> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanoss.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuration

> Store credentials, proxy and CA settings once with scanoss-cli config, instead of passing flags on every run.

## Storing your API key

```bash theme={null}
scanoss-cli config set api-key SC_abc123def456
scanoss-cli scan ./my-project --output results.json
```

Settings use the same names as the flags: `api-key`, `api-url`, `proxy`, and `ca-cert`. They are
stored in `~/.scanoss/settings.json`:

```json theme={null}
{
  "api_key": "SC_abc123def456",
  "api_url": "https://api.scanoss.com",
  "proxy": "http://proxy.example.com:8080",
  "ca_cert": "/etc/ssl/corp-ca.pem"
}
```

The command line always uses the dashed names. The file stores keys in `snake_case`, but that is only
the file's format, and you can't type a key that way on the command line.

## Precedence

Every setting resolves the same way, and each has a matching flag:

```
--flag  >  environment variable  >  ~/.scanoss/settings.json  >  built-in default
```

The environment variable is the setting name in upper case with a `SCANOSS_` prefix:
`SCANOSS_API_KEY`, `SCANOSS_API_URL`, `SCANOSS_PROXY`, `SCANOSS_CA_CERT`. The CLI treats an empty
value from the environment or the file as unset and moves on to the next source.

```bash theme={null}
scanoss-cli config set api-url https://scanoss.internal.example.com

scanoss-cli scan .                                                         # 1. stored value wins
SCANOSS_API_URL=https://scanoss.staging.example.com scanoss-cli scan .     # 2. env overrides file
SCANOSS_API_URL=https://scanoss.staging.example.com \
  scanoss-cli scan . --api-url https://api.scanoss.com                    # 3. flag overrides both
```

`--verbose` reports which source won for each setting. It prints the source only, never the key's
value.

## Inspecting configuration

```console theme={null}
$ scanoss-cli config list
api-key  ********                              (env: SCANOSS_API_KEY)
api-url  https://scanoss.internal.example.com  (config file)

Config file: /Users/you/.scanoss/settings.json
```

<Note>
  The CLI never prints the API key. `list` and `get` always show it as `********`, and no flag
  reveals it, so it can't end up in your shell history or a CI log. `config get api-key` only
  tells you whether the key is set, through its exit code: `0` if set, `1` if not. Scripts that
  need the value should use `$SCANOSS_API_KEY`. To read your own file directly, run
  `cat "$(scanoss-cli config path)"`.
</Note>

Non-secret values print normally:

```console theme={null}
$ scanoss-cli config get api-url
https://scanoss.internal.example.com
```

## On-prem endpoint

A custom API URL may not require an API key, so pointing the CLI at an internal deployment takes
one command:

```bash theme={null}
scanoss-cli config set api-url https://scanoss.internal.example.com
scanoss-cli scan .
```

## Proxy and custom CA

The CLI honours `HTTP_PROXY`, `HTTPS_PROXY`, and `NO_PROXY` without any flags. `--proxy` overrides
them for one run, and `--ca-cert` trusts a CA that the system pool doesn't have:

```bash theme={null}
scanoss-cli scan . --proxy http://proxy.example.com:8080
scanoss-cli scan . --ca-cert /etc/ssl/corp-ca.pem
```

`--ca-cert` *adds* the CA to the system pool, so the public API keeps working and TLS verification
stays on. `--ignore-cert-errors` is different. It turns off TLS verification entirely, which is
insecure, so use it only to test against a self-signed internal endpoint. `--proxy` and
`--ca-cert` work on every command that reaches the API. The CLI doesn't support proxy
auto-configuration (PAC). Read the proxy address from the PAC file and pass it with `--proxy`.

You can store both settings, so you don't have to repeat either flag:

```bash theme={null}
scanoss-cli config set proxy http://proxy.example.com:8080
scanoss-cli config set ca-cert /etc/ssl/corp-ca.pem
scanoss-cli scan .
```

A stored `proxy` takes precedence over `HTTP_PROXY` and `HTTPS_PROXY`. You can't store
`--ignore-cert-errors`, so turning off verification is always a choice you make for one run.

## CI

In CI, set the key in the environment instead of a config file. You don't need `config set`, and
the key stays off the command line, where it would end up in build logs:

```yaml theme={null}
- name: SCANOSS scan
  env:
    SCANOSS_API_KEY: ${{ secrets.SCANOSS_API_KEY }}
  run: scanoss-cli scan . --output results.json
```

## Rotating and removing

```bash theme={null}
scanoss-cli config set api-key SC_newkey789   # overwrite in place
scanoss-cli config unset api-key              # remove the key
scanoss-cli config path                       # print the file location
```

You can edit the file by hand. `config set` leaves keys that the current version doesn't
recognize untouched.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.