KORTHEXDocumentation

Docs / DEVELOPER TOOLS

DEVELOPER TOOLS

Authentication

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

The SDK uses your Korthex license to authenticate, with optional API tokens for granular, scope-limited access. The authentication model mirrors the CLI: same credentials, same tier-gating, same audit trail.

License-Based Auth

The same KORTHEX_LICENSE environment variable used by the CLI is picked up automatically when no license option is passed. For fully offline runs, point KORTHEX_LICENSE_FILE at a license token (see License Management).

API Tokens

For programmatic access from CI/CD, create scoped API tokens in the Dashboard ( Settings → API Tokens ) and pass them at client construction. Tokens carry their own scopes and can be rotated without touching the license.

Scopes

ScopeAllows
scan:readRead scan reports and inventories
scan:runTrigger new scans
policy:readRead policy + verdicts
policy:writeUpdate policy file
plan:readRead migration plans
plan:execute(V2) Execute auto-migration
exploit:runInvoke Exploit engine (ToS gate required)
admin:*Full administrative access (Enterprise)