Sign inSign up

classifyre/api

By classifyre

•Updated about 14 hours ago

Classifyre API backend: scans, findings, cases and investigation automation.

Buildkit cache
Image
Security
Machine learning & AI
Data science
0

50K+

classifyre/api repository overview

Classifyre

⁠Classifyre API

Backend service of the open-source Classifyre investigation platform — REST API, scan orchestration, findings, cases and AI autopilot.

Classifyre turns the data scattered across the systems you already run — file shares, Confluence, Jira, SharePoint, S3, Git repositories, databases — into investigations you can act on: detectors raise findings (leaked secrets, PII, security risks), and analysts work them through inquiries, duplicates, cases and hypotheses.

This classifyre/api image is the Classifyre backend (NestJS): it serves the REST API and WebSockets, orchestrates scans, runs the background job queues (pg-boss) and semantic embeddings, and spawns scan workers. It is one of three service images — together with classifyre/web⁠ (frontend) and classifyre/cli⁠ (scan jobs) — composed into the classifyre/all-in-one⁠ image and deployed separately by the classifyre/classifyre-core⁠ Helm chart.

You normally don't run this image by hand: use the all-in-one image⁠ for local use or the Helm chart⁠ for Kubernetes.

📚 Full documentation: https://docs.classifyre.com⁠


⁠Quickstart (standalone)

The API needs PostgreSQL 15+ with pgvector:

docker run -d --name classifyre-api \
  -p 8000:8000 \
  -e DATABASE_URL="postgresql://user:[email protected]:5432/classifyre?sslmode=require" \
  classifyre/api:latest

The DB user needs CREATE SCHEMA / CREATE EXTENSION (every workspace gets its own schema). Migrations run automatically on startup behind an advisory lock, so multiple replicas against one database are safe.

⁠Configuration

VariableDefaultPurpose
DATABASE_URL(required standalone)PostgreSQL connection string.
PORT8000Port the API listens on.
CLASSIFYRE_MASKED_CONFIG_KEYauto-generatedEncrypts stored source credentials and MCP tokens. Set explicitly in production and back it up.
SERVICE_ROLEapiapi serves traffic; worker runs background embedding/automation jobs (used by the Helm chart).
CORS_ORIGINsame-originSet when the UI is served from another host.
DEMO_MODEfalseRead-only mode; blocks every write.
TELEMETRY_DISABLED / DO_NOT_TRACKunsetSet either to 1 to disable anonymous usage telemetry.
CLASSIFYRE_AUTO_MIGRATEtruefalse skips startup migrations (only if you run them yourself).
EMBEDDING_PROVIDERtransformers-jsopenai-compatible for a remote embedding service.
EMBEDDING_BASE_URL / EMBEDDING_API_KEYunsetRemote endpoint for openai-compatible.
EMBEDDING_MODELXenova/all-MiniLM-L6-v2Embedding model id.
S3_BUCKET, S3_ENDPOINT, S3_REGION, S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEYunsetObject storage for scan logs (disk otherwise).

AI provider keys (LLM detectors, autopilot) are per-workspace settings in the UI (Settings → AI providers), not environment variables.

The Helm chart exposes further tuning (DB pool sizes, V8 heap, HNSW index parameters) — see values⁠.

⁠Tags

  • latest tracks the newest stable release; pin a version (e.g. classifyre/api:0.6.3) in production. API, web and CLI tags with the same version are built from the same commit — keep them in sync.

Classifyre is open source: https://github.com/classifyre/classifyre⁠ · Docs: https://docs.classifyre.com⁠

Tag summary

Content type

Image

Digest

sha256:05de58a7a…

Size

1.6 GB

Last updated

about 14 hours ago

docker pull classifyre/api