Skip to content
CodeDD Logo

CodeDD CLI · open source

Can you audit code the company won’t hand over?

The CodeDD CLI runs the audit on the company’s own machines, across the estate — every repository in scope. CodeDD receives findings and metrics, not source files. It is open source, so their engineers can read exactly what it does before they run it.

Start for FreeBook a Demo

pip install codedd-cli
Licence
MIT, open source
Runs on
Windows, macOS, Linux
Requires
Python 3.10+
LLM
Your own key

PyPISource on GitLab

What runs where

The analysis runs locally. The judgement runs on CodeDD.

Everything that has to read source code runs on the machine where the code lives. CodeDD turns the results into the same scores, benchmarks, and reports as a cloud audit.

On your machines

  • File analysisEach file reviewed by an LLM, using your own API key
  • Vulnerability validationCandidate issues checked with Semgrep and taint analysis
  • ComplexityCyclomatic and Halstead metrics
  • DependenciesLockfiles, manifests, and imports
  • Git historyCommits, contributors, and activity
  • ArchitectureComponents and the links between them

Sent to CodeDD

  • Findings with file and line
  • Metrics and scores
  • Package list
  • Architecture graph
  • Scope metadata: paths, file types, line counts

Source files never leave

On CodeDD

  • Consolidation and risk scoringOne score per area, across every repository
  • Vulnerability and licence dataPackages matched against CVE and licence sources
  • BenchmarksCompared with other audited codebases
  • Recommendations and reportsDashboards, IC-ready reports, and a fix plan

Why engineers agree to run it

Nothing to take on trust

Code access is the first objection in a technical DD. With the CLI, the company’s own team can check every claim.

  • Read the source

    The CLI is MIT-licensed and published on GitLab and PyPI. Security teams can review it, or pin and build it themselves.

  • Review every payload

    In review mode the CLI writes a summary of every request before it is sent, and waits for approval. Nothing leaves without that confirmation.

  • Their keys, their LLM contract

    Files are analysed with the company’s own Anthropic, OpenAI, Google Gemini, or xAI key, under the terms they already have with that provider.

After the audit

Work the findings down, or let an agent do it

The same CLI turns the audit into a fix loop. Progress is recorded against the audit in CodeDD, so the deal team sees the risk fall as the work lands.

  • One finding at a time, by severityTake the next issue, fix it, note what changed, and mark it resolved.
  • Built for AI coding agentsClaude Code, Cursor, and other agents can run the loop themselves. The CLI ships its own agent reference and a machine-readable session state.

Quick start

From install to a running audit in six commands

You need a CodeDD account, a CLI token (Account → CLI Access), and a key for at least one LLM provider. Each path you add must be a Git repository root.

6 commands
  1. # Install from PyPI$ pip install codedd-cli
  2. # Paste your CLI token$ codedd auth login
  3. # Pick the audit to run$ codedd audits select
  4. # Add repositories$ codedd scope add ./payments-api ./web-app
  5. # Or openai, gemini, grok$ codedd config set-key anthropic
  6. # Review, confirm, run$ codedd audit start --show

FAQ

Questions

Does any source code leave the company’s machines?

Source files are not sent to CodeDD. The CLI sends findings (with file and line references), metrics, the package list, the architecture graph, and scope metadata. Files are read by the LLM provider whose key the company supplies, under its own agreement with that provider. Run the audit with --show to review every payload first.

Is a CLI audit as complete as a cloud audit?

Yes. The CLI runs analysis logic taken from the CodeDD platform and kept in sync with it, and consolidation, scoring, benchmarks, and recommendations run on CodeDD exactly as for a cloud audit. The results appear in the same dashboards and reports.

What does it cost?

The CLI is free and open source. An audit run through it is billed like any CodeDD audit, by lines of code in scope; the CLI checks the budget before it starts. LLM usage is billed by the provider to the key that runs the analysis.

Which LLM providers are supported?

Anthropic, OpenAI, Google Gemini, and xAI. Keys are stored in the OS keychain with codedd config set-key, or read from environment variables such as ANTHROPIC_API_KEY on servers without a keychain.

Can it run in CI or on a headless server?

Yes. Set CODEDD_API_TOKEN and a provider key as environment variables instead of logging in, and use --yes to skip interactive prompts.

How are tokens and API keys stored?

In the operating system’s credential store (Windows Credential Locker, macOS Keychain, or Linux Secret Service), not in plain-text config. TLS certificate verification is always on, and CLI tokens expire after 90 days.

What if the audit is interrupted?

Progress is checkpointed after every batch. Run codedd audit start again and the CLI resumes from the last completed step instead of starting over.

Run your first audit without moving the code

Create an account, generate a CLI token, and start from your own terminal. Or walk through a CLI audit with the CodeDD team.