Skip to content
| Marketplace
Sign in
Visual Studio>Tools>OX Security
OX Security

OX Security

ox.security

ox.security
| (0) | Free
Scan your local changes with OX Security from inside Visual Studio: findings in a tool window, the Error List and the editor, with suggested fixes you can apply in one click.
Download

OX Security for Visual Studio

The OX Security extension scans your local code changes from inside Visual Studio and reports the results without leaving the IDE. It integrates with the OX Security platform and is intended for developers.

This option is not a replacement for full repository scans, but a complementary tool for early-stage, local validation.

The repository you scan must exist in your organization and be known to OX.

Currently the following issue categories are supported: Open Source Security, Code Security, SBOM, IaC, Secret/PII.

The main goal is to let you scan code locally before pushing changes to a remote repository, as follows:

  • Detect vulnerabilities and secrets before they are exposed.
  • Surface risky code before you push it to a shared repository.
  • Fix security issues early in the development process.

How it works

After you install the extension, the OX Security tool window is available from Extensions > OX Security > Show OX Security.

You can run a scan directly from the tool window's toolbar, which compresses your local changes and sends them to the OX backend for analysis. Results are grouped by severity or category in the tool window's tree, with each issue linked to the exact line of code and, where available, a suggested fix you can apply in one click.

Findings also appear in Visual Studio's Error List and as squiggles in the editor, so you can navigate to an issue the same way you would a compiler warning: double-click the row, or the squiggle's line, to jump to the exact location.

Requirements

  • Visual Studio 2022 17.14 or later, or Visual Studio 2026
  • Git on PATH
  • An OX Security account with API access

Generating IDE/CLI Integration key

Before you install the extension, you need to generate an API key.

To generate an API key:

  1. From the left pane of OX Security platform, select Settings > API Key Settings.

  2. In the API Key Settings window, select CREATE API KEY.

  3. In the Create API Key dialog, set the following:

    API key settings

API Key Name Add a meaningful name that is easy to identify. It is good practice to include the key's intended purpose in the name.
API Key Type Select IDE Integration.
Expiration Date Until when you can use this key.
  1. Select CREATE. The key appears.

    API key settings with the key

  2. Copy and save the API Key Secret to be used when connecting to APIs. This is the only time when you can see and copy the key.

  3. Select CLOSE. The new key appears in the API Key Settings page.

    API key in the OX Settings page

Configure

From Extensions > OX Security:

  • Configure API Key... to authenticate with the key you generated above.
  • Configure API Endpoint... to point the extension at a custom OX deployment instead of the predefined cloud endpoint.
  • Sign in with OAuth to authenticate with your OX account instead of an API key.

A connection check runs automatically after any of these change, so you know immediately whether scanning is available.

Scan

Run Scan Local Changes from Extensions > OX Security or from the ▶ button on the OX Security tool window's toolbar. Results appear in the tool window, the Error List and the editor once the scan completes.

Stop Scan, from the same menu, cancels a scan that is still running.

Settings

From Extensions > OX Security:

  • Scan Engines... to choose which engines a scan reports on: Open Source Security, Code Security, SBOM, IaC and Secret Scan.
  • Send Anonymous Telemetry... to enable or disable sending usage telemetry.

Troubleshooting

The OX Security Output pane (View > Output, then Show output from: OX Security) logs each step of a scan and any error the backend returns.

For more detailed logging, set the OX_IDE_DEBUG=1 environment variable before launching Visual Studio.

From Extensions > OX Security:

  • Report an Issue... to open a prefilled GitHub issue for the ox-ide repository, with the extension and Visual Studio versions already filled in.
  • Upload Logs to Telemetry to send the Output pane's buffered log lines to OX telemetry.

Support

  • Documentation: https://docs.ox.security/scan-and-analyze-with-ox/scanning/ox-ide-integrations/ox-ide-extension
  • Issues: https://github.com/oxsecurity/ox-ide/issues
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft