> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://contentful.com/developers/docs/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://contentful.com/_mcp/server. # CLI security check > This tutorial explains how you can use the `sec-check` command to assess your Contentful organization's security posture. You can use the `sec-check` command to quickly assess your Contentful organization's security posture. It runs out-of-the-box with the following check points: * Permissions. Only an organization admin or owner can perform the security check. * Security contact configured * Audit logging enabled * Long-expiry access tokens * SSO enabled * SSO enforced * SSO exempt users identified * MFA status for exempt users | Check | Description | | ------------------------------------ | -------------------------------------------------------------------------------------------- | | `permission_check` | Validates if the user has the required permissions (owner/admin) to perform security checks. | | `security_contact_set` | Ensures at least 1 security contact is configured. | | `audit_logging_configured` | Confirms audit logging is enabled. | | `active_tokens_with_long_expiry` | Flags active access tokens whose expiration date is more than 1 year in the future. | | `sso_enabled` | Validates SSO is enabled. | | `sso_enforced` | Validates SSO restricted mode is on. | | `sso_exempt_users` | Flags users exempt from SSO enforcement. | | `sso_exempt_users_with_mfa_disabled` | Flags SSO-exempt users without MFA. | Each check delivers clear **PASS**/**FAIL** results with actionable data. ## Prerequisites * Locally [installed](/tutorials/cli/installation) `contentful-cli`. * [Authenticated](/tutorials/cli/authentication) with `contentful-cli`. * A [Contentful Management API token](/references/content-management-api/overview) with organization admin or owner permissions to read organization settings. ## Usage ``` Usage: contentful organization sec-check --organization-id Options: -h, --help Show help [boolean] --organization-id, --oid Contentful organization ID [string] [required] --management-token, --mt Contentful management API token (overrides stored context token) [string] --header, -H Pass an additional HTTP Header [string] --output-file, -o Write JSON results to a file. If used without a filename, a default file ./data/--sec-check.json is created. [string] ``` ### Example ``` contentful organization sec-check --organization-id 123456789 -o ``` ![The security check output](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/contentful.docs.buildwithfern.com/9137fade56227a5f11316c29622ea71c17367f68f11599984f4036b2b07ab0b7/docs/assets/images/cli-security-check.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260930%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260930T003701Z&X-Amz-Expires=604800&X-Amz-Signature=fde46c84319a839fb68ac49661c9620fdd13b547f070b94ac87c855c892ac944&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject) The results can be exported as a JSON file with a single flag `-o`, making it easy to archive, track changes over time, or integrate with monitoring dashboards. Each failing check includes contextual details (counts, affected IDs) to help with troubleshooting. ### Output JSON with fields: ```json { "permission_check": { "description": "User has owner or admin role in the organization", "pass": true }, "security_contact_set": { "description": "Security contact is configured for the organization", "pass": true, "data": { "contactCount": 1 } }, "audit_logging_configured": { "description": "Audit logging is configured for the organization", "pass": true, "data": { "itemCount": 1 } }, "active_tokens_with_long_expiry": { "description": "Active (not revoked) access tokens whose expiration date is more than 1 year in the future.", "pass": false, "data": { "offendingCount": 6 } }, "sso_enabled": { "description": "SSO is enabled for the organization", "pass": true }, "sso_enforced": { "description": "SSO is enforced (restricted) for the organization", "pass": true }, "sso_exempt_users": { "description": "Check if users are exempted from SSO restricted mode (bypass SSO).", "pass": false, "data": { "exemptUserIds": [ "2qEuWkv9GLQ8ypPK96xjZk" ], "exemptCount": 1 } }, "sso_exempt_users_with_mfa_disabled": { "description": "Exempt users have MFA (2FA) enabled (reports users without MFA).", "pass": false, "data": { "mfaDisabledUsers": [ { "id": "2qEuWkv9GLQ8ypPK96xjZk", "email": "hussam.khrais+test@foo.com" } ], "mfaDisabledCount": 1 } } } ``` ## Next steps * [Check out the documentation in the GitHub repository](https://github.com/contentful/contentful-cli/tree/main/docs/organization/sec-check/) * [Learn more about access tools](https://www.contentful.com/help/admin/access-tools/) * [Learn more about access tokens](/references/content-management-api/overview) * [Learn more about token management](https://www.contentful.com/help/token-management/) * [Learn more about SSO (Single-Sign On)](https://www.contentful.com/help/faq/sso/) > This tutorial explains how you can use the `sec-check` command to assess your Contentful organization's security posture.