What RepliMap talks to
RepliMap is a local CLI. This page lists every network destination the shipped package can contact, what it sends, when, and how to check that yourself instead of trusting us.
Verified against the RepliMap 0.6.1 package on 2026-10-01. If something here does not match what you observe, open an issue.
At a glance
| Destination | When | What is sent |
|---|---|---|
| AWS service APIs (your credentials) | Commands that scan or read your account | Signed, read-only API requests to AWS |
api.replimap.com | Only when you run replimap license activate | License key, a hashed machine id, CLI version |
| Anything else | Never | Nothing. No update checks, telemetry or crash reports. |
Scan results, dependency graphs, generated Terraform and reports are written to your local disk and are never uploaded. Without a license key the CLI runs on the community tier and makes no license call at all.
1. AWS read-only APIs
- AWS calls go through boto3 with the profile and region you pass. They are metadata reads (
Describe*,List*,Get*). The package contains no AWS create, put, delete or modify calls. sts:GetCallerIdentityidentifies the account.sts:GetSessionTokenis called only if your profile requires MFA (core/security/session_manager.py).s3:GetObjecton the single Terraform state object you name, only fordriftorauditwith--state-bucketand--state-key(drift/state_parser.py). A local--statefile avoids it.replimap doctoropens a TCP connection tosts.amazonaws.com:443to test reachability and sends nothing (cli/commands/doctor.py).- Credential resolution for your profile is done by the AWS SDK, not by RepliMap. Depending on how your profile is set up, the SDK may contact AWS SSO or STS endpoints, or the link-local instance metadata address when running on EC2 or ECS.
The minimal IAM policy is in the IAM policy documentation (also IAM_POLICY.md on GitHub).
Never called
The package contains no call to any of the following, so do not grant them:
| Action | Why it matters |
|---|---|
secretsmanager:GetSecretValue | Returns secret values. RepliMap lists secret names and metadata only. |
ssm:GetParameter, GetParameters, GetParametersByPath | Return parameter values, including plain String ones. Only names are listed. |
kms:Decrypt | RepliMap reads key metadata and policies, never key material or ciphertext. |
lambda:GetFunction | Returns a presigned URL to download function code. Code is never read. |
DynamoDB data plane: Scan, Query, GetItem, BatchGetItem, ExportTableToPointInTime | Table items are never read. Only table definitions, tags, PITR and TTL settings are (scanners/dynamodb_scanner.py). |
ECR image pulls: GetAuthorizationToken, BatchGetImage, GetDownloadUrlForLayer | Image contents are unreachable. Only repository metadata is listed. |
Check it yourself with the commands in How to verify.
2. License validation
| Question | Answer |
|---|---|
| Endpoint | POST https://api.replimap.com/v1/license/validate. The URL is a constant in licensing/manager.py; setting REPLIMAP_LICENSE_API overrides it, for example to route the call through an internal proxy. |
| When | Only when you run replimap license activate <key>. No other command makes this call, and neither does the air-gapped path below: scan, codify, audit, drift and license status read the local cache and verify it offline. |
| Fields sent | JSON body with exactly three fields: license_key, machine_id, cli_version. The server also sees the standard connection metadata of any HTTPS request, such as your source IP address. |
What machine_id is | The first 32 hex characters of a SHA-256 over the OS name, CPU architecture and the operating system machine id (/etc/machine-id on Linux, IOPlatformUUID on macOS, MachineGuid on Windows). If none is readable, a random UUID stored in ~/.replimap/.device_id is used instead. Hostname and MAC address are not part of it, except in the rare case where that file cannot be written and a value derived from the hostname is used. The hash is not salted, so treat it as a stable pseudonymous identifier for the machine, not as anonymous data. |
| Second call, rarely | POST /v1/license/deactivate with license_key and the previous machine_id. It happens during activation, and only when the local cache holds the same key bound to a different machine id (for example after the id changed), to free the old machine slot. It is best-effort and never blocks activation. |
| What comes back | An Ed25519-signed license that the CLI verifies locally against a public key embedded in the package, then caches in ~/.replimap/license.json. The cached file is re-verified locally on every load, with no network I/O. |
| Offline behaviour | The signed license expires at the end of the current billing period plus a plan-dependent offline grace: 7 days on Pro, 14 days on Team, 30 days on Sovereign. The CLI never re-contacts the server on its own. After expiry the license is rejected locally and the CLI falls back to the community tier until you activate again. |
| Air-gapped activation (Sovereign, from CLI 0.6.1) | Zero network calls on the isolated host. You run replimap license machine-id on that host, we issue a signed license file for that machine on request, and you import it with replimap license activate --file <path>. The CLI verifies the Ed25519 signature locally, and refuses a file that is bound to a different machine or that is not issued for a Sovereign license. The file expires on the date set when it is issued. |
What the license service stores about these requests is described in the privacy policy.
3. Everything else
| Topic | Status |
|---|---|
| Update checks | None. The only HTTP client calls in the package are the two license calls above; nothing contacts PyPI or a version endpoint. |
| Telemetry, analytics, crash reports | None. There is no analytics or crash-reporting SDK in the dependencies. Error diagnostics are written to ~/.replimap/logs/errors/ and usage counters to ~/.replimap/usage_history.json, both local files. |
| Fonts, CDNs and scripts in generated HTML reports | None. The dependency graph and audit reports inline their JavaScript and CSS (D3, Chart.js and a precompiled Tailwind stylesheet are bundled in the package). Opening a report loads nothing from the internet. They contain plain links such as replimap.com and checkov.io that are followed only if you click them. |
replimap upgrade | Opens the pricing or checkout page in your own browser. The CLI process sends nothing. |
| MCP server | Uses stdio transport. It does not open a network listener (mcp_server.py). |
| Optional external programs | audit runs the separate checkov program if you have it installed, and codify runs terraform fmt if terraform is on your PATH. They are separate programs; RepliMap does not control their network behaviour, so include them in your own checks. |
How to verify it yourself
Inspect the package
List every import of a network library in the shipped code:
pip download replimap --no-deps -d rm-wheel unzip -q rm-wheel/*.whl -d rm-src grep -rnE "^\s*(import|from) (httpx|requests|urllib\.request|urllib3|aiohttp|http\.client|socket|webbrowser)\b" \ rm-src/replimap --include='*.py'
Expected hits: licensing/manager.py (httpx, the license calls), cli/commands/doctor.py (socket, the STS probe), cli/commands/upgrade.py and core/browser.py (webbrowser, which opens your browser). boto3 is the AWS path and is not matched here. To confirm the never-called list, search the same tree for get_secret_value, get_parameter, .decrypt(, get_function(, get_item(, batch_get_image and get_authorization_token. None are present.
Watch it run
- Proxy. Both the license call and boto3 honour
HTTPS_PROXY. Point it at any logging proxy (squid, mitmproxy) and read the destination hostnames:HTTPS_PROXY=http://127.0.0.1:3128 replimap scan --profile prod --region us-east-1. Expect only*.amazonaws.comhosts. ACONNECTlog is enough; you do not need to decrypt anything. - strace.
strace -f -e trace=connect -o rm.trace replimap scan --profile prodlists every outbound connection by address. Resolve the addresses and compare them with the AWS endpoints for your region. - Firewall. Run with default-deny egress and allow only AWS endpoints (and, for the one-time activation,
api.replimap.com). If the scan completes, nothing else was needed. - License call only. Run
replimap license activatebehind the proxy and you will see a single request toapi.replimap.com(plus the rare deactivate call described above). Runreplimap license statusafterwards and you will see none.