Quick Start
- Install the CLI (see Installation).
- Set your API key (flag, file, or env — see Configuration).
- Create or pick a workspace, then start scanning.
Installation
Option 1: Install from Go (recommended)
bin directory is in your PATH (e.g. $HOME/go/bin). The installed command is jsmon.
Option 2: Build from source
jsmon binary from source.
Configuration
API Key
Get your API key from Jsmon Settings. The CLI looks for it in this order:
Credentials file: Create
~/.jsmon/credentials and put your API key on the first line (no label). Lines starting with # are ignored.
Workspace ID
For scanning and data commands you need a workspace ID:- Pass it with
-wksp YOUR_WORKSPACE_ID, or - Set
JSMON_WORKSPACE_IDin your environment.
Optional Flags
-H "Header-Name: value"— Add custom HTTP headers for scan requests (can be used multiple times).-silent— Hide the Jsmon logo when running commands.-depth 1..4/-scan-depth 1..4— Control domain scan depth.-wafbypass/-waf-bypass— Enable WAF bypass for URL, domain, and file scans.-keywords "api,admin"/-scan-keywords "api,admin"— Add domain scan keywords.-extensions "js,json"/-scan-extensions "js,json"— Limit domain scans to supported extensions.
Scan commands submit work to Jsmon’s asynchronous pipeline. The CLI prints the queued
runId and version; use those values with read commands when you want run-scoped or version-specific results.Commands Overview
Scanning
Upload a single URL
Scan a domain
-depth, -keywords, and -extensions are domain-scan only. Supported extension values are html, php, txt, js, xml, json, map, xhtml, and aspx.
Upload a source code file
Upload multiple URLs from a file
Put one URL per line in a file, then submit the file to Jsmon’s server-side file scan:runId and version. Re-submit the file if a queued file scan fails before processing.
Viewing Data
Workspaces
Scanned URLs, domains, and files
page=1 and limit=100 if omitted. (Max limit: 5000 per page)
Secrets
Dashboard vulnerabilities
-issues command mirrors the dashboard vulnerability table and returns data, severityCount, and pagination.
Count summary
-runId RUN_ID for a specific run.
Reconnaissance & Filters
Fetch reconnaissance data
Get extracted intelligence for a field and optional pagination:apiPaths, urls/jsurls (scanned URLs), extractedUrls, extractedDomains, expiredDomains, ip, emails, s3Buckets, gqlQueries, gqlMutations, gqlFragments, param, allAwsAssets, npmPackages, socialUrls, portUrls, extensionUrls, and others (see jsmon -h).
Add runId=<id> to scope results to one scan. Add version=<n> with runId to inspect a specific monitoring/rescan version.
Filter by keyword
Search within a field (e.g. only URLs containing “github”):"fieldname=keyword page=N limit=N". Defaults: page=1, limit=100.
Reverse Search
Find where a value came from (e.g. which script exposes an API path):"fieldname=value". Use extractedDomains (not domains) for domain reverse search.
Advanced Scan Options
html, php, txt, js, xml, json, map, xhtml, aspx.
Updates
- Automatic: On startup the CLI checks for a newer release and prints a message if one exists (no auto-download).
- Manual check:
jsmon -uporjsmon --updateto check and see the install command. - Disable startup check:
jsmon -ducorjsmon --disable-update-check.
Field Names Reference
For -recon and -rsearch:
apiPaths, urls/jsurls (scanned URLs), extractedUrls, extractedDomains, ip, emails, s3Buckets, s3takeovers, gqlQueries, gqlMutations, gqlMutaions, gqlFragments, param (extracted parameter), npmPackages, npmConfusion, guids, localhost, expiredDomains, allAwsAssets, socialUrls, portUrls, extensionUrls
For -filters:
jsurls, apiPaths, urls, emails, gqlQueries, gqlMutations, gqlMutaions, sqlFragments, param (extracted parameter)
Examples
Links
- GitHub: github.com/jsmonhq/jsmon-cli
- Jsmon: jsmon.sh

