Welcome to the user documentation for Threat Model Forge (tmforge), a cross-platform
toolkit for authoring, validating, and reporting on .tm7-compatible threat models: in the
browser, in the terminal, and in CI. It is an open, automatable successor to the Windows-only
Microsoft Threat Modeling Tool (MTMT).
| If you want to | Read |
|---|---|
| Try it right now, no install (runs in your browser) | Live demo |
| Understand what the platform is and its features | Overview & features |
| Get running in a few minutes | Quick start |
| Install the CLI, container, or global tool | Installation |
| Guide | What it covers |
|---|---|
| Overview & features | Concepts, the three surfaces (CLI, Studio, API), formats, and rules at a glance. |
| Quick start | Author, analyze, and report on your first model. |
| Installation | Prebuilt binaries, container images, the .NET global tool, and building from source. |
| CLI reference | Every tmforge command, its options, exit codes, and JSON output. |
| Studio guide | Browser-based diagram authoring with the React Studio SPA. |
| Engine API reference | The versioned /v1 HTTP surface and its endpoints. |
| Formats & interoperability | .tm7, tmforge-json, draw.io, and Visio import/export and fidelity. |
| Analysis rules & CI | The built-in rule set, rule packs, suppressions, and gating a build. |
| Deployment | Running the engine API + Studio in containers, Kubernetes, and CI/CD. |
Threat Model Forge is one engine with three faces, so the same model behaves identically whether you drive it from a shell, a browser, or over HTTP.
- CLI (
tmforge): headless, scriptable authoring, validation, reporting, and conversion. - Studio: a React single-page app for drawing data-flow diagrams, served by the API.
- Engine API (
/v1): a versioned HTTP surface that hosts Studio and exposes the engine to any client.
- Project README: build, test, and contribution entry point.