Escape CLI¶
The Escape CLI is a command-line interface that enables you to automate security testing workflows and integrate Escape's capabilities directly into your development pipeline. The CLI is open source and provides commands and structured output for automation.
Overview¶
Use the CLI to manage assets, run scans, and handle security findings from your terminal or CI/CD environment.
Philosophy¶
The Escape CLI is designed with three core principles:
Automation-First¶
Every command is built to support scripting and automation. The CLI offers machine-readable output formats (JSON, YAML) alongside human-readable tables, making it equally suitable for interactive use and automated workflows.
Pipeline Integration¶
Make security testing part of your development process. The Escape CLI enables you to trigger scans and monitor results in your CI/CD pipelines. Use a quality-gate script to check scan status and findings before failing a build.
Developer Experience¶
Commands follow intuitive patterns with helpful aliases and clear documentation. Whether you're a security engineer or a developer new to security testing, the CLI provides a straightforward interface to Escape's capabilities.
Key Capabilities¶
Security Testing¶
- Start and monitor security scans for REST APIs, GraphQL APIs, and web applications
- Retrieve and analyze security findings in real-time
- Configure scan parameters and override settings programmatically
Asset Management¶
- Create and manage security test profiles for your applications
- Track and organize assets across your infrastructure
- Import assets in bulk from various sources
Private Location Support¶
The CLI enables you to deploy and manage Private Locations, allowing Escape to test applications within your private network while maintaining security and compliance requirements.
CI/CD Integration¶
- Integration with GitHub Actions, GitLab CI, Jenkins, and other CI/CD platforms
- Exit codes and output formats designed for pipeline automation
- Support for commit metadata and build context
Use Cases¶
Continuous Security Testing¶
Integrate security scanning into every pull request or deployment to review and address findings before production.
Asset Discovery and Management¶
Maintain an up-to-date inventory of your APIs and web applications, with automated tracking of new services and endpoints.
Security Operations¶
Automate security workflows, from initial scanning to issue triage and remediation tracking.
Compliance and Reporting¶
Generate security reports and track compliance status across your application portfolio through automated queries.
Getting Started¶
- Install the CLI on your system using your preferred method
- Configure authentication with your Escape API key
- Learn basic commands to navigate the CLI
- Explore practical examples for common security testing workflows
Other Commands¶
These command groups also support platform administration and automation. Run escape-cli <group> --help for subcommands and escape-cli <group> <command> --help for flags.
| Group | Commands and Purpose |
|---|---|
asm |
trigger (aliases scan, start) triggers ASM scans; filter with --asset-id. |
authentications |
start reads an authentication-check request from JSON stdin; get <authentication-id> retrieves its status. Both accept --watch. |
integrations |
list, get, create, update, delete. Specify --kind; list also supports --search, --project-id, and --location-id. Create and update read JSON stdin. |
jobs |
trigger-export --block <block-kind> starts a report export; optional --scan-id selects a scan; get <job-id> retrieves its status and result. Both accept --watch. |
projects |
list, get, create, update, delete; list accepts --search. Create and update read JSON stdin. |
roles |
list, get, create, update, delete, bind --role-id <role-id> --user-id <user-id>, unbind <binding-id>. Create and update read JSON stdin. |
users |
me, list, get, invite. List accepts --search; invite accepts repeated --email flags and --role-id. Top-level me also returns the current user. |
workflows |
list, get, create, update, delete. List filters include --trigger, --search, --project-id, --integration-id, and --workflow-id. Create and update read JSON stdin. |
stats |
Organization security statistics. |
capabilities |
Machine-readable command catalog. |
help-all, version |
Full command help and CLI version. |
escape-cli asm trigger --asset-id <asset-id>
escape-cli authentications start --input-schema
escape-cli integrations create --kind <integration-kind> --input-schema
escape-cli projects create --input-schema
escape-cli capabilities -o json
Open Source¶
The Escape CLI is fully open source and available on GitHub. Contributions, issues, and feature requests are welcome.
Support¶
- Documentation: Browse the sections below for detailed command references and examples
- API Reference: Escape V3 API Documentation
- Community: GitHub Issues