Skip to main content
The official command-line tool for Jsmon. Scan URLs, domains, and source code, upload files, and explore reconnaissance and vulnerability data from your terminal.

Quick Start

  1. Install the CLI (see Installation).
  2. Set your API key (flag, file, or env — see Configuration).
  3. Create or pick a workspace, then start scanning.

Installation

Ensure your Go bin directory is in your PATH (e.g. $HOME/go/bin). The installed command is jsmon.

Option 2: Build from source

This creates a local jsmon binary from source.

Configuration

API Key

Get your API key from Jsmon Settings. The CLI looks for it in this order: Credentials file: Create ~/.jsmon/credentials and put your API key on the first line (no label). Lines starting with # are ignored.

Workspace ID

For scanning and data commands you need a workspace ID:
  • Pass it with -wksp YOUR_WORKSPACE_ID, or
  • Set JSMON_WORKSPACE_ID in your environment.
The workspace ID is not read from the credentials file; it must be provided per command or via env.

Optional Flags

  • -H "Header-Name: value" — Add custom HTTP headers for scan requests (can be used multiple times).
  • -silent — Hide the Jsmon logo when running commands.
  • -depth 1..4 / -scan-depth 1..4 — Control domain scan depth.
  • -wafbypass / -waf-bypass — Enable WAF bypass for URL, domain, and file scans.
  • -keywords "api,admin" / -scan-keywords "api,admin" — Add domain scan keywords.
  • -extensions "js,json" / -scan-extensions "js,json" — Limit domain scans to supported extensions.
Scan commands submit work to Jsmon’s asynchronous pipeline. The CLI prints the queued runId and version; use those values with read commands when you want run-scoped or version-specific results.

Commands Overview

Scanning

Upload a single URL

Scan a domain

-depth, -keywords, and -extensions are domain-scan only. Supported extension values are html, php, txt, js, xml, json, map, xhtml, and aspx.

Upload a source code file

Upload multiple URLs from a file

Put one URL per line in a file, then submit the file to Jsmon’s server-side file scan:
The response includes runId and version. Re-submit the file if a queued file scan fails before processing.

Viewing Data

Workspaces

Scanned URLs, domains, and files

Default is page=1 and limit=100 if omitted. (Max limit: 5000 per page)

Secrets

Dashboard vulnerabilities

The -issues command mirrors the dashboard vulnerability table and returns data, severityCount, and pagination.

Count summary

Optional: add -runId RUN_ID for a specific run.

Reconnaissance & Filters

Fetch reconnaissance data

Get extracted intelligence for a field and optional pagination:
Common fields: apiPaths, urls/jsurls (scanned URLs), extractedUrls, extractedDomains, expiredDomains, ip, emails, s3Buckets, gqlQueries, gqlMutations, gqlFragments, param, allAwsAssets, npmPackages, socialUrls, portUrls, extensionUrls, and others (see jsmon -h). Add runId=<id> to scope results to one scan. Add version=<n> with runId to inspect a specific monitoring/rescan version.

Filter by keyword

Search within a field (e.g. only URLs containing “github”):
Format: "fieldname=keyword page=N limit=N". Defaults: page=1, limit=100. Find where a value came from (e.g. which script exposes an API path):
Format: "fieldname=value". Use extractedDomains (not domains) for domain reverse search.

Advanced Scan Options

Allowed extensions: html, php, txt, js, xml, json, map, xhtml, aspx.

Updates

  • Automatic: On startup the CLI checks for a newer release and prints a message if one exists (no auto-download).
  • Manual check: jsmon -up or jsmon --update to check and see the install command.
  • Disable startup check: jsmon -duc or jsmon --disable-update-check.
To upgrade after a new release:

Field Names Reference

For -recon and -rsearch:

apiPaths, urls/jsurls (scanned URLs), extractedUrls, extractedDomains, ip, emails, s3Buckets, s3takeovers, gqlQueries, gqlMutations, gqlMutaions, gqlFragments, param (extracted parameter), npmPackages, npmConfusion, guids, localhost, expiredDomains, allAwsAssets, socialUrls, portUrls, extensionUrls

For -filters:

jsurls, apiPaths, urls, emails, gqlQueries, gqlMutations, gqlMutaions, sqlFragments, param (extracted parameter)

Examples