RepliMap

What RepliMap talks to

RepliMap is a local CLI. This page lists every network destination the shipped package can contact, what it sends, when, and how to check that yourself instead of trusting us.

Verified against the RepliMap 0.6.1 package on 2026-10-01. If something here does not match what you observe, open an issue.

At a glance

All network destinations of the RepliMap CLI
DestinationWhenWhat is sent
AWS service APIs (your credentials)Commands that scan or read your accountSigned, read-only API requests to AWS
api.replimap.comOnly when you run replimap license activateLicense key, a hashed machine id, CLI version
Anything elseNeverNothing. No update checks, telemetry or crash reports.

Scan results, dependency graphs, generated Terraform and reports are written to your local disk and are never uploaded. Without a license key the CLI runs on the community tier and makes no license call at all.

1. AWS read-only APIs

  • AWS calls go through boto3 with the profile and region you pass. They are metadata reads (Describe*, List*, Get*). The package contains no AWS create, put, delete or modify calls.
  • sts:GetCallerIdentity identifies the account. sts:GetSessionToken is called only if your profile requires MFA (core/security/session_manager.py).
  • s3:GetObject on the single Terraform state object you name, only for drift or audit with --state-bucket and --state-key (drift/state_parser.py). A local --state file avoids it.
  • replimap doctor opens a TCP connection to sts.amazonaws.com:443 to test reachability and sends nothing (cli/commands/doctor.py).
  • Credential resolution for your profile is done by the AWS SDK, not by RepliMap. Depending on how your profile is set up, the SDK may contact AWS SSO or STS endpoints, or the link-local instance metadata address when running on EC2 or ECS.

The minimal IAM policy is in the IAM policy documentation (also IAM_POLICY.md on GitHub).

Never called

The package contains no call to any of the following, so do not grant them:

AWS actions RepliMap never calls
ActionWhy it matters
secretsmanager:GetSecretValueReturns secret values. RepliMap lists secret names and metadata only.
ssm:GetParameter, GetParameters, GetParametersByPathReturn parameter values, including plain String ones. Only names are listed.
kms:DecryptRepliMap reads key metadata and policies, never key material or ciphertext.
lambda:GetFunctionReturns a presigned URL to download function code. Code is never read.
DynamoDB data plane: Scan, Query, GetItem, BatchGetItem, ExportTableToPointInTimeTable items are never read. Only table definitions, tags, PITR and TTL settings are (scanners/dynamodb_scanner.py).
ECR image pulls: GetAuthorizationToken, BatchGetImage, GetDownloadUrlForLayerImage contents are unreachable. Only repository metadata is listed.

Check it yourself with the commands in How to verify.

2. License validation

License validation request
QuestionAnswer
EndpointPOST https://api.replimap.com/v1/license/validate. The URL is a constant in licensing/manager.py; setting REPLIMAP_LICENSE_API overrides it, for example to route the call through an internal proxy.
WhenOnly when you run replimap license activate <key>. No other command makes this call, and neither does the air-gapped path below: scan, codify, audit, drift and license status read the local cache and verify it offline.
Fields sentJSON body with exactly three fields: license_key, machine_id, cli_version. The server also sees the standard connection metadata of any HTTPS request, such as your source IP address.
What machine_id isThe first 32 hex characters of a SHA-256 over the OS name, CPU architecture and the operating system machine id (/etc/machine-id on Linux, IOPlatformUUID on macOS, MachineGuid on Windows). If none is readable, a random UUID stored in ~/.replimap/.device_id is used instead. Hostname and MAC address are not part of it, except in the rare case where that file cannot be written and a value derived from the hostname is used. The hash is not salted, so treat it as a stable pseudonymous identifier for the machine, not as anonymous data.
Second call, rarelyPOST /v1/license/deactivate with license_key and the previous machine_id. It happens during activation, and only when the local cache holds the same key bound to a different machine id (for example after the id changed), to free the old machine slot. It is best-effort and never blocks activation.
What comes backAn Ed25519-signed license that the CLI verifies locally against a public key embedded in the package, then caches in ~/.replimap/license.json. The cached file is re-verified locally on every load, with no network I/O.
Offline behaviourThe signed license expires at the end of the current billing period plus a plan-dependent offline grace: 7 days on Pro, 14 days on Team, 30 days on Sovereign. The CLI never re-contacts the server on its own. After expiry the license is rejected locally and the CLI falls back to the community tier until you activate again.
Air-gapped activation (Sovereign, from CLI 0.6.1)Zero network calls on the isolated host. You run replimap license machine-id on that host, we issue a signed license file for that machine on request, and you import it with replimap license activate --file <path>. The CLI verifies the Ed25519 signature locally, and refuses a file that is bound to a different machine or that is not issued for a Sovereign license. The file expires on the date set when it is issued.

What the license service stores about these requests is described in the privacy policy.

3. Everything else

Other possible network activity and its status
TopicStatus
Update checksNone. The only HTTP client calls in the package are the two license calls above; nothing contacts PyPI or a version endpoint.
Telemetry, analytics, crash reportsNone. There is no analytics or crash-reporting SDK in the dependencies. Error diagnostics are written to ~/.replimap/logs/errors/ and usage counters to ~/.replimap/usage_history.json, both local files.
Fonts, CDNs and scripts in generated HTML reportsNone. The dependency graph and audit reports inline their JavaScript and CSS (D3, Chart.js and a precompiled Tailwind stylesheet are bundled in the package). Opening a report loads nothing from the internet. They contain plain links such as replimap.com and checkov.io that are followed only if you click them.
replimap upgradeOpens the pricing or checkout page in your own browser. The CLI process sends nothing.
MCP serverUses stdio transport. It does not open a network listener (mcp_server.py).
Optional external programsaudit runs the separate checkov program if you have it installed, and codify runs terraform fmt if terraform is on your PATH. They are separate programs; RepliMap does not control their network behaviour, so include them in your own checks.

How to verify it yourself

Inspect the package

List every import of a network library in the shipped code:

pip download replimap --no-deps -d rm-wheel
unzip -q rm-wheel/*.whl -d rm-src
grep -rnE "^\s*(import|from) (httpx|requests|urllib\.request|urllib3|aiohttp|http\.client|socket|webbrowser)\b" \
  rm-src/replimap --include='*.py'

Expected hits: licensing/manager.py (httpx, the license calls), cli/commands/doctor.py (socket, the STS probe), cli/commands/upgrade.py and core/browser.py (webbrowser, which opens your browser). boto3 is the AWS path and is not matched here. To confirm the never-called list, search the same tree for get_secret_value, get_parameter, .decrypt(, get_function(, get_item(, batch_get_image and get_authorization_token. None are present.

Watch it run

  • Proxy. Both the license call and boto3 honour HTTPS_PROXY. Point it at any logging proxy (squid, mitmproxy) and read the destination hostnames: HTTPS_PROXY=http://127.0.0.1:3128 replimap scan --profile prod --region us-east-1. Expect only *.amazonaws.com hosts. A CONNECT log is enough; you do not need to decrypt anything.
  • strace. strace -f -e trace=connect -o rm.trace replimap scan --profile prod lists every outbound connection by address. Resolve the addresses and compare them with the AWS endpoints for your region.
  • Firewall. Run with default-deny egress and allow only AWS endpoints (and, for the one-time activation, api.replimap.com). If the scan completes, nothing else was needed.
  • License call only. Run replimap license activate behind the proxy and you will see a single request to api.replimap.com (plus the rare deactivate call described above). Run replimap license status afterwards and you will see none.