> ## Documentation Index
> Fetch the complete documentation index at: https://docs.jsmon.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# CLI Tool

> The official command-line tool for Jsmon. Scan URLs, domains, and source code, upload files, and explore reconnaissance and vulnerability data from your terminal.

The official command-line tool for [Jsmon](https://jsmon.sh). Scan URLs, domains, and source code, upload files, and explore reconnaissance and vulnerability data from your terminal.

## Quick Start

1. **Install** the CLI (see [Installation](#installation)).
2. **Set your API key** (flag, file, or env — see [Configuration](#configuration)).
3. **Create or pick a workspace**, then start scanning.

```bash theme={null}
# Create a workspace
jsmon -cw "My Project" -key YOUR_API_KEY

# Scan a URL (use the workspace ID from the previous command)
jsmon -u "https://example.com/app.js" -wksp YOUR_WORKSPACE_ID

# List reconnaissance data (e.g. emails)
jsmon -recon "field=emails page=1" -wksp YOUR_WORKSPACE_ID
```

## Installation

### Option 1: Install from Go (recommended)

```bash theme={null}
go install github.com/jsmonhq/jsmon-cli/v2/cmd/jsmon@latest
```

Ensure your Go `bin` directory is in your `PATH` (e.g. `$HOME/go/bin`). The installed command is `jsmon`.

### Option 2: Build from source

```bash theme={null}
git clone https://github.com/jsmonhq/jsmon-cli.git
cd jsmon-cli
go build -o jsmon ./cmd/jsmon
```

This creates a local `jsmon` binary from source.

## Configuration

### API Key

Get your API key from [Jsmon Settings](https://app.jsmon.sh/settings). The CLI looks for it in this order:

| Priority | Source |
| - | - |
| 1 | `-key YOUR_API_KEY` |
| 2 | File: `~/.jsmon/credentials` |
| 3 | Environment: `JSMON_API_KEY` |

**Credentials file:** Create `~/.jsmon/credentials` and put your API key on the first line (no label). Lines starting with `#` are ignored.

### Workspace ID

For scanning and data commands you need a **workspace ID**:

* Pass it with `-wksp YOUR_WORKSPACE_ID`, or
* Set `JSMON_WORKSPACE_ID` in your environment.

The workspace ID is **not** read from the credentials file; it must be provided per command or via env.

### Optional Flags

* `-H "Header-Name: value"` — Add custom HTTP headers for scan requests (can be used multiple times).
* `-silent` — Hide the Jsmon logo when running commands.
* `-depth 1..4` / `-scan-depth 1..4` — Control domain scan depth.
* `-wafbypass` / `-waf-bypass` — Enable WAF bypass for URL, domain, and file scans.
* `-keywords "api,admin"` / `-scan-keywords "api,admin"` — Add domain scan keywords.
* `-extensions "js,json"` / `-scan-extensions "js,json"` — Limit domain scans to supported extensions.

<Info>
  Scan commands submit work to Jsmon's asynchronous pipeline. The CLI prints the queued `runId` and `version`; use those values with read commands when you want run-scoped or version-specific results.
</Info>

## Commands Overview

```text theme={null}
Usage: jsmon [OPTIONS]

Input:
  -u <input>                                  Input URL to scan
  -d <input>                                  Input domain to scan
  -cs <input> | -code-scan <input>            Input source code file to scan
  -f <input>                                  Upload a URL list file for server-side file scan
  -cw <input> | --create-workspace <input>    Create a new workspace

Configuration:
  -key <input>                                API key
  -wksp <wksp id>                             Workspace ID to scan the target
  -runId <id>                                 Existing run ID for rescan or run-scoped counts
  -depth <1..4> | -scan-depth <1..4>          Optional scan depth for domain scans
  -wafbypass | -waf-bypass                    Enable WAF bypass
  -keywords <a,b> | -scan-keywords <a,b>      Optional domain scan keywords
  -extensions <a,b> | -scan-extensions <a,b>  Optional domain scan extensions
  -H <input>                                  Custom HTTP headers
  -silent                                     Silent the logo
  -up, --update                               Check for updates
  -duc, --disable-update-check                Disable automatic update check on startup

Scans:
  -count                                      Show counts of recon data and secrets
  --urls "page=<n> limit=<n>"                 Fetch all scanned URLs
  --domains "page=<n> limit=<n>"              Fetch all scanned domains
  --files "page=<n> limit=<n>"                Fetch all scanned files

Data:
  -workspaces                                 Fetch all workspaces
  -issues "page=<n> limit=<n> ..."            Fetch dashboard vulnerabilities
  -secrets "page=<n> limit=<n> ..."           Fetch all secrets for a workspace
  -recon "field=<name> page=<n> limit=<n>"    Fetch reconnaissance data

Reverse Search:
  -rsearch "<field>=<value>"                  Search the source of a result

Filter:
  -filters "<field>=<keyword> page=<n>"       Match keywords in recon results
```

## Scanning

### Upload a single URL

```bash theme={null}
jsmon -u "https://example.com/script.js" -wksp YOUR_WORKSPACE_ID
```

### Scan a domain

```bash theme={null}
jsmon -d "example.com" -wksp YOUR_WORKSPACE_ID
jsmon -d "example.com" -depth 3 -wksp YOUR_WORKSPACE_ID
jsmon -d "example.com" -depth 3 -keywords "api,admin" -extensions "js,json" -wksp YOUR_WORKSPACE_ID
jsmon -d "example.com" -wafbypass -wksp YOUR_WORKSPACE_ID
```

`-depth`, `-keywords`, and `-extensions` are domain-scan only. Supported extension values are `html`, `php`, `txt`, `js`, `xml`, `json`, `map`, `xhtml`, and `aspx`.

### Upload a source code file

```bash theme={null}
jsmon -cs app.js -wksp YOUR_WORKSPACE_ID
```

### Upload multiple URLs from a file

Put one URL per line in a file, then submit the file to Jsmon's server-side file scan:

```bash theme={null}
jsmon -f urls.txt -wksp YOUR_WORKSPACE_ID
jsmon -f urls.txt -wafbypass -wksp YOUR_WORKSPACE_ID
```

The response includes `runId` and `version`. Re-submit the file if a queued file scan fails before processing.

## Viewing Data

### Workspaces

```bash theme={null}
jsmon -workspaces -key YOUR_API_KEY
```

### Scanned URLs, domains, and files

```bash theme={null}
jsmon --urls "page=1 limit=50" -wksp YOUR_WORKSPACE_ID
jsmon --domains "page=1 limit=50" -wksp YOUR_WORKSPACE_ID
jsmon --files "page=1 limit=50" -wksp YOUR_WORKSPACE_ID
```

Default is `page=1` and `limit=100` if omitted. (Max limit: 5000 per page)

### Secrets

```bash theme={null}
jsmon -secrets "page=1 limit=100" -wksp YOUR_WORKSPACE_ID
```

### Dashboard vulnerabilities

```bash theme={null}
jsmon -issues "page=1 limit=20" -wksp YOUR_WORKSPACE_ID
jsmon -issues "page=1 limit=20 severity=critical,high dateFrom=2026-04-01 dateTo=2026-04-14" -wksp YOUR_WORKSPACE_ID
```

The `-issues` command mirrors the dashboard vulnerability table and returns `data`, `severityCount`, and `pagination`.

### Count summary

```bash theme={null}
jsmon -count -wksp YOUR_WORKSPACE_ID
```

Optional: add `-runId RUN_ID` for a specific run.

## Reconnaissance & Filters

### Fetch reconnaissance data

Get extracted intelligence for a **field** and optional pagination:

```bash theme={null}
jsmon -recon "field=emails page=1 limit=50" -wksp YOUR_WORKSPACE_ID
```

**Common fields:** `apiPaths`, `urls`/`jsurls` (scanned URLs), `extractedUrls`, `extractedDomains`, `expiredDomains`, `ip`, `emails`, `s3Buckets`, `gqlQueries`, `gqlMutations`, `gqlFragments`, `param`, `allAwsAssets`, `npmPackages`, `socialUrls`, `portUrls`, `extensionUrls`, and others (see `jsmon -h`).

Add `runId=<id>` to scope results to one scan. Add `version=<n>` with `runId` to inspect a specific monitoring/rescan version.

### Filter by keyword

Search within a field (e.g. only URLs containing "github"):

```bash theme={null}
jsmon -filters "urls=github.com page=1" -wksp YOUR_WORKSPACE_ID
jsmon -filters "param=github page=1" -wksp YOUR_WORKSPACE_ID
```

Format: `"fieldname=keyword page=N limit=N"`. Defaults: `page=1`, `limit=100`.

## Reverse Search

Find where a value came from (e.g. which script exposes an API path):

```bash theme={null}
jsmon -rsearch "apipaths=@azure/msal-browser" -wksp YOUR_WORKSPACE_ID
jsmon -rsearch "extractedDomains=blogs.jsmon.sh" -wksp YOUR_WORKSPACE_ID
```

Format: `"fieldname=value"`. Use **extractedDomains** (not `domains`) for domain reverse search.

## Advanced Scan Options

```bash theme={null}
# URL scan with WAF bypass
jsmon -u "https://example.com/app.js" -wafbypass -wksp YOUR_WORKSPACE_ID

# Domain scan with depth, keywords, extensions, and WAF bypass
jsmon -d "example.com" -depth 3 -keywords "api,admin" -extensions "js,json" -wafbypass -wksp YOUR_WORKSPACE_ID

# File scan with WAF bypass
jsmon -f urls.txt -wafbypass -wksp YOUR_WORKSPACE_ID
```

Allowed extensions: `html`, `php`, `txt`, `js`, `xml`, `json`, `map`, `xhtml`, `aspx`.

## Updates

* **Automatic:** On startup the CLI checks for a newer release and prints a message if one exists (no auto-download).
* **Manual check:** `jsmon -up` or `jsmon --update` to check and see the install command.
* **Disable startup check:** `jsmon -duc` or `jsmon --disable-update-check`.

To upgrade after a new release:

```bash theme={null}
go install github.com/jsmonhq/jsmon-cli/v2/cmd/jsmon@latest
```

## Field Names Reference

### For `-recon` and `-rsearch`:

`apiPaths`, `urls`/`jsurls` (scanned URLs), `extractedUrls`, `extractedDomains`, `ip`, `emails`, `s3Buckets`, `s3takeovers`, `gqlQueries`, `gqlMutations`, `gqlMutaions`, `gqlFragments`, `param` (extracted parameter), `npmPackages`, `npmConfusion`, `guids`, `localhost`, `expiredDomains`, `allAwsAssets`, `socialUrls`, `portUrls`, `extensionUrls`

### For `-filters`:

`jsurls`, `apiPaths`, `urls`, `emails`, `gqlQueries`, `gqlMutations`, `gqlMutaions`, `sqlFragments`, `param` (extracted parameter)

## Examples

```bash theme={null}
# Create workspace
jsmon -cw "My Project" -key YOUR_API_KEY

# Scan targets
jsmon -u "https://example.com/script.js" -wksp YOUR_WORKSPACE_ID
jsmon -u "https://example.com/script.js" -wafbypass -wksp YOUR_WORKSPACE_ID
jsmon -d "example.com" -wksp YOUR_WORKSPACE_ID
jsmon -d "example.com" -depth 2 -wksp YOUR_WORKSPACE_ID
jsmon -d "example.com" -depth 3 -keywords "api,admin" -extensions "js,json" -wafbypass -wksp YOUR_WORKSPACE_ID
jsmon -cs app.js -wksp YOUR_WORKSPACE_ID
jsmon -f urls.txt -wksp YOUR_WORKSPACE_ID

# Use credentials file (no -key needed)
jsmon -u "https://example.com/script.js" -wksp YOUR_WORKSPACE_ID

# Reconnaissance
jsmon -recon "field=emails page=1" -wksp YOUR_WORKSPACE_ID
jsmon -recon "field=allAwsAssets page=1" -wksp YOUR_WORKSPACE_ID
jsmon -issues "page=1 limit=20 severity=critical,high" -wksp YOUR_WORKSPACE_ID

# Filter and reverse search
jsmon -filters "urls=api page=1" -wksp YOUR_WORKSPACE_ID
jsmon -rsearch "apipaths=/auth/login" -wksp YOUR_WORKSPACE_ID
```

## Links

* **GitHub:** [github.com/jsmonhq/jsmon-cli](https://github.com/jsmonhq/jsmon-cli)
* **Jsmon:** [jsmon.sh](https://jsmon.sh)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.