as Netlify names it on its own consent screen — so you can compare this table to what you are shown.
| Permission | Grant | What it is used for |
|---|---|---|
| Full account access | Write | Netlify's OAuth has no scope parameter, so the token carries whatever the authorising user can do. We only ever call GET /sites — but the grant itself is broader than that, and saying otherwise would be false. |
| Sites: Read | Read | The only thing we actually use: list your sites and their live addresses. |
Setting it up
What you do, and what you will be looking at while you do it.
Connect your Netlify account
Press Connect Netlify below and approve on Netlify's own screen.
Know what the token carries
Netlify does not offer read-only access tokens and its OAuth accepts no scope parameter, so connecting grants whatever your account can do. Poliogo only ever calls GET /sites — but the grant is broader than the use, and we would rather you heard that here than discovered it later. Revoke any time under User settings → Applications.
Pick a site
Your sites and their live addresses are listed for you. Choose the one this project covers.
Check what it found and generate
Review the detected services and generate your documents.
Want the deeper scan? Add the repo
Connecting the repository Netlify builds from adds the source sweep on top of the variable names.
Choose how to scan your app
Pick one. We scan your code and settings to find the services your app uses — the scan keeps that list, not your files.
Connect your Netlify account and pick a site — nothing to type.
Connect your Netlify account
Granted on Netlify's own screen — this panel can show it, never widen it.
Connect NetlifyPick a deployment
Environment variables detected
STRIPE_SECRET_KEYStripePOSTHOG_API_KEYPostHogSUPABASE_URLSupabaseNames only. No value is requested, and no table in the database has a column to keep one in.
Project synced · 8 minutes agoRead my projectWhat Poliogo detects from Netlify
The right-hand column is the part worth reading: it is what this connection cannot reach even if we wanted it to.
What it reads
- Your project or site list, so you can pick the right one instead of typing an address.
- The production URL, which is what your policies name as the service they cover.
- Environment variable names — enough to prove which services you use.
What it never reads
- Environment variable values. They are never requested and never stored.
- Your source code — a hosting connection does not grant repository access.
- Anything beyond GET /sites. That is the only call we make, despite the token Netlify issues.
Ready to connect Netlify?
The free plan covers one project with no credit card. You approve everything before a single document is written.
Poliogo is a compliance management platform, not a law firm. What it produces is not legal advice. See exactly what each connection reads.