Skip to main content

Client-side code analysis tool for API connections

Project description

Rohkun CLI v2

Client-side code analysis tool that finds API connections in your codebase.

Features

  • 🚀 Fast - All analysis happens locally on your machine
  • 🔒 Private - Your code never leaves your computer
  • 🎯 Accurate - Finds endpoints and API calls across multiple languages
  • 📊 Detailed Reports - Saved locally in .rohkun/reports/
  • 💥 Blast Radius - See impact of code changes
  • 📈 Confidence Scoring - Know how reliable each connection is
  • 🔄 Diff Over Time - Compare reports to track changes
  • High Impact Detection - Find critical nodes in your codebase

Installation

pip install rohkun

Quick Start

  1. Get your API key from rohkun.com/dashboard

  2. Configure the CLI:

rohkun config --api-key YOUR_API_KEY
  1. Run analysis on your project:
rohkun run

Or run on a specific directory:

rohkun run /path/to/project

Note: rohkun scan is still available as an alias for backward compatibility.

How It Works

  1. Authorization Check - CLI checks with server if you have credits
  2. Local Analysis - All code analysis happens on your machine
  3. Snapshot Creation - Each scan automatically creates a snapshot (like Git commits)
  4. Automatic Comparison - Starting from your second scan, automatically compares with previous snapshot
  5. Report Generation - Results saved to .rohkun/reports/
  6. Usage Tracking - CLI reports completion to server for billing

Your code is never uploaded to our servers.

Snapshot Workflow

Think of it like Git commits for your architecture:

  • First scan: Creates Snapshot #1 (baseline)
  • Second scan: Creates Snapshot #2, automatically compares with #1
  • Third scan: Creates Snapshot #3, automatically compares with #2
  • And so on...

Each scan shows you exactly what changed—new endpoints, removed API calls, broken connections, and more.

Commands

Run Analysis

rohkun run [path]

Note: rohkun scan is an alias for rohkun run and works the same way.

Options:

  • path - Project directory to scan (default: current directory)
  • -v, --verbose - Show detailed output including blast radius and confidence scores

Note: Comparison with previous snapshots happens automatically starting from your second scan. No flag needed!

Configure

rohkun config --api-key YOUR_KEY

Set your API key. Saved to .rohkun/config.json in your project.

Version

rohkun --version

Supported Languages

  • Python (Flask, FastAPI, Django)
  • JavaScript/TypeScript (Express, Next.js, React)
  • Go (net/http, Gin, Echo)
  • Java (Spring Boot)
  • And more...

Report Format

Reports are saved as JSON in .rohkun/reports/:

{
  "version": "2.0.0",
  "generated_at": "2024-01-15T10:30:00Z",
  "summary": {
    "total_endpoints": 25,
    "total_api_calls": 18,
    "total_connections": 15,
    "high_confidence_connections": 12,
    "medium_confidence_connections": 2,
    "low_confidence_connections": 1,
    "estimated_accuracy": "High (80%+)",
    "high_impact_nodes": 3
  },
  "endpoints": [...],
  "api_calls": [...],
  "connections": [
    {
      "endpoint": {...},
      "api_call": {...},
      "confidence": "high",
      "confidence_score": 85,
      "confidence_reasons": ["HTTP method matches", "Path matches exactly"]
    }
  ],
  "blast_radius": [
    {
      "target": "GET:/api/users",
      "severity": "high",
      "total_dependents": 15,
      "affected_files": [...],
      "impact_description": "..."
    }
  ],
  "high_impact_nodes": [...],
  "accuracy": {...}
}

Configuration

API Key

Set via command:

rohkun config --api-key YOUR_KEY

Or environment variable:

export ROHKUN_API_KEY=your_key_here

Custom API URL

For self-hosted instances:

export ROHKUN_API_URL=https://your-api.com

Troubleshooting

"No API key found"

rohkun config --api-key YOUR_KEY

"Invalid or expired API key"

Get a new key at rohkun.com/dashboard

"Insufficient credits"

Upgrade your plan at rohkun.com/pricing

Privacy

  • Your code is analyzed locally on your machine
  • Only authorization requests are sent to our servers
  • No code content is ever uploaded
  • Reports are saved locally in your project

Support

License

MIT License - see LICENSE file for details

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

rohkun-2.1.2.tar.gz (42.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

rohkun-2.1.2-py3-none-any.whl (49.2 kB view details)

Uploaded Python 3

File details

Details for the file rohkun-2.1.2.tar.gz.

File metadata

  • Download URL: rohkun-2.1.2.tar.gz
  • Upload date:
  • Size: 42.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.0

File hashes

Hashes for rohkun-2.1.2.tar.gz
Algorithm Hash digest
SHA256 a52b2e11b3dec9d544b8ea5e11a022b6c1a51528967709dcd17ab80e8e4df42c
MD5 fadb36f984e6956ddfac868b2269f49f
BLAKE2b-256 e18705ffff74fd755eb8fdd2b4ca52701a5bd599de36d84a34998ed028f18a95

See more details on using hashes here.

File details

Details for the file rohkun-2.1.2-py3-none-any.whl.

File metadata

  • Download URL: rohkun-2.1.2-py3-none-any.whl
  • Upload date:
  • Size: 49.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.0

File hashes

Hashes for rohkun-2.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 c1d1c5ee47bae6563119fcb70d6a5990bb9527966a7962f5a4391bc254245454
MD5 43e90b6f55b204f8ac0e1e28dffef403
BLAKE2b-256 c1600f6d862680f7179eafc3cb0558dc228f99bf4cefb197537035eebf520f6b

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page