Skip to main content

Client-side code analysis tool for API connections

Project description

Rohkun CLI v2

Client-side code analysis tool that finds API connections in your codebase.

Features

  • 🚀 Fast - All analysis happens locally on your machine
  • 🔒 Private - Your code never leaves your computer
  • 🎯 Accurate - Finds endpoints and API calls across multiple languages
  • 📊 Detailed Reports - Saved locally in .rohkun/reports/
  • 💥 Blast Radius - See impact of code changes
  • 📈 Confidence Scoring - Know how reliable each connection is
  • 🔄 Diff Over Time - Compare reports to track changes
  • High Impact Detection - Find critical nodes in your codebase

Installation

pip install rohkun

Quick Start

  1. Get your API key from rohkun.com/dashboard

  2. Configure the CLI:

rohkun config --api-key YOUR_API_KEY
  1. Run analysis on your project:
rohkun run

Or run on a specific directory:

rohkun run /path/to/project

Note: rohkun scan is still available as an alias for backward compatibility.

How It Works

  1. Authorization Check - CLI checks with server if you have credits
  2. Local Analysis - All code analysis happens on your machine
  3. Snapshot Creation - Each scan automatically creates a snapshot (like Git commits)
  4. Automatic Comparison - Starting from your second scan, automatically compares with previous snapshot
  5. Report Generation - Results saved to .rohkun/reports/
  6. Usage Tracking - CLI reports completion to server for billing

Your code is never uploaded to our servers.

Snapshot Workflow

Think of it like Git commits for your architecture:

  • First scan: Creates Snapshot #1 (baseline)
  • Second scan: Creates Snapshot #2, automatically compares with #1
  • Third scan: Creates Snapshot #3, automatically compares with #2
  • And so on...

Each scan shows you exactly what changed—new endpoints, removed API calls, broken connections, and more.

Commands

Run Analysis

rohkun run [path]

Note: rohkun scan is an alias for rohkun run and works the same way.

Options:

  • path - Project directory to scan (default: current directory)
  • -v, --verbose - Show detailed output including blast radius and confidence scores

Note: Comparison with previous snapshots happens automatically starting from your second scan. No flag needed!

Configure

rohkun config --api-key YOUR_KEY

Set your API key. Saved to .rohkun/config.json in your project.

Version

rohkun --version

Supported Languages

  • Python (Flask, FastAPI, Django)
  • JavaScript/TypeScript (Express, Next.js, React)
  • Go (net/http, Gin, Echo)
  • Java (Spring Boot)
  • And more...

Report Format

Reports are saved as JSON in .rohkun/reports/:

{
  "version": "2.0.0",
  "generated_at": "2024-01-15T10:30:00Z",
  "summary": {
    "total_endpoints": 25,
    "total_api_calls": 18,
    "total_connections": 15,
    "high_confidence_connections": 12,
    "medium_confidence_connections": 2,
    "low_confidence_connections": 1,
    "estimated_accuracy": "High (80%+)",
    "high_impact_nodes": 3
  },
  "endpoints": [...],
  "api_calls": [...],
  "connections": [
    {
      "endpoint": {...},
      "api_call": {...},
      "confidence": "high",
      "confidence_score": 85,
      "confidence_reasons": ["HTTP method matches", "Path matches exactly"]
    }
  ],
  "blast_radius": [
    {
      "target": "GET:/api/users",
      "severity": "high",
      "total_dependents": 15,
      "affected_files": [...],
      "impact_description": "..."
    }
  ],
  "high_impact_nodes": [...],
  "accuracy": {...}
}

Configuration

API Key

Set via command:

rohkun config --api-key YOUR_KEY

Or environment variable:

export ROHKUN_API_KEY=your_key_here

Custom API URL

For self-hosted instances:

export ROHKUN_API_URL=https://your-api.com

Troubleshooting

"No API key found"

rohkun config --api-key YOUR_KEY

"Invalid or expired API key"

Get a new key at rohkun.com/dashboard

"Insufficient credits"

Upgrade your plan at rohkun.com/pricing

Privacy

  • Your code is analyzed locally on your machine
  • Only authorization requests are sent to our servers
  • No code content is ever uploaded
  • Reports are saved locally in your project

Support

License

MIT License - see LICENSE file for details

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

rohkun-2.1.1.tar.gz (42.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

rohkun-2.1.1-py3-none-any.whl (49.2 kB view details)

Uploaded Python 3

File details

Details for the file rohkun-2.1.1.tar.gz.

File metadata

  • Download URL: rohkun-2.1.1.tar.gz
  • Upload date:
  • Size: 42.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.0

File hashes

Hashes for rohkun-2.1.1.tar.gz
Algorithm Hash digest
SHA256 778cbfd2ee46d1d4fb5662a37a2bfac553d437f6cc65fcc353398449e5dbda37
MD5 e2082fd966237e9308751253f6de9b27
BLAKE2b-256 f186bc580a6bd66fdae2f7e826a30c96c628f166e06ee9b722af5f63f2749f35

See more details on using hashes here.

File details

Details for the file rohkun-2.1.1-py3-none-any.whl.

File metadata

  • Download URL: rohkun-2.1.1-py3-none-any.whl
  • Upload date:
  • Size: 49.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.0

File hashes

Hashes for rohkun-2.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 fafbabc72fb1e1484d465b9fc3da5f6250bb621d590d778d9b5a87373b9ac84f
MD5 53afaff8c6dc0098df8b1587cc437ad3
BLAKE2b-256 c5d8dc1beb90455780e548aecccb294d0510fb00bf9407ddc4effe6e4f5e900d

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page