Tool
Run BTP Lens on your own machine.
Guided mode asks four questions and opens the report in your browser. The scan command does the same from a script or a CI (continuous integration) job. Everything below comes from the public repository's README at commit 9fe7d0db6498.
Guided mode
You need Node.js (the LTS installer) and a BTP login with the Space Auditor role, which is read-only. You do not need the cf command-line tool.
npx btp-lens Guided mode asks where your landscape is (pick a region or paste the API endpoint from the cockpit), how to sign in (your browser opens your company login and shows a one-time code), which org, and whether to start. The report then opens in your browser. Never used a terminal? Follow the step-by-step guide. Something not working? npx btp-lens doctor checks Node.js, network, certificates, login and the output folder.
Run it from source
v0.1 is in development and 0.1.0 is not published yet. Until then, run it from source with Node.js 22.12 or later:
git clone https://github.com/sebastianomarchesini/BTP-Lens.git && cd BTP-Lens
npm ci && npm run build
node packages/cli/dist/cli.js # guided mode
node packages/cli/dist/cli.js scan --api <cf api url> --org my-org Credentials
BTP Lens uses the first of these that is set:
BTP_LENS_ACCESS_TOKEN, for exampleBTP_LENS_ACCESS_TOKEN="$(cf oauth-token)".BTP_LENS_CLIENT_IDandBTP_LENS_CLIENT_SECRET, for an OAuth client with a CF role.- Your cf CLI session (
~/.cf/config.json, or$CF_HOME/.cf/config.json). It must target the same API as--api. An expired token is refreshed in memory only, and the file is never written.
Behind a corporate proxy, set NODE_USE_ENV_PROXY=1 so that Node.js honours HTTPS_PROXY.
Commands
btp-lens guided mode (four questions, report opens in the browser)
btp-lens guided [--no-open] the same, explicitly
btp-lens doctor [--api <url>] checks Node.js, network, certificates, login and output folder
btp-lens scan --api <cf api url> --org <name> [--space <name>] [--deep] [--no-probe-routes]
[--out ./reports] [--format html,json,csv,sarif] [--fail-on <severity>] [--concurrency 5]
btp-lens report --from <snapshot.json> [--format html,json,csv,sarif] [--out ./reports] [--fail-on <severity>]
btp-lens version - With no arguments on a terminal, guided mode starts; in a script it prints usage and exits 2.
- Guided mode signs in the way
cf login --ssodoes (one-time code from your company login) or with username and password, keeps the session in memory only, and writes to./btp-lens-reports/<date-time>/. scanwrites one snapshot (snapshot-<time>.json) and the requested reports.report --fromre-runs every rule on a snapshot offline, for example after you upgrade BTP Lens.- Exit codes: 0 when no finding reaches
--fail-on(the default,none, never fails); 1 when findings met the threshold; 2 for a tool error.
Documentation
-
ToolSynced 3 October 2026
Getting started without being a developer
Install Node.js, run npx btp-lens, answer four questions and read the report. Step by step, for people who have never used a terminal.
-
ToolSynced 3 October 2026
Permissions
Which Cloud Foundry role each check needs, how to ask an administrator for Space Auditor, what --deep adds and what happens when a role is missing.
-
ToolSynced 3 October 2026
Privacy
Where BTP Lens sends requests, what it keeps in the report and the snapshot, what it never keeps, and the one side effect of --deep in your landscape.
-
ToolSynced 3 October 2026
Rules
Every BTP Lens rule with its severity, the evidence that triggers it, the remediation and the references, plus how the risk score is computed.
-
ToolSynced 3 October 2026
Frequently asked questions
Is it safe with a production login, will SAP know, does it change anything, what leaves your machine, can you share the report, what does it cost.
-
ToolSynced 3 October 2026
Roadmap
What v0.1, v0.2 and v0.3 contain, and the good first issues.