Manage your compliance program from the terminal—list controls, review tests,
upload evidence, and more—using the same Vanta API that powers your account.
Install · Authenticate · Quick start · Development
macOS and Linux:
curl -fsSL https://raw.githubusercontent.com/OpenVanta/cli/main/scripts/install.sh | bashOptional flags:
# Install a specific version
curl -fsSL https://raw.githubusercontent.com/OpenVanta/cli/main/scripts/install.sh | bash -s -- --version v0.2.0
# Install to a custom directory
curl -fsSL https://raw.githubusercontent.com/OpenVanta/cli/main/scripts/install.sh | bash -s -- --install-dir ~/.local/binConfirm the install:
vanta versionStandalone binaries are published for Linux, macOS, and Windows. macOS builds are signed and notarized.
Create an OAuth client in the Vanta developer portal, then run:
vanta loginYou’ll be prompted for your API base URL, client ID, and client secret. Credentials are stored in the OS keychain when available (macOS Keychain or Windows Credential Manager), matching the previous Go CLI (com.vanta.cli / oauth). Your API base is saved to ~/.vanta/config.json.
You can also pass credentials via environment variables or flags:
| Option | Flag | Environment variable |
|---|---|---|
| Client ID | --client-id |
VANTA_CLIENT_ID |
| Client secret | --client-secret |
VANTA_CLIENT_SECRET |
| OAuth scope | --scope |
VANTA_OAUTH_SCOPE |
| API base URL | --api-base |
VANTA_API_BASE |
Default API base: https://api.vanta.com/v1
Default scope: vanta-api.all:read vanta-api.all:write
# List controls
vanta controls list --page-size 50
# Get a policy
vanta policies get --id code-of-conduct-bsi
# List controls for a framework
vanta frameworks list-controls --id soc2
# Find tests that need attention
vanta tests list --status-filter NEEDS_ATTENTION| Resource | Command |
|---|---|
| Controls | vanta controls |
| Policies | vanta policies |
| Documents | vanta documents |
| Tests | vanta tests |
| People | vanta people |
| Business units | vanta business-units |
| Issues | vanta issues |
| Personnel notification settings | vanta people notification-settings |
| Program scopes | vanta program-scopes |
| Vendor assessment types | vanta vendors assessment-types |
| Vendor risk attributes | vanta vendors risk-attributes |
| Groups | vanta groups |
| Frameworks | vanta frameworks |
| Users | vanta users |
| Vulnerabilities | vanta vulnerabilities |
| Vulnerable assets | vanta vulnerable-assets |
| Vulnerability remediations | vanta vulnerability-remediations |
| Contracts | vanta contracts |
| Risk scenarios | vanta risk-scenarios |
| Monitored computers | vanta monitored-computers |
| Vendors | vanta vendors |
| Discovered vendors | vanta discovered-vendors |
| Integrations | vanta integrations |
| Event logs | vanta event-logs |
| Customer Trust accounts, questionnaires, exports, and tags | vanta customer-trust |
| Knowledge Base answers and resources | vanta knowledge-base |
| Trust Center configuration, content, access, and subscribers | vanta trust-centers |
Run vanta <resource> --help for the full list of actions on each resource.
| Flag | Description |
|---|---|
--dry-run |
Print the request without sending |
--pretty |
Pretty-print JSON output (on by default; use --no-pretty for compact output) |
--verbose |
Log request details to stderr |
--agent-mode |
Optimize output for AI coding agents (TOON) |
The CLI periodically checks GitHub Releases for a newer version (cached for 24h in ~/.vanta/update-check.json) and prints a notice on stderr when one is available. Checks are skipped for dev builds, non-TTY stderr, CI, agent mode, or when VANTA_NO_UPDATE=1.
To upgrade:
curl -fsSL https://raw.githubusercontent.com/OpenVanta/cli/main/scripts/install.sh | bashRequires Node 22+ and pnpm 12. Bun is required to build standalone binaries.
pnpm install
pnpm generate # OpenAPI → src/generated
pnpm dev version
pnpm typecheck
pnpm test
pnpm build # generate + bundle for Node
VANTA_VERSION=0.2.0 pnpm build:binariesThe typed API client is generated from api-spec.json with @hey-api/openapi-ts.