Skip to main content
Create the GitLab connection from the workspace integrations page. The connection must be able to read merge requests and repository content and, when comment publishing is enabled, create merge-request notes. Configure the Veridical webhook URL and shared secret for merge-request and push events. Veridical verifies the secret and rejects replays before queueing. For self-managed GitLab, the deployment administrator must allow the GitLab base URL through the egress policy and validate its TLS chain. Store tokens in the configured Vault or cloud secret manager, never in repository config.
Last modified on July 28, 2026