Skip to main content
NEW · Blast Radius: a field playbook for leaked API keys on AWS, GCP and Azure
Scan Source

Notion Integration

Scan pages shared through the Notion OAuth connection, with target and scan-result checks for coverage.

Key Features

  • Notion OAuth connection with a page and database picker
  • Accessible page, database and data-source content discovered as scan targets
  • Supported text blocks, comments when allowed, and supported file blocks
  • Scheduled follow-up scans for accessible changed content

Requirements

  1. 1A Notion user allowed to grant the connection access to intended pages
  2. 2A Cremit Platform account with permission to add a scan source
  3. 3Read access to the pages, databases and file content to be inspected

Step-by-step setup guide

Review the steps needed to configure this integration.

What does the Notion connection read?

Cremit uses a Notion OAuth connection. During authorization, the Notion page picker lets you choose pages and databases to share. The connection does not receive a copy of the entire workspace merely because it is installed. Cremit discovers resources visible to its access token and creates scan targets from them. If a page is absent from that scope, it cannot be treated as checked.

The worker examines accessible page and database content, including supported text blocks. It can also inspect comments when the connection has the needed capability and supported file blocks within its limits. An unsupported block, unreadable or oversized file, permission error, or unfinished discovery can leave content out of a run. A clean result covers only content actually read.

Connect through OAuth

In Cremit Platform, open Configuration → Scan Sources, create a Notion source, and continue to Notion’s authorization screen. Choose the workspace and the pages or databases to share. Return to Cremit and inspect the discovered target list; enable the intended targets. The current product flow does not ask you to create an internal integration or paste its static secret into this form.

If an expected resource is absent, check the Notion connection’s page access and the user’s permission to share it, then refresh or reconnect the source. Do not assume that selecting one parent guarantees every future child is visible; verify newly added pages in the target list.

Verify coverage after the first scan

Check source connection status, target enablement, the latest completed scan and any skipped or failed pages, blocks or files. Large workspaces may need more than one job to finish discovery and scanning. Changes are revisited by scheduled work; editing a page does not guarantee a result within a fixed number of minutes. For a safe functional check, place a nonworking example string on an enabled test page and confirm a finding after the relevant scan without using a real key.

Investigate a finding

Record the page or file location without copying the secret into a ticket. For supported credential types, review the issuer check and its time, then confirm the current service owner and affected workload. The owner replaces or revokes a confirmed exposed credential at the issuer; deleting the Notion text alone does not invalidate it.

Primary documentation

Notion authorization and page selection

Notion search API

Notion connection access management

Cremit scanning scope

Get started now

Review the setup steps and required permissions for the Notion integration.

Notion Integration