CAST Highlight Settings
Overview
The CAST Highlight Settings are provided for customers that are using the com.castsoftware.highlight2mri extension to inject CAST Highlight results as properties of objects generated during an application analysis. By linking directly to your CAST Highlight account, your CAST Highlight SCA vulnerabilities can be downloaded direct and injected into the analysis results, which is then reused in CAST Imaging. You can find out more information about when to fill in these fields in the documentation linked above.
- Using the integration with CAST Highlight via the com.castsoftware.highlight2mri extension requires a live internet connection to the URL defined in the Highlight URL field.
- The CAST Highlight data is made available in Viewer.
- It is NOT necessary to configure these settings if you are using the com.castsoftware.highlight2mri extension to generate CloudReady information for consumption in Viewer.
Settings


Highlight URL
The URL to your CAST Highlight instance, for example https://rpa.casthighlight.com.
Company ID / Client ID
These entries can be found in your CAST Highlight user profile. Note that Client ID is optional, while Company ID is required. If you do not supply the Client ID value, then CAST Imaging is not able to know when the supplied CAST Highlight token expires and will therefore not generate a system alert about this (i.e. the token could expire and CAST Imaging will not know).
Token
The Highlight Token - this can be also be found in your CAST Highlight user profile but must be manually enabled by CAST Highlight Support first. Note that a token is valid for a finite duration and will expire. When it has expired and if you supply the Client ID value (see above), a system alert is generated to warn you.
Longer tokens issued by CAST Highlight 6.0
CAST Highlight 6.0 generates the token with Keycloak. A token in this format is considerably longer than a token issued by an earlier release of CAST Highlight:
- In 3.6.7-funcrel and above, a token of up to 1024 characters is accepted.
- In releases before 3.6.7-funcrel, a token longer than 255 characters cannot be saved. Save fails and the analysis of any application that relies on the token fails.
The move to the new authentication system is rolled out by CAST Highlight - see Action required: upgrading to our new authentication system for the date on which your CAST Highlight instance switches over.
A token issued in the previous format remains valid until 5 November 2026. Replace it with a token in the new format before that date.
Injecting CAST Highlight results into your analysis results with a token in the new format also requires a release of the com.castsoftware.highlight2mri extension that supports the new format - see the extension documentation for the minimum release.
Create application
Enabled by default and will automatically create the corresponding application in CAST Highlight if it does not already exist there.
Save
Saves the entries that you have added (a check is actioned to ensure that the entries are valid). In addition, saving the entries will ensure that the com.castsoftware.highlight2mri extension is automatically added to the Force Install list - in other words the extension will be automatically installed in all existing applications when the next analysis is run and all new applications by default.