---
title: "BugRunner CLI and SDKs | Local scan, Go, Python, TypeScript"
description: "Run bugrunner scan from a terminal with no server, gate CI on severity, and use the Go, Python and TypeScript SDKs. What is published and what is not."
image: "https://bugrunner.io/og-image.png"
---

[Home](https://bugrunner.io/)CLI and SDKs

# A local scan from the terminal, and SDKs for your own code

The bugrunner CLI runs the synthetic user on your machine with no server. The Go, Python and TypeScript SDKs wrap the same REST API the dashboard uses.

[Talk to the founder on WhatsApp](https://wa.me/5548992091242?text=Hi!%20I%27m%20interested%20in%20BugRunner%20%28AI%20synthetic%20users%20that%20find%20bugs%20in%20web%20apps%29%20and%20I%27d%20like%20to%20talk%20about%20early%20access.%20I%20came%20from%3A%20CLI%20and%20SDKs%20page)

**Availability.** The CLI builds from the repository today and none of the SDKs is published to npm, PyPI or the Go proxy yet. The TypeScript package is prepared for npm, but publishing it is still a manual step nobody has done. Ask the founder for access.

## bugrunner scan

`bugrunner scan <url>` drives a browser with the same engine as the hosted runner. It needs an `OPENAI_API_KEY` or an `ANTHROPIC_API_KEY` in the environment, and `bugrunner doctor` checks that setup without spending anything.

sample session sample output, not a real app

```
$ bugrunner doctor
ok AI provider found
ok browser available
$ bugrunner scan https://app.example.com --steps 8 --out report.md
scanning app.example.com, up to 8 steps
high  Signup returns 500 after "Create account"
low   Image on /pricing has no alt text
usage: input and output tokens, model, estimated cost
report written to report.md
```

## What the flags do

| Flag | What it does |
| --- | --- |
| `--steps` | Maximum page interactions, 8 by default. |
| `--persona` | `new_user` (default), `power_user`, `edge_case` or `returning_user`. |
| `--repeat`, `--interval`, `--max-runs` | Continuous mode: scan again on an interval. |
| `--out` and `--fail-on` | Write a JSON or Markdown report, and exit non-zero when a finding reaches critical, high, medium or low. Use it as a CI gate. |
| `--session` | A Playwright storage state, for apps behind single sign-on. |
| `--email`, `--password` | Log in through a form. |
| `--allow-internal` | Allow localhost and private addresses for a local app. |
| `--github-repo` | File findings as GitHub issues, with a `GITHUB_TOKEN` set. |

The report includes token usage, the model and an estimated cost in dollars, priced from one table in the code.

## Against the hosted service

With an API key from the dashboard the same binary manages projects and runs: `bugrunner projects`, `run start`, `run wait` and `reports`. Self-hosted and CI setups can set `BUGRUNNER_API_KEY` and `BUGRUNNER_API_URL` instead of logging in.

## SDKs

| Language | Package state |
| --- | --- |
| Go | Module in the repository, not published. |
| Python | Package `bugrunner` version 0.1.0 in the repository, not on PyPI. |
| TypeScript | Package `@bugrunner/sdk` version 0.1.0 prepared, not published. |

All three wrap the public REST API described in the repository's OpenAPI file.
