Connected GitHub Assurance
Already connected GitHub? Run the full HAIEC scan directly from your IDE. Once a repository is connected to an AI System through the HAIEC GitHub App, Cursor or another development environment can trigger HAIEC through the Assurance API.
Your IDE sends your HAIEC API key and the selected system/source identifiers. GitHub repository credentials stay server-side between HAIEC and the GitHub App — no checkout required and no GitHub token is sent to HAIEC.
The API caller sends only the HAIEC API key, AI System ID, and verified Source Asset ID. Repository credentials stay server-side between HAIEC and the organization-linked GitHub App.
One-time dashboard setup
- Install the HAIEC GitHub App for the GitHub organization or account.
- Ensure the installation is linked to the correct HAIEC organization.
- In AI Inventory, select the target AI System.
- Register the repository under Connected Assets and request verification.
- Verify that the source is
CONNECTED + VERIFIED. - Copy the
aiSystemIdandsourceAssetId.
Create the API key
Create an Assurance API / IDE key — it carries scan:create, scan:read, report:read, system:read, and source:read. No GitHub token, OAuth token, or X-GitHub-Token header is required. Keep the key server-side: .env.local (gitignored) or a secret manager — never NEXT_PUBLIC_*.
export HAIEC_BASE_URL=https://www.haiec.com
export HAIEC_API_KEY=haiec_live_xxx
export HAIEC_AI_SYSTEM_ID=SYSTEM_ID
export HAIEC_SOURCE_ASSET_ID=SOURCE_ASSET_IDTrigger from an IDE terminal
# Connected GitHub mode — no local source analysis
curl -X POST "$HAIEC_BASE_URL/api/v1/assurance/runs" \
-H "Authorization: Bearer $HAIEC_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d "{ \"aiSystemId\": \"$HAIEC_AI_SYSTEM_ID\",
\"engines\": { \"static\": { \"enabled\": true,
\"executionMode\": \"api\",
\"sourceAssetId\": \"$HAIEC_SOURCE_ASSET_ID\" } } }"
# Poll until evaluation.evaluationId appears
curl -H "Authorization: Bearer $HAIEC_API_KEY" \
"$HAIEC_BASE_URL/api/v1/assurance/runs/RUN_ID"The server revalidates the Source Asset, organization installation, repository scope, GitHub repository ID, branch, and commit before dispatching the remote scanner. For an agent-driven version of this flow, see the Cursor guide; the optional haiec scan github CLI mode wraps the same API (preview — the CLI package is not yet published).
Same result as Local / IDE
Prefer Local Assurance when you want the source to remain on your machine. Prefer Connected GitHub when you want HAIEC's remote scan infrastructure and the repository is already authorized. The two paths differ in where source analysis runs, not in the Assurance model — both produce the same organization-bound AI System evaluation surfaces:
If the installation is suspended, the repository leaves installation scope, or the verified GitHub repository identity changes, the run fails closed. A public URL alone cannot become trusted AI-System evidence.