Skip to content

Escape CLI

The Escape CLI is a command-line interface that enables you to automate security testing workflows and integrate Escape's capabilities directly into your development pipeline. The CLI is open source and provides commands and structured output for automation.

Overview

Use the CLI to manage assets, run scans, and handle security findings from your terminal or CI/CD environment.

Philosophy

The Escape CLI is designed with three core principles:

Automation-First

Every command is built to support scripting and automation. The CLI offers machine-readable output formats (JSON, YAML) alongside human-readable tables, making it equally suitable for interactive use and automated workflows.

Pipeline Integration

Make security testing part of your development process. The Escape CLI enables you to trigger scans and monitor results in your CI/CD pipelines. Use a quality-gate script to check scan status and findings before failing a build.

Developer Experience

Commands follow intuitive patterns with helpful aliases and clear documentation. Whether you're a security engineer or a developer new to security testing, the CLI provides a straightforward interface to Escape's capabilities.

Key Capabilities

Security Testing

  • Start and monitor security scans for REST APIs, GraphQL APIs, and web applications
  • Retrieve and analyze security findings in real-time
  • Configure scan parameters and override settings programmatically

Asset Management

  • Create and manage security test profiles for your applications
  • Track and organize assets across your infrastructure
  • Import assets in bulk from various sources

Private Location Support

The CLI enables you to deploy and manage Private Locations, allowing Escape to test applications within your private network while maintaining security and compliance requirements.

CI/CD Integration

  • Integration with GitHub Actions, GitLab CI, Jenkins, and other CI/CD platforms
  • Exit codes and output formats designed for pipeline automation
  • Support for commit metadata and build context

Use Cases

Continuous Security Testing

Integrate security scanning into every pull request or deployment to review and address findings before production.

Asset Discovery and Management

Maintain an up-to-date inventory of your APIs and web applications, with automated tracking of new services and endpoints.

Security Operations

Automate security workflows, from initial scanning to issue triage and remediation tracking.

Compliance and Reporting

Generate security reports and track compliance status across your application portfolio through automated queries.

Getting Started

  1. Install the CLI on your system using your preferred method
  2. Configure authentication with your Escape API key
  3. Learn basic commands to navigate the CLI
  4. Explore practical examples for common security testing workflows

Other Commands

These command groups also support platform administration and automation. Run escape-cli <group> --help for subcommands and escape-cli <group> <command> --help for flags.

Group Commands and Purpose
asm trigger (aliases scan, start) triggers ASM scans; filter with --asset-id.
authentications start reads an authentication-check request from JSON stdin; get <authentication-id> retrieves its status. Both accept --watch.
integrations list, get, create, update, delete. Specify --kind; list also supports --search, --project-id, and --location-id. Create and update read JSON stdin.
jobs trigger-export --block <block-kind> starts a report export; optional --scan-id selects a scan; get <job-id> retrieves its status and result. Both accept --watch.
projects list, get, create, update, delete; list accepts --search. Create and update read JSON stdin.
roles list, get, create, update, delete, bind --role-id <role-id> --user-id <user-id>, unbind <binding-id>. Create and update read JSON stdin.
users me, list, get, invite. List accepts --search; invite accepts repeated --email flags and --role-id. Top-level me also returns the current user.
workflows list, get, create, update, delete. List filters include --trigger, --search, --project-id, --integration-id, and --workflow-id. Create and update read JSON stdin.
stats Organization security statistics.
capabilities Machine-readable command catalog.
help-all, version Full command help and CLI version.
escape-cli asm trigger --asset-id <asset-id>
escape-cli authentications start --input-schema
escape-cli integrations create --kind <integration-kind> --input-schema
escape-cli projects create --input-schema
escape-cli capabilities -o json

Open Source

The Escape CLI is fully open source and available on GitHub. Contributions, issues, and feature requests are welcome.

Support