Skip to main content

Client-side code analysis tool for API connections

Project description

Rohkun CLI v2

Client-side code analysis tool that finds API connections in your codebase.

Features

  • 🚀 Fast - All analysis happens locally on your machine
  • 🔒 Private - Your code never leaves your computer
  • 🎯 Accurate - Finds endpoints and API calls across multiple languages
  • 📊 Detailed Reports - Saved locally in .rohkun/reports/
  • 💥 Blast Radius - See impact of code changes
  • 📈 Confidence Scoring - Know how reliable each connection is
  • 🔄 Diff Over Time - Compare reports to track changes
  • High Impact Detection - Find critical nodes in your codebase

Installation

pip install rohkun

Quick Start

  1. Get your API key from rohkun.com/dashboard

  2. Configure the CLI:

rohkun config --api-key YOUR_API_KEY
  1. Run analysis on your project:
rohkun run

Or run on a specific directory:

rohkun run /path/to/project

Note: rohkun scan is still available as an alias for backward compatibility.

How It Works

  1. Authorization Check - CLI checks with server if you have credits
  2. Local Analysis - All code analysis happens on your machine
  3. Snapshot Creation - Each scan automatically creates a snapshot (like Git commits)
  4. Automatic Comparison - Starting from your second scan, automatically compares with previous snapshot
  5. Report Generation - Results saved to .rohkun/reports/
  6. Usage Tracking - CLI reports completion to server for billing

Your code is never uploaded to our servers.

Snapshot Workflow

Think of it like Git commits for your architecture:

  • First scan: Creates Snapshot #1 (baseline)
  • Second scan: Creates Snapshot #2, automatically compares with #1
  • Third scan: Creates Snapshot #3, automatically compares with #2
  • And so on...

Each scan shows you exactly what changed—new endpoints, removed API calls, broken connections, and more.

Commands

Run Analysis

rohkun run [path]

Note: rohkun scan is an alias for rohkun run and works the same way.

Options:

  • path - Project directory to scan (default: current directory)
  • -v, --verbose - Show detailed output including blast radius and confidence scores

Note: Comparison with previous snapshots happens automatically starting from your second scan. No flag needed!

Configure

rohkun config --api-key YOUR_KEY

Set your API key. Saved to .rohkun/config.json in your project.

Version

rohkun --version

Supported Languages

  • Python (Flask, FastAPI, Django)
  • JavaScript/TypeScript (Express, Next.js, React)
  • Go (net/http, Gin, Echo)
  • Java (Spring Boot)
  • And more...

Report Format

Reports are saved as JSON in .rohkun/reports/:

{
  "version": "2.0.0",
  "generated_at": "2024-01-15T10:30:00Z",
  "summary": {
    "total_endpoints": 25,
    "total_api_calls": 18,
    "total_connections": 15,
    "high_confidence_connections": 12,
    "medium_confidence_connections": 2,
    "low_confidence_connections": 1,
    "estimated_accuracy": "High (80%+)",
    "high_impact_nodes": 3
  },
  "endpoints": [...],
  "api_calls": [...],
  "connections": [
    {
      "endpoint": {...},
      "api_call": {...},
      "confidence": "high",
      "confidence_score": 85,
      "confidence_reasons": ["HTTP method matches", "Path matches exactly"]
    }
  ],
  "blast_radius": [
    {
      "target": "GET:/api/users",
      "severity": "high",
      "total_dependents": 15,
      "affected_files": [...],
      "impact_description": "..."
    }
  ],
  "high_impact_nodes": [...],
  "accuracy": {...}
}

Configuration

API Key

Set via command:

rohkun config --api-key YOUR_KEY

Or environment variable:

export ROHKUN_API_KEY=your_key_here

Custom API URL

For self-hosted instances:

export ROHKUN_API_URL=https://your-api.com

Troubleshooting

"No API key found"

rohkun config --api-key YOUR_KEY

"Invalid or expired API key"

Get a new key at rohkun.com/dashboard

"Insufficient credits"

Upgrade your plan at rohkun.com/pricing

Privacy

  • Your code is analyzed locally on your machine
  • Only authorization requests are sent to our servers
  • No code content is ever uploaded
  • Reports are saved locally in your project

Support

License

MIT License - see LICENSE file for details

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

rohkun-2.2.0.tar.gz (54.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

rohkun-2.2.0-py3-none-any.whl (63.5 kB view details)

Uploaded Python 3

File details

Details for the file rohkun-2.2.0.tar.gz.

File metadata

  • Download URL: rohkun-2.2.0.tar.gz
  • Upload date:
  • Size: 54.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.0

File hashes

Hashes for rohkun-2.2.0.tar.gz
Algorithm Hash digest
SHA256 06828bf4c3ad0b33ec7f737c265cf9cabc595985ee9d599d33559b2ce1337e27
MD5 55fa0b51cd8a192f83c50a1bc39c5b7e
BLAKE2b-256 3a1fe9498266f05b761a2fc416568b90217a26bea046367b71211f99a62ceb10

See more details on using hashes here.

File details

Details for the file rohkun-2.2.0-py3-none-any.whl.

File metadata

  • Download URL: rohkun-2.2.0-py3-none-any.whl
  • Upload date:
  • Size: 63.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.0

File hashes

Hashes for rohkun-2.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 bac7df7f4ad39eb93a6e79b4584bcff1efb1b5094d872c6bfc6f20f4ab16fadf
MD5 e8fac869c4159b47f874fa729dfa189c
BLAKE2b-256 a18c8cdfb00f808b8853dc5dcc3f4e7c6320489e0938c58160bcdfc51fd28543

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page