Get an API key
SCANOSS issues API keys for the hosted SCANOSS API (https://api.scanoss.com) under a commercial
licence. To get one, contact sales@scanoss.com or
support@scanoss.com.
One key works for every tool on this page. Treat it as a password:
- Keep it in your CI system’s secret store, and pass it to the tools as the
SCANOSS_API_KEYenvironment variable. - Do not type it on a command line in CI. CI systems often write commands to build logs.
- Do not commit it to a repository, and do not put it in
scanoss.json.
What needs a key
scanoss-cli
Ways to provide the key
config set writes to ~/.scanoss/settings.json. Run scanoss-cli config path to print the
exact location.
Precedence
Each setting resolves in the same order. The first source that has a non-empty value wins:Check what is in effect
scanoss-cli config get api-key only reports whether a key is set, and
exits 0 if it is and 1 if it is not, so you can use it in a script:
--verbose to any command to log which source each setting came from. The CLI never logs the
key’s value.
What happens without a key
If no key is set and the API URL is the defaulthttps://api.scanoss.com, every command that
calls the API stops before it sends anything. It prints a “No API key provided” notice to stderr
and exits with code 1.
If the API rejects the key (HTTP 401), the CLI prints
Unauthorized: missing or invalid API key and exits with code 1.
Rotate or remove a stored key
Crypto Finder
Ways to provide the key
crypto-finder configure writes to ~/.scanoss/crypto-finder/config.json. This file is separate
from the scanoss-cli file. If the file is readable by other users, Crypto Finder restricts it to
the owner when it loads it.
Precedence
- Command-line flags (
--api-key,--api-url) - Environment variables (
SCANOSS_API_KEY,SCANOSS_API_URL) - Config file (
~/.scanoss/crypto-finder/config.json) - Project settings (
scanoss.jsonin the scanned directory) - Defaults (
https://api.scanoss.com)
SCANOSS_API_KEY and SCANOSS_API_URL, one pair of environment
variables configures both in the same pipeline.
Use a custom API URL
Point the tools at an on-premise SCANOSS deployment, or any other SCANOSS endpoint, with the API URL setting:Proxies and custom certificate authorities
scanoss-cli
scanoss-cli honoursHTTP_PROXY, HTTPS_PROXY, and NO_PROXY without any flag. To override
them, or to trust a private CA, use the flags or store the settings:
--ca-certadds a PEM file to the system trust store. Verification stays on, and the public API still works.- A stored or flag
proxytakes precedence overHTTP_PROXY/HTTPS_PROXY. - scanoss-cli does not support proxy auto-configuration (PAC) files. Read the proxy address from
the PAC file and pass it with
--proxy. --ignore-cert-errorsturns off all TLS verification. Use it only to test against a self-signed internal endpoint. It cannot be stored in the config file.
Crypto Finder
Crypto Finder has no proxy or CA flags. It uses the Go standard HTTP client, which means it:- honours the
HTTP_PROXY,HTTPS_PROXY, andNO_PROXYenvironment variables - trusts the operating system’s certificate store
SSL_CERT_FILE to a bundle that
contains it. SSL_CERT_FILE replaces the default bundle, so the file must also contain the public
root certificates.
Calling the API directly
Send the key in thex-api-key request header. Header names are not case-sensitive.
CI example
Store the key as a secret in your CI system and expose it to the job asSCANOSS_API_KEY. The
commands then need no key flag: