| title | kosli evaluate input |
|---|---|
| tag | BETA |
| description | Evaluate a local JSON input against a Rego policy. |
import CliBetaNotice from "/snippets/cli-beta-notice.mdx";
kosli evaluate input [flags]Evaluate a local JSON input against a Rego policy.
Read JSON from a file or stdin and evaluate it against a Rego policy.
The input file should contain the raw JSON object your policy expects —
not the wrapper produced by --show-input. Use jq '.input' to extract
the policy input from a --show-input --output json capture.
The policy must use package policy and define an allow rule.
An optional violations rule (a set of strings) can provide human-readable denial reasons.
By default a deny exits with code 1. Pass --no-assert to print the verdict
and exit 0 even on deny, when this command is feeding another tool as a
policy decision point.
When --input-file is omitted, JSON is read from stdin.
Use --params to pass configuration data to the policy as data.params.
This accepts inline JSON or a file reference (@file.json).
| Flag | Type | Description |
|---|---|---|
--assert |
bool | [optional] Exit with a non-zero status when the policy denies. This is the current default; pass --assert to lock it in across future releases. |
-h, --help |
bool | help for input |
-i, --input-file |
string | [optional] Path to a JSON input file. Reads from stdin if omitted. |
--no-assert |
bool | [optional] Print the result and always exit 0, even when the policy denies. Use when this command feeds another tool as a policy decision point. |
-o, --output |
string | [defaulted] The format of the output. Valid formats are: [table, json]. (default "table") |
--params |
string | [optional] Policy parameters as inline JSON or @file.json. Available in policies as data.params. |
-p, --policy |
string | Path or http(s):// URL of a Rego policy to evaluate against the input. |
--show-input |
bool | [optional] Include the policy input data in the output. |
| Flag | Type | Description |
|---|---|---|
-a, --api-token |
string | The Kosli API token. |
-c, --config-file |
string | [optional] The Kosli config file path. Config is read from this path or the default only, never implicitly from the current directory. (default "$HOME/.kosli.yml") |
--debug |
bool | [optional] Print debug logs to stdout. |
-H, --host |
string | [defaulted] The Kosli endpoint. (default "https://app.kosli.com") |
--http-proxy |
string | [optional] The HTTP proxy URL including protocol and port number. e.g. http://proxy-server-ip:proxy-port |
-r, --max-api-retries |
int | [defaulted] How many times should API calls be retried when the API host is not reachable. (default 3) |
--org |
string | The Kosli organization. |
-q, --quiet |
bool | [optional] Suppress non-critical warning messages. Errors and normal output are not affected. If both --quiet and --debug are set, --debug wins. |
In [this YAML file](https://github.com/cyber-dojo/snyk-scanning/blob/30111f180ac4e3611cdbd7d805381a0bb9f53cff/tests/test_rego_rules.sh#L304)
</Tab>
These examples all assume that the flags --api-token, --org, --host, (and --flow, --trail when required), are set/provided.
</Accordion>
<Accordion title="then iterate on your policy locally">
```shell
kosli evaluate input
--input-file trail-data.json
--policy policy.rego
</Accordion>
<Accordion title="read input from stdin">
```shell
cat trail-data.json | kosli evaluate input
--policy policy.rego
</Accordion>
<Accordion title="evaluate with policy parameters from a file">
```shell
kosli evaluate input
--input-file trail-data.json
--policy policy.rego
--params @params.json
</Accordion>
<Accordion title="evaluate as a decision point (print verdict, never fail the step)">
```shell
kosli evaluate input
--input-file trail-data.json
--policy policy.rego
--no-assert