> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanoss.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Quick start

> Scan a project, generate fingerprints only, or refresh an existing inventory with scanoss-cli.

## Scan a project

```bash theme={null}
scanoss-cli scan ./my-project --api-key "$SCANOSS_API_KEY" --output results.json
```

The default endpoint, `https://api.scanoss.com`, requires an API key. A custom API URL, such as
an on-prem deployment, may not require one. See
[Configuration](/en/latest/cli/scanoss-go/configuration#on-prem-endpoint).

## Generate fingerprints only

This uploads nothing and needs no API key:

```bash theme={null}
scanoss-cli wfp ./my-project > project.wfp
```

## Refresh an existing inventory

Add or update the vulnerability, licence, crypto, and geoprovenance layers on a result you already
have, without re-scanning:

```bash theme={null}
scanoss-cli enrich results.json --include vulns,licenses --api-key "$SCANOSS_API_KEY" > enriched.json
```

## Debug logging

Add `-v` or `--verbose` to any command to write structured debug logs to stderr. The logs cover
the scan flow, the fingerprinting detail, and each API request with its method, URL, status, and
duration. Stdout carries only results, so logs never corrupt `--output` or piped JSON.

```bash theme={null}
scanoss-cli scan ./my-project --api-key "$SCANOSS_API_KEY" --verbose
```

## Commands at a glance

| Command | Purpose |
| - | - |
| `scan <path>` | Fingerprint a folder/file, scan against the SCANOSS v3 API, and output results. |
| `scan wfp <wfp>` | Scan a pre-generated WFP file (no fingerprinting). |
| `wfp <path>` | Generate WFP fingerprints only (no upload). |
| `results <scan-id>` | Resume or poll a scan by its id. |
| `sbom <input>` | Produce an SBOM from a raw inventory, or convert between formats, offline. |
| `enrich <input>` | Add purl-keyed layers (vulns/licenses/crypto/geo) to a raw or SBOM file. |
| `dependencies [path]` | Extract local dependencies, or query direct/transitive deps for a PURL. |
| `vulnerabilities`, `cryptography`, `licenses`, `geoprovenance`, `copyright`, `components` | Decoration lookups by PURL. |
| `config` | Store settings in `~/.scanoss/settings.json`. |

[Scanning your project](/en/latest/cli/scanoss-go/scanning-your-project) and
[Decoration and enrichment](/en/latest/cli/scanoss-go/decoration-and-enrichment) cover each command
in full. You can also run `scanoss-cli <command> --help`.

## What's next

* Store your API key, proxy, and CA settings once. See
  [Configuration](/en/latest/cli/scanoss-go/configuration).
* Choose between `raw`, SPDX 2.3, and CycloneDX 1.7 output. See
  [Output formats](/en/latest/cli/scanoss-go/output-formats).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.