> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanoss.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Choose your path

> Use Earnie for out-of-the-box governance, or build your own pipeline from SCANOSS's standalone CLIs, public API, and copy-pasteable Recipes.

SCANOSS gives you two ways to answer the same questions: what open source is in this code, under
which licences, with which known vulnerabilities, and which cryptography it uses. Both ways use
the same SCANOSS Knowledge Base. The difference is how much of the work around the results SCANOSS
does for you.

## Option 1: Earnie, ready to use

[Earnie](/en/latest/earnie/introduction) is SCANOSS's governance platform. Choose it if you want
SCANOSS to run the whole workflow for you:

* policies that you define once and apply to every repository
* a merge gate on every pull request
* a review workspace to triage findings and record decisions
* dashboards across all your projects
* exportable evidence for customers and auditors

You connect your repositories, and Earnie runs the scans, applies your policies, and records each
decision. You write no pipeline code.

<Card title="Go to Earnie" href="/en/latest/earnie/introduction">
  Policies, merge gates, triage, dashboards, and evidence in one platform.
</Card>

## Option 2: Standalone tools, build your own pipeline

Choose the standalone tools if you already have a pipeline, a results store, or a review process,
and you want SCANOSS data inside it. You run the tools, you keep the output, and you decide what
fails a build.

SCANOSS does not maintain integrations for specific CI platforms. Instead, we publish
[Recipes](/en/latest/developer-tools/recipes). Each Recipe is a complete workflow written in plain
shell commands, with an explanation of every step. Recipes run in any CI system, in a Git hook, or
on a laptop.

| Tool | What it does | Output |
| - | - | - |
| [**scanoss-cli**](/en/latest/cli/scanoss-go/installation) | Fingerprints source code, scans it against the SCANOSS API, and adds licence, vulnerability, cryptography, geoprovenance, and dependency data. Also converts and refreshes SBOMs, and looks up component data by PURL. | SCANOSS raw inventory (JSON), SPDX 2.3, CycloneDX 1.7 |
| [**Crypto Finder**](/en/latest/cli/crypto-finder/overview) | Finds cryptographic algorithm, protocol, certificate, and key usage in your source code and, optionally, in your third-party dependencies. Can trace reachability through the call graph. | Findings JSON, CycloneDX 1.7 CBOM |
| [**SCANOSS API (v3)**](/en/latest/developer-tools/api-overview) | The public HTTP API that both tools call. Call it directly when you build your own client or need component data in another service. | JSON |

<Note>
  `scanoss-cli` uses the SCANOSS v3 API and does not work with OSSKB.org. If you depend on
  OSSKB.org, use [SCANOSS-PY](/en/latest/cli/scanoss-py/installation).
</Note>

## Which one fits?

| If you want to | Use |
| - | - |
| Block risky changes on pull requests, without writing pipeline code | Earnie |
| Triage findings and keep a record of every decision | Earnie |
| Add a SCANOSS check to a pipeline you already maintain | scanoss-cli and a [Recipe](/en/latest/developer-tools/recipes/scan-pull-requests) |
| Publish an SBOM with every release | scanoss-cli ([Recipe](/en/latest/developer-tools/recipes/release-sbom)) |
| Build a cryptographic inventory for post-quantum planning | Crypto Finder ([Recipe](/en/latest/developer-tools/recipes/crypto-inventory-cbom)) |
| Scan code that cannot leave a restricted network | scanoss-cli fingerprints ([Recipe](/en/latest/developer-tools/recipes/fingerprint-only-scanning)) |
| Put SCANOSS component data in your own service | [SCANOSS API](/en/latest/developer-tools/api-overview) |

## Where to start

<Steps>
  <Step title="Get an API key">
    The hosted SCANOSS API at `https://api.scanoss.com` requires an API key. See
    [API keys and authentication](/en/latest/developer-tools/authentication).
  </Step>

  <Step title="Run your first scan">
    Install scanoss-cli, scan a project, and generate an SBOM in about five minutes. See
    [Quickstart](/en/latest/developer-tools/quickstart).
  </Step>

  <Step title="Pick a Recipe">
    Copy a complete workflow into your pipeline. See [Recipes](/en/latest/developer-tools/recipes).
  </Step>
</Steps>

## Running SCANOSS in your own infrastructure

If you need the SCANOSS Knowledge Base inside your own network instead of calling the hosted API,
see the Knowledge Base and deployment pages in this section. You then set a custom API URL so both
tools send requests to your deployment. See
[Use a custom API URL](/en/latest/developer-tools/authentication#use-a-custom-api-url).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.