Docs / DEVELOPER TOOLS
DEVELOPER TOOLS
Authentication
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
The SDK uses your Korthex license to authenticate, with optional API tokens for granular, scope-limited access. The authentication model mirrors the CLI: same credentials, same tier-gating, same audit trail.
License-Based Auth
The same KORTHEX_LICENSE environment variable used by the CLI is picked up automatically when no license option is passed. For fully offline runs, point KORTHEX_LICENSE_FILE at a license token (see License Management).
API Tokens
For programmatic access from CI/CD, create scoped API tokens in the Dashboard ( Settings → API Tokens ) and pass them at client construction. Tokens carry their own scopes and can be rotated without touching the license.
Scopes
| Scope | Allows |
|---|---|
| scan:read | Read scan reports and inventories |
| scan:run | Trigger new scans |
| policy:read | Read policy + verdicts |
| policy:write | Update policy file |
| plan:read | Read migration plans |
| plan:execute | (V2) Execute auto-migration |
| exploit:run | Invoke Exploit engine (ToS gate required) |
| admin:* | Full administrative access (Enterprise) |