Skip to main content

Getting started

This page takes you from installing the extension to your first findings in about five minutes.

1. Install the extension​

From the Marketplace

  1. Open the Extensions view in VS Code or Cursor (Ctrl+Shift+X, or Cmd+Shift+X on macOS).
  2. Search for FossID and select Install.

From a VSIX file

Use this route if your organization distributes the extension itself, for example in a network-restricted environment. Your administrator gives you a platform-specific .vsix file.

  1. Open the Extensions view.
  2. Open the … menu and choose Install from VSIX….
  3. Select the file, then reload the window when prompted.

The extension starts automatically once the editor has finished loading. You don't need to open any particular file.

2. Sign in​

The Sign in to FossID window opens by itself the first time the extension starts. You can also open it at any time:

  • from the FossID icon in the Activity Bar, by selecting Set Up FossID;
  • by clicking FossID: Not configured in the status bar;
  • by running FossID: Sign In from the Command Palette (Ctrl+Shift+P, or Cmd+Shift+P on macOS).

In the window:

  1. Server. Enter the address of your FossID server, or select the Europe / US preset (https://eu1.foss.id). If your administrator has set the address already, it is filled in for you.
  2. Sign in with your organization account. Select Continue with Microsoft or Continue with Okta:
    • Microsoft. Your browser opens at the Microsoft sign-in page. Pick your work account.
    • Okta. A Work email field appears. Enter your work email address and select Continue with Okta again. FossID uses the email domain only to find your organization's Okta sign-in page; nothing is sent until you continue. Your browser then opens at your organization's Okta sign-in page.
  3. When the browser says Signed in to FossID, close the tab and return to the editor.

The window shows Checking your FossID connection to <server>… and then Connected to <server>. You're done.

See Signing in for details, including what to do if sign-in fails.

3. See your first findings​

Open any source file or dependency manifest (for example package.json, pom.xml or requirements.txt). FossID scans it in the background:

  • The FossID item in the status bar shows FossID scanning…, then either FossID: clean or FossID: N finding(s).
  • Findings appear in the Problems panel under the source FossID, and as squiggles in the editor.
  • In a manifest, each dependency gets a short annotation at the end of its line, such as → 4.17.21 ✓ or → 6.4.4, ⚠ 1 CVE (HIGH).

To scan everything at once, run FossID: Scan Workspace. See Scanning.

4. Set up your license policy​

The license rules need a policy to tell them which licenses are acceptable. Without one, FossID still reports vulnerabilities and modified license texts, but it doesn't flag any license as prohibited or conditional.

  • Open the FossID view in the Activity Bar and select License Policies to build a policy for this workspace. See License policy.
  • If your organization manages a central policy, turn on Remote Policy instead (setting fossid.remotePolicy.enabled). See Using your organization's policy service.

5. Connect your AI assistant (optional)​

After you sign in, FossID registers itself with Copilot, Claude Code and Cursor automatically. It does this by writing small configuration files into your workspace folder:

  • .vscode/mcp.json for Copilot;
  • .mcp.json for Claude Code;
  • .cursor/mcp.json for Cursor.

In Copilot Agent Mode or Claude Code, try:

  • "Scan this workspace and give me a risk overview."
  • "Find all files with GPL-3.0 licenses and push them to the Problems panel."

Cursor adds the servers in a disabled state. Enable fossid-mcp and fossid-editor once in Cursor's MCP settings.

See Using FossID with AI assistants.

Tip: The configuration files contain addresses specific to your machine and no credentials. The first time FossID writes them, it offers to copy the lines for your .gitignore. We recommend ignoring them:

.vscode/mcp.json
.mcp.json
.cursor/mcp.json

The FossID side bar​

Select the FossID icon in the Activity Bar to open the side bar.

  • Before you sign in, it shows the Setup view, with Set Up FossID and Contact FossID buttons. A badge on the icon reminds you that setup isn't finished.
  • After you sign in, it shows two views:
    • Policies, with links to Detection Rules and License Policies. Its … menu also holds FossID: Scan Workspace and FossID: Reconfigure.
    • Ignores, with a Manage Ignores link to the list of accepted exceptions.