---
title: How do I configure a Qualys WAS Integration?
description:   Login to your Qualys region using an Admin account. Qualys Assign Role and Permissions  
---

[Skip to content](https://support.nopsec.com/knowledge/how-do-i-configure-a-qualys-integration-0#main-content)

English

Show submenu for translations

![nopsec-full-logo-white.png\]](https://support.nopsec.com/hs-fs/hubfs/Images/Logos/NopSec%20Logos/nopsec-full-logo-white.png?height=40&name=nopsec-full-logo-white.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [NopSec.com](https://www.nopsec.com/)

[NopSec.com](https://www.nopsec.com/)

 Welcome to the NopSec Knowledge Base. Start your search below.

- There are no suggestions because the search field is empty.

1. [Knowledge Base](https://support.nopsec.com/knowledge?hsLang=en)
2. [Implementation/Admin Learning Path](https://support.nopsec.com/knowledge/implementation-admin-learning-path?hsLang=en)

# How do I configure a Qualys WAS Integration?

## In the Qualys Cloud Platform API access is granted by creating a Service User account and enabling specific permissions and scopes for it. The username and password for this account function as your API credentials. Here is the step-by-step guide to creating a dedicated API user.

### **Step 1: Create a Dedicated Service Account**

- Log in to the Qualys platform using an account with **Manager** privileges.
- Use the application picker (the drop-down menu in the top left corner) to select the **Administration** utility.
- In the left-hand navigation menu, click on **Users**, then select **User Management**.
- Click the **Create User** button.
- Fill out the required **General Information** fields. We recommend using a descriptive naming convention, such as "Nopsec", for the user details.

### **Step 2: Enable API Access**

- Within the user creation window, navigate to the **Security** (or Locale/Security) tab.
- Locate the **User Access** section.
- Check the box next to **API** to allow this account to make programmatic requests to the Qualys servers.
- Manually specify a strong password. **This username and password combination will act as your API credentials.**

### **Step 3: Assign the WAS Reader Role and Scope**

To ensure the account is read-only and restricted to Web Application Scanning (WAS) data, you must apply the correct Role-Based Access Control (RBAC) settings.

- Navigate to the **Roles and Scopes** tab in the user creation window.
- Under the **Roles** section, select the **WAS Reader** role from the list of available roles. This is a built-in Qualys role that strictly limits the user to viewing web application assets, scan findings, and reports, without granting the ability to launch scans or modify configurations.
- Under the **Scope** section, assign the specific **Tags** or **Asset Groups** this API account is permitted to query.  
  **Note:** If the API needs visibility into *all* web applications across your subscription, assign your organization's root tag or a global tag (e.g., "Cloud Agent" or "All Assets"). If left scoped to specific tags, the API will silently omit any assets outside that scope from its responses.
- Click **Save** to finalize and create the API user.

**Step 4: Enable the integration in the Nopsec Platform**

- Navigate to Integrations in the NopSec UI and select the option to add the Qualys integration 
    - NOTE: You are able to use the existing "Qualys" integration for both infrastructure and WAS findings and asset data. Follow the instructions above to add WAS visibility to your existing Qualys/Nopsec integration account
- Enter Integration Access Info: When prompted enter the following information and click the "Save and Connect" button: 
    - **Connection Name**: Unique name for this integration (QualysWAS)
    - **Username:**  The username created in the previous steps
    - **Password:** The password created in previous steps
    - **Platform:** Your Qualys url's region i.e. "US Platform 1"
    - SAVE and CLOSE

- [NopSec Platform 101](https://support.nopsec.com/knowledge/nopsec-platform-101?hsLang=en)
- [Implementation/Admin Learning Path](https://support.nopsec.com/knowledge/implementation-admin-learning-path?hsLang=en)
- [Analyst/Remediator Learning Path](https://support.nopsec.com/knowledge/analyst-remediator-learning-path?hsLang=en#main-content)

    - [Reporting](https://support.nopsec.com/knowledge/analyst-remediator-learning-path?hsLang=en#reporting)
    - [Workflow (Remediation/Exception)](https://support.nopsec.com/knowledge/analyst-remediator-learning-path?hsLang=en#workflow-remediation-exception)
    - [Insights](https://support.nopsec.com/knowledge/analyst-remediator-learning-path?hsLang=en#insights)
    - [Asset Management](https://support.nopsec.com/knowledge/analyst-remediator-learning-path?hsLang=en#asset-management)
- [New Features](https://support.nopsec.com/knowledge/new-features?hsLang=en)
- [Training Videos](https://support.nopsec.com/knowledge/training-videos?hsLang=en)
- [Release Notes](https://support.nopsec.com/knowledge/release-notes?hsLang=en)

[![Chill listening crop-3](https://support.nopsec.com/hs-fs/hubfs/Images/Logos/NopSec-logo-160x160.png?width=24&height=24&name=NopSec-logo-160x160.png "Chill listening crop-3")](https://www.nopsec.com)

NopSec Knowledge Base

Copyright © 2026, NopSec