Data Sources

Vercel

Vercel Marketplace OAuth scopes, environment metadata boundaries, evidence outputs, and troubleshooting.

Vercel

Noru connects to Vercel through the Vercel Marketplace installation and OAuth flow. The integration collects project, deployment, domain, team, and environment-variable metadata.

Environment values are not collected

Noru collects environment variable metadata for evidence, not environment variable values.

Permission reference

Prop

Type

Setup

Start the Vercel connection flow in Noru.
Choose the Vercel team or user account in the Marketplace installation UI.
Complete the OAuth callback and confirm the team context in Noru.
Run the first sync and review project, deployment, domain, and environment metadata evidence.

What Noru collects

  • projects and deployment configuration metadata
  • deployment history and deployment status
  • custom domains and SSL/certificate-related metadata
  • team members and role metadata where exposed
  • environment variable metadata, not values

What Noru does not collect

  • environment variable values
  • write access to deploy or change Vercel projects
  • source code from linked repositories

Evidence produced

Vercel evidence supports deployment controls, production change tracking, domain ownership, environment configuration review, and team access controls.

Troubleshooting

Disconnect behavior

Disconnecting stops future syncs. Remove the Marketplace integration in Vercel to remove provider-side authorization.

Scope minimization

Install the integration only for the Vercel team in scope and review team membership before connecting production projects.