CLI & Team Keys
Install the ScanDrix CLI, authenticate with team API keys, and run reviews locally or in CI.
The ScanDrix CLI runs the same review engine locally, in pre-commit hooks, or inside any CI runner.
Install
curl -fsSL https://scandrix.dev/install | bash
The installer places a scandrix binary on your PATH (macOS, Linux, WSL). Verify:
scandrix --version
Team API keys
CLI and CI runs authenticate with team API keys generated in the dashboard under Settings → API Keys. Keys start with the scandrix_ prefix.
# Export for the current shell
export SCANDRIX_TEAM_KEY=scandrix_live_8f3a9b...
Pass the key per request either way:
x-team-key: scandrix_live_8f3a9b...
Authorization: Bearer scandrix_live_8f3a9b...
Treat team keys like passwords. They live in CI secret stores and developer environment files only — never in source code, shell history committed to a repo, or client-side bundles. Rotate immediately from the dashboard if a key is exposed; old keys are revoked instantly.
Local reviews
Review the current staging area before you even commit:
scandrix review --staged
Other useful invocations:
# Review uncommitted changes against main
scandrix review --base main
# Run a single rule against the working tree
scandrix review --rule sec-001
# Validate repository configuration
scandrix config validate
Output is a terminal-friendly summary with file:line anchors; add --json for machine-readable findings.
CI usage
Run reviews in your pipeline with the same key. GitLab example:
stages:
- review
scandrix_code_review:
stage: review
image: scandrix/cli:latest
script:
- scandrix review --ci --base $CI_MERGE_REQUEST_TARGET_BRANCH_NAME
only:
- merge_requests
variables:
SCANDRIX_TEAM_KEY: $SCANDRIX_TEAM_KEY
In --ci mode the CLI exits non-zero when findings at or above your blocking severity exist, so merge gates work with your existing required-checks setup.
Pre-commit hook
scandrix install-hooks
This adds a hook that runs scandrix review --staged before each commit. Skippable per-commit with git commit --no-verify when you need to land a WIP.
Command overview
| Command | Purpose |
|---|---|
scandrix review | Review staged, branch, or PR changes |
scandrix rules list | Print the rule catalog with IDs |
scandrix rules dry-run | Preview rule changes against history |
scandrix config validate | Lint scandrix.yml |
scandrix install-hooks | Install git hooks |
scandrix auth login | Interactive auth for local use (alternative to team key) |