Skip to content

Connect Figma to Black Cat SSPM

Version française

Connect your Figma organization so Black Cat can review webhooks, token hygiene and activity such as role and permission changes.

≈ 5 min · audit access · no write-capable permission

What Black Cat reads, and why

PermissionWhat it lets Black Cat doStatus
current_user:readLets Black Cat confirm the account it is connected as and whether that account is organization-scoped.Required
webhooks:readLets Black Cat review webhooks, their destinations and whether they are protected by a passcode.Required
org:activity_log_readLets Black Cat see organization activity such as member role and permission changes.Optional
org:developer_log_readLets Black Cat see how recently each access token was used.Optional

What you'll need

  • Personal API token Required — Created in your Figma account settings, under personal access tokens.
  • Organization identifier — Optional — needed for organization-wide activity; shown in the address bar of your Figma admin settings.

Where to create it

What we check on Figma →

Other setup guides

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications are based on publicly available documentation and may change over time.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default access you can revoke any time.

Run a free posture scan