Tool

Run BTP Lens on your own machine.

Guided mode asks four questions and opens the report in your browser. The scan command does the same from a script or a CI (continuous integration) job. Everything below comes from the public repository's README at commit 9fe7d0db6498.

Guided mode

You need Node.js (the LTS installer) and a BTP login with the Space Auditor role, which is read-only. You do not need the cf command-line tool.

npx btp-lens

Guided mode asks where your landscape is (pick a region or paste the API endpoint from the cockpit), how to sign in (your browser opens your company login and shows a one-time code), which org, and whether to start. The report then opens in your browser. Never used a terminal? Follow the step-by-step guide. Something not working? npx btp-lens doctor checks Node.js, network, certificates, login and the output folder.

Run it from source

v0.1 is in development and 0.1.0 is not published yet. Until then, run it from source with Node.js 22.12 or later:

git clone https://github.com/sebastianomarchesini/BTP-Lens.git && cd BTP-Lens
npm ci && npm run build
node packages/cli/dist/cli.js                          # guided mode
node packages/cli/dist/cli.js scan --api <cf api url> --org my-org

Credentials

BTP Lens uses the first of these that is set:

  1. BTP_LENS_ACCESS_TOKEN, for example BTP_LENS_ACCESS_TOKEN="$(cf oauth-token)".
  2. BTP_LENS_CLIENT_ID and BTP_LENS_CLIENT_SECRET, for an OAuth client with a CF role.
  3. Your cf CLI session (~/.cf/config.json, or $CF_HOME/.cf/config.json). It must target the same API as --api. An expired token is refreshed in memory only, and the file is never written.

Behind a corporate proxy, set NODE_USE_ENV_PROXY=1 so that Node.js honours HTTPS_PROXY.

Commands

btp-lens                       guided mode (four questions, report opens in the browser)
btp-lens guided [--no-open]    the same, explicitly
btp-lens doctor [--api <url>]  checks Node.js, network, certificates, login and output folder
btp-lens scan   --api <cf api url> --org <name> [--space <name>] [--deep] [--no-probe-routes]
                [--out ./reports] [--format html,json,csv,sarif] [--fail-on <severity>] [--concurrency 5]
btp-lens report --from <snapshot.json> [--format html,json,csv,sarif] [--out ./reports] [--fail-on <severity>]
btp-lens version
  • With no arguments on a terminal, guided mode starts; in a script it prints usage and exits 2.
  • Guided mode signs in the way cf login --sso does (one-time code from your company login) or with username and password, keeps the session in memory only, and writes to ./btp-lens-reports/<date-time>/.
  • scan writes one snapshot (snapshot-<time>.json) and the requested reports.
  • report --from re-runs every rule on a snapshot offline, for example after you upgrade BTP Lens.
  • Exit codes: 0 when no finding reaches --fail-on (the default, none, never fails); 1 when findings met the threshold; 2 for a tool error.

Documentation

  • ToolSynced 3 October 2026

    Getting started without being a developer

    Install Node.js, run npx btp-lens, answer four questions and read the report. Step by step, for people who have never used a terminal.

  • ToolSynced 3 October 2026

    Permissions

    Which Cloud Foundry role each check needs, how to ask an administrator for Space Auditor, what --deep adds and what happens when a role is missing.

  • ToolSynced 3 October 2026

    Privacy

    Where BTP Lens sends requests, what it keeps in the report and the snapshot, what it never keeps, and the one side effect of --deep in your landscape.

  • ToolSynced 3 October 2026

    Rules

    Every BTP Lens rule with its severity, the evidence that triggers it, the remediation and the references, plus how the risk score is computed.

  • ToolSynced 3 October 2026

    Frequently asked questions

    Is it safe with a production login, will SAP know, does it change anything, what leaves your machine, can you share the report, what does it cost.

  • ToolSynced 3 October 2026

    Roadmap

    What v0.1, v0.2 and v0.3 contain, and the good first issues.

Source, issues and discussions on GitHub