VANTA_CLIENT_ID, VANTA_CLIENT_SECRET) and 1 optional secret (VANTA_API_BASE) in ConfigView when setup is complete.
Scope of this integration today. ConfigView reads Vanta’s personnel list and where each person’s security tasks stand (training, policy acceptance, device monitoring, background check, offboarding), who can sign in to Vanta, groups, the systems connected to Vanta, the vendor inventory with risk and review status, apps Vanta discovered people signing in to, compliance test status, monitored computers, and Vanta’s event log. It never reads documents, policies’ text, evidence files, audit requests or Trust Center content. ConfigView only reads. It never creates, changes or deletes anything in Vanta.
What you need
- A Vanta admin account, to open the Developer Console
- Vanta’s API is included with the Vanta platform. Some areas are only filled in if your Vanta plan includes them: vendor management and vendor discovery need Vanta’s vendor risk features, and monitored computers need the Vanta agent or an MDM integration built by Vanta. If an area is not on your plan, that collector skips itself and its table stays empty. That does not count as a failure.
Step 1: Open the Vanta page in ConfigView
Open ConfigView in a second browser tab and leave it open:https://{companyname}.configview.com/admin/integrations/vanta
Vanta shows the client secret once, when you generate it, so paste it straight into ConfigView instead of keeping it in a notes file.
Step 2: Create a Manage Vanta application
- Sign in to Vanta as an admin
- Open Settings → Developer Console (
https://app.vanta.com/settings/developer-console; EU accounts useapp.eu.vanta.com, Australian accountsapp.aus.vanta.com) - Click Create
- Set the app type to Manage Vanta. The other types (“Build Integrations” and “Auditor API”) can’t read your account’s data
- Name it
ConfigViewand add a short description, for example “Read-only inventory for ConfigView” - Save. Vanta generates the client ID. It starts with
vci_ - Click Generate client secret. Copy the secret. It starts with
vcs_ - Switch to the ConfigView tab and paste the two values into
VANTA_CLIENT_IDandVANTA_CLIENT_SECRETunder Credentials, then click the save icon for each
vanta-api.all:read and nothing else.
Give ConfigView its own application
Vanta allows one active token per application. When something requests a new token, Vanta cancels the previous one straight away. If ConfigView shares an application with another script, a Postman collection or the Vanta MCP server, each one keeps cancelling the other’s token and both fail at random. Create a separate application for ConfigView and don’t use its credentials anywhere else. ConfigView’s own collectors all start at the same time, so they share one token. They don’t cancel each other.Vanta Gov
If your company uses Vanta Gov, pastehttps://api.vanta-gov.com into VANTA_API_BASE. Everyone else leaves it empty: US, EU and Australian accounts all use https://api.vanta.com.
Step 3: Connect and verify
- Back on
https://{companyname}.configview.com/admin/integrations/vanta, confirm the credentials show as saved - Click Connect. ConfigView creates its tables and schedules every collector at your default run time. Stop any you don’t want under Collectors:
- Click Verify now. The health check reads both secrets and gets a token. It reuses the collectors’ token when one is current, so a check never interrupts a running collector. It then reads your organization’s name and one person, and tries one record from each of the other areas.
- Token fails with 401 or invalid_client. The client ID or secret is wrong, or the secret was rotated in the Developer Console. Generate a new secret and paste it again.
- Token fails with invalid_scope. The application isn’t a Manage Vanta app. Create a new one with that type.
- Token fails with 429. Vanta allows 5 token requests a minute. Wait a minute and verify again.
- An area shows as skipped. Vanta answered “forbidden” or “not found” for it, which usually means your plan doesn’t include it. Nothing to fix.
- Collectors fail with 401 now and then. The application’s credentials are being used somewhere else as well. See Give ConfigView its own application.
Data Tables
Once the scripts run, these tables are created in your database. Each table has arun_at column and a raw_json column, which holds the record as Vanta returned it, minus anything listed under What isn’t collected. The snapshot tables keep only the newest run. vanta_event_logs keeps every event ever collected.
Things worth knowing
Statuses are Vanta’s. “Overdue”, “due soon” and “needs attention” are Vanta’s own verdicts. ConfigView stores them as they are, so its answers match the Vanta dashboard. Group membership is on the person.vanta_people.group_ids lists the ids of a person’s groups, separated by commas. Join to vanta_groups.group_id.
Vendor owners are Vanta user ids. security_owner_user_id and business_owner_user_id match vanta_users.user_id.
Monitored computers don’t include partner integrations. Vanta only lists computers reported by the Vanta agent or by MDM integrations Vanta built itself. If you use a partner-built MDM integration, its computers won’t appear here.
The event log has ids, not names. Each event names its actor and targets by id and type only. Match actor ids against vanta_users.user_id, and Person targets against vanta_people.person_id. The first run collects the last 90 days. After that, each run picks up from the newest event already stored.
Rate limit. Vanta allows 50 API requests a minute and 5 token requests a minute. Each ConfigView collector paces itself at 20 a minute, so two can run at once and still leave room for your own use. Discovered Vendor Accounts makes one request per discovered app, so with a few hundred apps it takes several minutes.
What isn’t collected
- Vendor account manager names and emails, free-text vendor notes, and procurement ticket links
- Documents, evidence files, policy text, risk register entries, audit requests, questionnaires and Trust Center content
- The client secret and the access token never go into the database. The token is cached for up to an hour in a file only ConfigView can read, so the collectors can share it