Fail-closed Rules of Engagement, validated findings, sealed reports. Run automated and autonomous penetration tests with AI agents from the web platform, the CLI, the Python SDK or the REST API. This cookbook shows you how to get the most out of every product.
Drive pentests, chat with agents and triage findings from the browser.
CLILaunch and control pentests from your terminal, in the cloud or locally.
Python SDKBuild pentesting into your own tools with rank-sdk.
Integrate directly with the platform over HTTP.
npm install -g @aleex-rank/cli
rank auth set rk_live_xxxxxxxxxxxxxxxx
rank pentest create -n "Demo" -u https://example.com -t web -m automaticAn active Rules of Engagement is required before the run starts — set it from the web app, the SDK or the REST API (the CLI does not yet create RoE).
rank pentest run 1 import rank
client = rank.Rank(api_key="rk_live_xxxxxxxxxxxxxxxx")
pentest = client.pentests.create(
name="Demo",
type="web",
mode="automatic",
assets=[{"asset_type": "url", "asset_value": "https://example.com", "is_primary": True}],
)
roe = client.pentests.roe.create(
pentest.id,
allowed_domains=["example.com"],
authorization_ref="ENG-2026-0042",
escalation_contacts=[{"type": "email", "value": "security@example.com"}],
activate=True,
)
print(pentest.id, roe.status) curl https://api.aleex-rank.ai/api/v2/pentests \
-H "X-API-Key: rk_live_xxxxxxxxxxxxxxxx" \
-H "Content-Type: application/json" \
-d '{
"name": "Demo",
"type": "web",
"mode": "automatic",
"assets": [{"asset_type": "url", "asset_value": "https://example.com", "is_primary": true}]
}'
curl https://api.aleex-rank.ai/api/v2/pentests/1/roe \
-H "X-API-Key: rk_live_xxxxxxxxxxxxxxxx" \
-H "Content-Type: application/json" \
-d '{
"allowed_domains": ["example.com"],
"authorization_ref": "ENG-2026-0042",
"escalation_contacts": [{"type": "email", "value": "security@example.com"}],
"activate": true
}' From zero to a finished pentest with findings.
Rules of Engagement & kill switchActivate a fail-closed RoE and stop a run without losing evidence.
Retest a fixed findingConfirm a patch without rewriting the original validation verdict.
Push findings to Jira, GitHub or SlackOpen tickets and notify a channel from live finding events.