CLI & Team Keys

Install the ScanDrix CLI, authenticate with team API keys, and run reviews locally or in CI.

The ScanDrix CLI runs the same review engine locally, in pre-commit hooks, or inside any CI runner.

Install

bash
curl -fsSL https://scandrix.dev/install | bash

The installer places a scandrix binary on your PATH (macOS, Linux, WSL). Verify:

bash
scandrix --version

Team API keys

CLI and CI runs authenticate with team API keys generated in the dashboard under Settings → API Keys. Keys start with the scandrix_ prefix.

bash
# Export for the current shell
export SCANDRIX_TEAM_KEY=scandrix_live_8f3a9b...

Pass the key per request either way:

http
x-team-key: scandrix_live_8f3a9b...
http
Authorization: Bearer scandrix_live_8f3a9b...

Treat team keys like passwords. They live in CI secret stores and developer environment files only — never in source code, shell history committed to a repo, or client-side bundles. Rotate immediately from the dashboard if a key is exposed; old keys are revoked instantly.

Local reviews

Review the current staging area before you even commit:

bash
scandrix review --staged

Other useful invocations:

bash
# Review uncommitted changes against main
scandrix review --base main

# Run a single rule against the working tree
scandrix review --rule sec-001

# Validate repository configuration
scandrix config validate

Output is a terminal-friendly summary with file:line anchors; add --json for machine-readable findings.

CI usage

Run reviews in your pipeline with the same key. GitLab example:

yaml
stages:
  - review

scandrix_code_review:
  stage: review
  image: scandrix/cli:latest
  script:
    - scandrix review --ci --base $CI_MERGE_REQUEST_TARGET_BRANCH_NAME
  only:
    - merge_requests
  variables:
    SCANDRIX_TEAM_KEY: $SCANDRIX_TEAM_KEY

In --ci mode the CLI exits non-zero when findings at or above your blocking severity exist, so merge gates work with your existing required-checks setup.

Pre-commit hook

bash
scandrix install-hooks

This adds a hook that runs scandrix review --staged before each commit. Skippable per-commit with git commit --no-verify when you need to land a WIP.

Command overview

CommandPurpose
scandrix reviewReview staged, branch, or PR changes
scandrix rules listPrint the rule catalog with IDs
scandrix rules dry-runPreview rule changes against history
scandrix config validateLint scandrix.yml
scandrix install-hooksInstall git hooks
scandrix auth loginInteractive auth for local use (alternative to team key)