liveapisec — CLI/SDK for the LiveAPISec Developer API
Official, thin client for the LiveAPISec Developer API. Install it once, use it in any project, script and CI/CD pipeline — no dashboard, no curl.
When to use this? Instead of walking through the wizard in the dashboard, a developer pushes endpoints + an optional token from their own environment (CI/CD, agent, script). The token is generated on your side and encrypted server-side (AES-256). Tip: no token = we only test what's public.
Installation
One command (Linux / macOS) — recommended
curl -fsSL https://raw.githubusercontent.com/LiveApiSec/liveapisec/main/install.sh | bash
The installer uses pipx when available, otherwise it creates an isolated
virtualenv and symlinks the command into ~/.local/bin — no sudo, and it
works on PEP 668 systems (Ubuntu 24.04+) where a plain pip install is
blocked. After installing, open a new terminal and run liveapisec --help.
From PyPI (recommended for developers with pipx/venv)
pipx install liveapisec # or: pip install liveapisec (inside a venv)
From GitHub (if you prefer building from the repository)
pip install "liveapisec @ git+https://github.com/LiveApiSec/liveapisec.git"
Verify:
liveapisec --help
Install once (e.g. in a CI image, on a dev machine, in GitHub Actions) and the
liveapisec command is available in every project on that machine.
Configuration
Generate an API key once in the dashboard: Settings → Developer API → Create API key
(the las_dev_... key is shown only once — store it as a secret).
First run (interactive)
The first time you run a command that needs the API (e.g. push, scan), the CLI
asks for your key, shows you exactly where to find it, and saves it to
~/.config/liveapisec/config.json (mode 0600). Next runs pick it up automatically:
$ liveapisec push --name my-api --base-url https://api.example.com ...
No LiveAPISec API key found.
Generate one in the dashboard: Settings → Developer API → Create API key
https://liveapisec.com/settings
The key looks like: las_dev_...
Tip: no key = only public endpoints can be tested.
Paste your API key: las_dev_...
✓ API key saved to /home/you/.config/liveapisec/config.json
Environment variables (recommended for CI)
export LIVEAPISEC_API_KEY=las_dev_... # required
export LIVEAPISEC_API_URL=https://liveapisec.com # optional (default)
Precedence: --api-key / --api-url flags → environment variables →
saved config file.
Manage the saved key
liveapisec config # show where the key is stored
liveapisec config --clear # remove the saved config file
Commands
1. push — push your API (idempotent, safe in CI)
liveapisec push \
--name my-api \
--base-url https://api.example.com \
--endpoint "GET /users" \
--endpoint "POST /payments"
- The same
name+base_url= the same site (update, not a duplicate) — you can call push in every build. - Instead of a list of endpoints you can provide an OpenAPI spec:
--openapi-url https://api.example.com/openapi.json. - Optional token:
--auth-type jwt --auth-token <TOKEN>(orbearer,cookie --auth-cookie "session=...",api_key --auth-header X-API-Key).
Output:
site 65f...abc: my-api — 2 endpoints, auth=none
export SITE_ID=65f...abc
2. push-code — scan your source code and push the endpoints
Point the CLI at a repo/folder and it detects the framework, extracts the API endpoints from the code and pushes them — no running site or OpenAPI spec needed.
cd my-project
liveapisec push-code --dir . --name my-api --base-url https://api.example.com
- Auto-detected frameworks: FastAPI, Flask, Next.js (
app/api+pages/api), Laravel, and generic PHP ($app->get, Slim, Lumen). - Preview before pushing (no API key needed):
liveapisec push-code --dir . --name my-api --base-url https://api.example.com --dry-run
liveapisec push-code --dir . --name my-api --base-url https://api.example.com --dry-run --json
- Force a framework if auto-detection misses it:
--framework nextjs.
Output:
framework: fastapi (42 files scanned)
found 58 endpoints:
GET /users
POST /payments
site 65f...abc: my-api — 58 endpoints, auth=none
export SITE_ID=65f...abc
3. scan — run a security test
# fire and forget (202, does not wait)
liveapisec scan --site SITE_ID --branch main --commit "$GITHUB_SHA"
# wait for the result and fail the build on high (CI gate)
liveapisec scan --site SITE_ID --branch main --commit "$SHA" \
--wait --fail-on high
--wait— polls until the scan finishes (default timeout 600 s, interval 3 s; change with--timeout/--poll-interval).--fail-on high— exit code 1 when a finding of severityhigh/criticalis found;--fail-on criticalonly for criticals; omit it → always exit 0 (except errors).
4. status — site status + recent scans
liveapisec status --site SITE_ID
5. findings — scan results
liveapisec findings --site SITE_ID --scan SCAN_ID
liveapisec findings --site SITE_ID --scan SCAN_ID --json # raw data (for agents/AI)
6. sites — site details
liveapisec sites --site SITE_ID
GitHub Actions — full example (gate on push)
name: liveapisec
on: push
jobs:
security-test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with: { python-version: "3.12" }
- name: Install CLI
run: pip install "liveapisec @ git+https://github.com/LiveApiSec/liveapisec.git"
- name: Push API + run security test (gate on high)
env:
LIVEAPISEC_API_KEY: ${{ secrets.LIVEAPISEC_KEY }}
run: |
liveapisec push --name my-api --base-url "$BASE_URL" \
--endpoint "GET /users" --endpoint "POST /payments"
liveapisec scan --site "$SITE_ID" \
--branch "${GITHUB_REF#refs/heads/}" --commit "$GITHUB_SHA" \
--wait --fail-on high
Why is push safe? Push is idempotent (name+base_url → the same site), so the next build does not create junk — it updates endpoints and the token, and the next
scantests the latest state.
Exit codes
| Code | Meaning |
|---|---|
| 0 | OK (no findings at/above the threshold, or no --fail-on) |
| 1 | Gate failed — findings found at/above --fail-on |
| 2 | Usage error / API error / missing key |
Development / tests
pip install -e ./cli[dev]
cd cli && python -m pytest tests/ -q
SDK (API)
Besides the CLI, the package also exports a client for scripts:
from liveapisec import LiveAPISec
api = LiveAPISec() # LIVEAPISEC_API_KEY from env
site = api.create_site("my-api", "https://api.example.com",
endpoints=[{"method": "GET", "path": "/users"}])
scan = api.trigger_scan(site["site_id"], branch="main", commit="abc")
done = api.wait_for_scan(site["site_id"], scan["scan_id"])
blocked = LiveAPISec.findings_above(done["findings"], "high")
Instructions for AI coding assistants (Copilot, Cursor, etc.)
Copy-paste the block below into your AI assistant (GitHub Copilot, Cursor, Windsurf…) to let it use the LiveAPISec CLI on your behalf.
You can use the `liveapisec` CLI (https://pypi.org/project/liveapisec/) to
push API specifications and run security scans against the LiveAPISec platform.
Environment:
- `LIVEAPISEC_API_KEY` — dev API key (las_dev_...), usually already set.
- `LIVEAPISEC_API_URL` — API base URL (default: https://liveapisec.com).
- `SITE_ID` — the site id returned by `liveapisec push` / `liveapisec sites`.
Workflow:
1. Push the API under test (idempotent — safe to repeat):
`liveapisec push --name <name> --base-url <url> --endpoint "METHOD /path" [--endpoint ...] [--openapi-url <url>] [--auth-type jwt|bearer|cookie|api_key --auth-token <token>]`
2. Read the site id from the output (or `liveapisec sites --site <id>`).
3. Run a security scan and wait for the result:
`liveapisec scan --site <site_id> --branch <branch> --commit <sha> --wait`
4. Read findings:
`liveapisec findings --site <site_id> --scan <scan_id>` (add `--json` for raw JSON).
5. Check site status: `liveapisec status --site <site_id>`.
Rules:
- Never print or commit the API key; use the environment variable.
- If a scan fails, read `liveapisec findings --site <id> --scan <scan_id> --json`
and summarize each finding (severity, title, target).
- Push is idempotent, so re-running it is always safe.
- Exit code 1 from `scan --wait --fail-on <sev>` means the gate failed
(findings at/above that severity); exit 2 means usage/API error.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file liveapisec-0.1.3.tar.gz.
File metadata
- Download URL: liveapisec-0.1.3.tar.gz
- Upload date:
- Size: 24.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a59a38718a3f7165700cea4127d232d7a5e0b1ce7ac5a6f2c2c3c4107ffd821a
|
|
| MD5 |
880c960172db69b522d687667121e140
|
|
| BLAKE2b-256 |
355b93f2b040e1e6658c19498de8a1c56d45d8ca6f48fc5317438956b79369c0
|
File details
Details for the file liveapisec-0.1.3-py3-none-any.whl.
File metadata
- Download URL: liveapisec-0.1.3-py3-none-any.whl
- Upload date:
- Size: 17.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
d80450e315728e8e8e8642560dc7e105fb3d0197f249b073953606fa7b41a9b0
|
|
| MD5 |
6d1029819e16abd6affda04e81585eed
|
|
| BLAKE2b-256 |
010ad7fdb7e6ff5f6bc0523bc10593928272d230f699cb5dd458c9f317a7ded2
|