> ## Documentation Index
> Fetch the complete documentation index at: https://support.configview.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Vanta setup

ConfigView reads your Vanta account through the Manage Vanta API, using a **Manage Vanta application** that a Vanta admin creates in Vanta's Developer Console. The application gets a client ID and a client secret. ConfigView exchanges them for a short-lived token and asks only for read access.

You will end up with **2 required secrets** (`VANTA_CLIENT_ID`, `VANTA_CLIENT_SECRET`) and **1 optional secret** (`VANTA_API_BASE`) in ConfigView when setup is complete.

> **Scope of this integration today.** ConfigView reads Vanta's personnel list and where each person's security tasks stand (training, policy acceptance, device monitoring, background check, offboarding), who can sign in to Vanta, groups, the systems connected to Vanta, the vendor inventory with risk and review status, apps Vanta discovered people signing in to, compliance test status, monitored computers, and Vanta's event log. It never reads documents, policies' text, evidence files, audit requests or Trust Center content. ConfigView only reads. It never creates, changes or deletes anything in Vanta.

***

## What you need

* A Vanta **admin** account, to open the Developer Console
* Vanta's API is included with the Vanta platform. Some areas are only filled in if your Vanta plan includes them: vendor management and vendor discovery need Vanta's vendor risk features, and monitored computers need the Vanta agent or an MDM integration built by Vanta. If an area is not on your plan, that collector skips itself and its table stays empty. That does not count as a failure.

***

## Step 1: Open the Vanta page in ConfigView

Open ConfigView in a second browser tab and leave it open:

`https://{companyname}.configview.com/admin/integrations/vanta`

Vanta shows the client secret once, when you generate it, so paste it straight into ConfigView instead of keeping it in a notes file.

***

## Step 2: Create a Manage Vanta application

1. Sign in to Vanta as an admin
2. Open **Settings → Developer Console** (`https://app.vanta.com/settings/developer-console`; EU accounts use `app.eu.vanta.com`, Australian accounts `app.aus.vanta.com`)
3. Click **Create**
4. Set the app type to **Manage Vanta**. The other types ("Build Integrations" and "Auditor API") can't read your account's data
5. Name it `ConfigView` and add a short description, for example "Read-only inventory for ConfigView"
6. Save. Vanta generates the **client ID**. It starts with `vci_`
7. Click **Generate client secret**. Copy the secret. It starts with `vcs_`
8. Switch to the ConfigView tab and paste the two values into `VANTA_CLIENT_ID` and `VANTA_CLIENT_SECRET` under **Credentials**, then click the save icon for each

ConfigView requests the read-only scope `vanta-api.all:read` and nothing else.

### Give ConfigView its own application

Vanta allows **one active token per application**. When something requests a new token, Vanta cancels the previous one straight away. If ConfigView shares an application with another script, a Postman collection or the Vanta MCP server, each one keeps cancelling the other's token and both fail at random. Create a separate application for ConfigView and don't use its credentials anywhere else.

ConfigView's own collectors all start at the same time, so they share one token. They don't cancel each other.

### Vanta Gov

If your company uses Vanta Gov, paste `https://api.vanta-gov.com` into `VANTA_API_BASE`. Everyone else leaves it empty: US, EU and Australian accounts all use `https://api.vanta.com`.

***

## Step 3: Connect and verify

1. Back on `https://{companyname}.configview.com/admin/integrations/vanta`, confirm the credentials show as saved
2. Click **Connect**. ConfigView creates its tables and schedules every collector at your default run time. Stop any you don't want under **Collectors**:

| Script | Notes |
| - | - |
| **People** | Everyone Vanta tracks as personnel: employment status, start and end dates, leave, groups, and where each security task stands: training, policy acceptance, device monitoring, background check and offboarding tasks. |
| **Vanta Users** | People who can sign in to Vanta itself, and whether each login is active. |
| **Groups** | Personnel groups, created by hand or imported from your identity provider, with how many people each has and its point of contact. |
| **Connected Integrations** | Systems connected to Vanta, each connection, and whether Vanta has disabled it and why. |
| **Vendors** | The vendor inventory: category, status, inherent and residual risk, how staff sign in, whether MFA is required, owners, contract dates and value, security review dates, and the latest decision. |
| **Discovered Vendors** | Apps Vanta found people using, from Okta, Google Workspace, Microsoft 365, Jamf or Vendr, that aren't in the vendor inventory. Includes the account count and whether each app is waiting for review, ignored or rejected. |
| **Discovered Vendor Accounts** | Who uses each discovered app. Runs after Discovered Vendors and makes one request per app. |
| **Tests** | Vanta's automated compliance tests: status, how many items fail, the remediation deadline and the owner. |
| **Monitored Computers** | Computers watched by the Vanta agent or an MDM integration built by Vanta: owner, serial number, operating system, last check-in, and pass or fail for screen lock, disk encryption, password manager and antivirus. |
| **Event Log** | Vanta's event log. ConfigView keeps every event it collects. |

3. Click **Verify now**. The health check reads both secrets and gets a token. It reuses the collectors' token when one is current, so a check never interrupts a running collector. It then reads your organization's name and one person, and tries one record from each of the other areas.

If a check fails:

* **Token fails with 401 or invalid\_client.** The client ID or secret is wrong, or the secret was rotated in the Developer Console. Generate a new secret and paste it again.
* **Token fails with invalid\_scope.** The application isn't a **Manage Vanta** app. Create a new one with that type.
* **Token fails with 429.** Vanta allows 5 token requests a minute. Wait a minute and verify again.
* **An area shows as skipped.** Vanta answered "forbidden" or "not found" for it, which usually means your plan doesn't include it. Nothing to fix.
* **Collectors fail with 401 now and then.** The application's credentials are being used somewhere else as well. See *Give ConfigView its own application*.

***

## Data Tables

Once the scripts run, these tables are created in your database. Each table has a `run_at` column and a `raw_json` column, which holds the record as Vanta returned it, minus anything listed under *What isn't collected*. The snapshot tables keep only the newest run. `vanta_event_logs` keeps every event ever collected.

| Table | Source | Key Columns |
| - | - | - |
| `vanta_people` | `GET /v1/people` | person\_id, user\_id, email, display\_name, job\_title, employment\_status, start\_date, end\_date, leave\_status, group\_ids, tasks\_status, tasks\_due\_date, training\_status, incomplete\_trainings, policies\_status, unaccepted\_policies, custom\_tasks\_status, offboarding\_status, incomplete\_offboarding\_tasks, device\_monitoring\_status, background\_check\_status, end\_date\_integration |
| `vanta_users` | `GET /v1/users` | user\_id, email, display\_name, is\_active |
| `vanta_groups` | `GET /v1/groups` | group\_id, name, group\_source, personnel\_count, contact\_email |
| `vanta_integrations` | `GET /v1/integrations` | integration\_id, display\_name, resource\_kinds, connection\_id, is\_disabled, error\_message |
| `vanta_vendors` | `GET /v1/vendors` | vendor\_id, name, website\_host, category, vendor\_status, inherent\_risk, residual\_risk, auth\_method, mfa\_required, contract dates and amount, next\_review\_due\_date, last\_review\_completed\_date, decision\_status |
| `vanta_discovered_vendors` | `GET /v1/discovered-vendors` (once per review state) | discovered\_vendor\_id, name, category, discovery\_source, discovered\_at, account\_count, review\_state |
| `vanta_discovered_vendor_accounts` | `GET /v1/discovered-vendors/{id}/accounts` | discovered\_vendor\_id, vendor\_name, account\_type, email, owner\_email |
| `vanta_tests` | `GET /v1/tests` | test\_id, name, category, test\_status, integrations, failing\_item\_count, remediation\_status, remediate\_by, owner\_email |
| `vanta_monitored_computers` | `GET /v1/monitored-computers` | computer\_id, serial\_number, os\_type, os\_version, owner\_email, last\_check\_at, screenlock, disk\_encryption, password\_manager, antivirus |
| `vanta_event_logs` | `GET /v1/event-logs` | event\_id, event\_at, event\_action, actor\_type, actor\_id, target\_types, target\_ids |

***

## Things worth knowing

**Statuses are Vanta's.** "Overdue", "due soon" and "needs attention" are Vanta's own verdicts. ConfigView stores them as they are, so its answers match the Vanta dashboard.

**Group membership is on the person.** `vanta_people.group_ids` lists the ids of a person's groups, separated by commas. Join to `vanta_groups.group_id`.

**Vendor owners are Vanta user ids.** `security_owner_user_id` and `business_owner_user_id` match `vanta_users.user_id`.

**Monitored computers don't include partner integrations.** Vanta only lists computers reported by the Vanta agent or by MDM integrations Vanta built itself. If you use a partner-built MDM integration, its computers won't appear here.

**The event log has ids, not names.** Each event names its actor and targets by id and type only. Match actor ids against `vanta_users.user_id`, and `Person` targets against `vanta_people.person_id`. The first run collects the last 90 days. After that, each run picks up from the newest event already stored.

**Rate limit.** Vanta allows 50 API requests a minute and 5 token requests a minute. Each ConfigView collector paces itself at 20 a minute, so two can run at once and still leave room for your own use. Discovered Vendor Accounts makes one request per discovered app, so with a few hundred apps it takes several minutes.

## What isn't collected

* Vendor account manager names and emails, free-text vendor notes, and procurement ticket links
* Documents, evidence files, policy text, risk register entries, audit requests, questionnaires and Trust Center content
* The client secret and the access token never go into the database. The token is cached for up to an hour in a file only ConfigView can read, so the collectors can share it


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.