Skip to main content

Storing your API key

Settings use the same names as the flags: api-key, api-url, proxy, and ca-cert. They are stored in ~/.scanoss/settings.json:
The command line always uses the dashed names. The file stores keys in snake_case, but that is only the file’s format, and you can’t type a key that way on the command line.

Precedence

Every setting resolves the same way, and each has a matching flag:
The environment variable is the setting name in upper case with a SCANOSS_ prefix: SCANOSS_API_KEY, SCANOSS_API_URL, SCANOSS_PROXY, SCANOSS_CA_CERT. The CLI treats an empty value from the environment or the file as unset and moves on to the next source.
--verbose reports which source won for each setting. It prints the source only, never the key’s value.

Inspecting configuration

The CLI never prints the API key. list and get always show it as ********, and no flag reveals it, so it can’t end up in your shell history or a CI log. config get api-key only tells you whether the key is set, through its exit code: 0 if set, 1 if not. Scripts that need the value should use $SCANOSS_API_KEY. To read your own file directly, run cat "$(scanoss-cli config path)".
Non-secret values print normally:

On-prem endpoint

A custom API URL may not require an API key, so pointing the CLI at an internal deployment takes one command:

Proxy and custom CA

The CLI honours HTTP_PROXY, HTTPS_PROXY, and NO_PROXY without any flags. --proxy overrides them for one run, and --ca-cert trusts a CA that the system pool doesn’t have:
--ca-cert adds the CA to the system pool, so the public API keeps working and TLS verification stays on. --ignore-cert-errors is different. It turns off TLS verification entirely, which is insecure, so use it only to test against a self-signed internal endpoint. --proxy and --ca-cert work on every command that reaches the API. The CLI doesn’t support proxy auto-configuration (PAC). Read the proxy address from the PAC file and pass it with --proxy. You can store both settings, so you don’t have to repeat either flag:
A stored proxy takes precedence over HTTP_PROXY and HTTPS_PROXY. You can’t store --ignore-cert-errors, so turning off verification is always a choice you make for one run.

CI

In CI, set the key in the environment instead of a config file. You don’t need config set, and the key stays off the command line, where it would end up in build logs:

Rotating and removing

You can edit the file by hand. config set leaves keys that the current version doesn’t recognize untouched.