Storing your API key
api-key, api-url, proxy, and ca-cert. They are
stored in ~/.scanoss/settings.json:
snake_case, but that is only
the file’s format, and you can’t type a key that way on the command line.
Precedence
Every setting resolves the same way, and each has a matching flag:SCANOSS_ prefix:
SCANOSS_API_KEY, SCANOSS_API_URL, SCANOSS_PROXY, SCANOSS_CA_CERT. The CLI treats an empty
value from the environment or the file as unset and moves on to the next source.
--verbose reports which source won for each setting. It prints the source only, never the key’s
value.
Inspecting configuration
The CLI never prints the API key.
list and get always show it as ********, and no flag
reveals it, so it can’t end up in your shell history or a CI log. config get api-key only
tells you whether the key is set, through its exit code: 0 if set, 1 if not. Scripts that
need the value should use $SCANOSS_API_KEY. To read your own file directly, run
cat "$(scanoss-cli config path)".On-prem endpoint
A custom API URL may not require an API key, so pointing the CLI at an internal deployment takes one command:Proxy and custom CA
The CLI honoursHTTP_PROXY, HTTPS_PROXY, and NO_PROXY without any flags. --proxy overrides
them for one run, and --ca-cert trusts a CA that the system pool doesn’t have:
--ca-cert adds the CA to the system pool, so the public API keeps working and TLS verification
stays on. --ignore-cert-errors is different. It turns off TLS verification entirely, which is
insecure, so use it only to test against a self-signed internal endpoint. --proxy and
--ca-cert work on every command that reaches the API. The CLI doesn’t support proxy
auto-configuration (PAC). Read the proxy address from the PAC file and pass it with --proxy.
You can store both settings, so you don’t have to repeat either flag:
proxy takes precedence over HTTP_PROXY and HTTPS_PROXY. You can’t store
--ignore-cert-errors, so turning off verification is always a choice you make for one run.
CI
In CI, set the key in the environment instead of a config file. You don’t needconfig set, and
the key stays off the command line, where it would end up in build logs:
Rotating and removing
config set leaves keys that the current version doesn’t
recognize untouched.