> ## Documentation Index
> Fetch the complete documentation index at: https://www.oplane.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect GitLab projects to Oplane

> Connect Oplane to GitLab projects for automated threat modeling on merge requests. No app install required, just sign in with your GitLab account.

Connect Oplane to your GitLab projects to enable automated threat modeling on merge requests. No app installation required, just sign in with your GitLab account.

<Steps>
  <Step title="Open Workspaces">
    Navigate to **Workspaces** in the left sidebar and click the **+ Workspace** button in the top right corner.

    <Frame>
      <img src="https://mintcdn.com/oplane-6a173d70/GQK91gqL1oAEp0r4/images/gitlab-setup/workspaces.webp?fit=max&auto=format&n=GQK91gqL1oAEp0r4&q=85&s=28c7b0371138eb251a9107ea058bc416" alt="Oplane Workspaces page" width="3840" height="2160" data-path="images/gitlab-setup/workspaces.webp" />
    </Frame>

    <Frame caption="Click the + Workspace button">
      <img src="https://mintcdn.com/oplane-6a173d70/GQK91gqL1oAEp0r4/images/gitlab-setup/zoom-button.png?fit=max&auto=format&n=GQK91gqL1oAEp0r4&q=85&s=f28411bcaac0b49d2a237b9bfb711071" alt="+ Workspace button" width="1400" height="1180" data-path="images/gitlab-setup/zoom-button.png" />
    </Frame>
  </Step>

  <Step title="Add a repository source">
    On the New Workspace page, enter a **Name** and optional **Description**. Then under **Sources**, click **Continue with GitLab** to connect your account. You can also set **Access** for the workspace on this same page, or leave **Sources** empty to run threat modeling locally via [MCP](/docs/find/mcp).

    <Frame>
      <img src="https://mintcdn.com/oplane-6a173d70/GQK91gqL1oAEp0r4/images/gitlab-setup/setup.webp?fit=max&auto=format&n=GQK91gqL1oAEp0r4&q=85&s=24281135f27fca67a3d5eeb598835d99" alt="Connect GitLab under Sources on the New Workspace page" width="3840" height="2160" data-path="images/gitlab-setup/setup.webp" />
    </Frame>
  </Step>

  <Step title="Sign in to GitLab">
    Oplane redirects you to GitLab to sign in. Enter your credentials or use one of the alternative sign-in methods (Google, GitHub, Bitbucket, Salesforce, or Passkey).

    Once authenticated, GitLab redirects you back to Oplane with your account connected.

    <Frame>
      <img src="https://mintcdn.com/oplane-6a173d70/jwR0xubu7PkQElvJ/images/gitlab-setup/signin.webp?fit=max&auto=format&n=jwR0xubu7PkQElvJ&q=85&s=1ab00d3f69ec4d7d71b22a98e149eb99" alt="GitLab sign-in page" width="652" height="859" data-path="images/gitlab-setup/signin.webp" />
    </Frame>
  </Step>

  <Step title="Select a project">
    Once your account is connected, **Sources** shows a GitLab group dropdown alongside a project search. Pick the group, search for the project you want, and click **Select**. Use **Add GitLab account** or **Switch Git provider** in the dropdown to connect a different account or provider.

    <Note>
      Oplane lists only GitLab projects where you are Maintainer or Owner. This access level is required to create a project access token.
    </Note>

    <Note>
      GitLab groups already claimed by a different Oplane organisation appear greyed out in the picker and cannot be selected. See [Namespace claims](/docs/how-it-works/workspaces#namespace-claims) for details.
    </Note>

    <Frame>
      <img src="https://mintcdn.com/oplane-6a173d70/GQK91gqL1oAEp0r4/images/gitlab-setup/search.webp?fit=max&auto=format&n=GQK91gqL1oAEp0r4&q=85&s=01e38cadb860adb43d5f9b4748bb8f19" alt="Select a group and project under Sources" width="1024" height="742" data-path="images/gitlab-setup/search.webp" />
    </Frame>
  </Step>

  <Step title="Configure and create">
    Once a project is selected, an **Analyse Pull Requests** toggle appears. Leave it on to automatically threat model every MR. If disabled, you can still trigger reviews by mentioning `@oplane` in an MR comment.

    Under **Access**, add team members who should have access and set **General access** (Restricted, or open to the organisation). Then click **Create**.

    <Frame>
      <img src="https://mintcdn.com/oplane-6a173d70/GQK91gqL1oAEp0r4/images/gitlab-setup/configure.webp?fit=max&auto=format&n=GQK91gqL1oAEp0r4&q=85&s=dc933cb81f96acc9cfd9db5b1c05b9cd" alt="Configure merge request analysis and access, then create the workspace" width="1024" height="742" data-path="images/gitlab-setup/configure.webp" />
    </Frame>
  </Step>

  <Step title="Choose threat models">
    Oplane analyses your repository and suggests threat models based on the codebase. Select the ones relevant to your project, or describe your own scope in the text box. You can also click **Skip and go to workspace** to do this later. This step helps Oplane understand what to focus on in future MR reviews.

    <Frame>
      <img src="https://mintcdn.com/oplane-6a173d70/GQK91gqL1oAEp0r4/images/gitlab-setup/suggest.webp?fit=max&auto=format&n=GQK91gqL1oAEp0r4&q=85&s=ba4cf87591d138afd5e663be7d5d684d" alt="Choose threat models for your project" width="1024" height="742" data-path="images/gitlab-setup/suggest.webp" />
    </Frame>
  </Step>
</Steps>

## GitLab integrations

The steps above work for projects on GitLab.com. If your team runs its own GitLab server, an organisation Owner first adds it as an integration in **Org Settings > Integrations**. After that, your self-managed instance shows up next to GitLab.com when you continue with GitLab, and you connect projects the same way.

<Card title="Connect a self-managed GitLab instance" icon="plug" href="/docs/connect/gitlab-self-managed">
  Create a GitLab OAuth application and add the integration in your organisation settings.
</Card>

## What's next?

<Card title="Review pull and merge requests" icon="git-pull-request" href="/docs/find/pull-and-merge-requests">
  Learn how Oplane reviews your merge requests.
</Card>

<Card title="Merge gating" icon="shield-check" href="/docs/prove/merge-gating">
  Set a failure threshold to use the Oplane Security Review check as a merge gate in GitLab merge-request approvals.
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.