{
  "name": "CodeRifts",
  "description": "Signed, offline-verifiable authorization for API-contract changes. Only a granted change can proceed. Three tools: preflight_change_set, verify_receipt, get_decision_details.",
  "supportedInterfaces": [
    {
      "url": "https://app.coderifts.com/mcp",
      "protocolBinding": "MCP",
      "protocolVersion": "1.0"
    },
    {
      "url": "https://app.coderifts.com/api/v1/preflight",
      "protocolBinding": "REST",
      "protocolVersion": "1.0"
    }
  ],
  "provider": {
    "organization": "CodeRifts",
    "url": "https://coderifts.com"
  },
  "version": "1.0.3",
  "documentationUrl": "https://coderifts.com/docs",
  "capabilities": {
    "streaming": false,
    "pushNotifications": false,
    "extendedAgentCard": false,
    "extensions": [
      {
        "uri": "https://coderifts.com/.well-known/coderifts.json",
        "description": "Platform limits and which calls take a key. The card is discovery, not permission.",
        "required": false,
        "params": {
          "does_not_prove": [
            "Evidence is RECORDED — a pinned capture, replayed — not a live provider run.",
            "proof_scope TRUSTED_EXECUTOR, provider_witness NOT_APPLICABLE, externally_witnessed false: CodeRifts did not witness or sign a provider state.",
            "Not externally witnessed, and not PATH B. The GitHub provider-loop is a separate claim.",
            "The grant does not bind the canonical tool-call bytes, so what-was-called is not proven equal to what-was-authorized (planned, not available).",
            "There is no single cross-domain evidence bundle over grant, measurement and supply chain (planned / on request, not available).",
            "A downstream agent is not given a strictly narrower grant than its caller held — delegation attenuation is not available.",
            "No DSSE or in-toto envelope is emitted by any published artifact.",
            "The published tool-surface digest establishes what the server serves now. It does not establish that an existing client connection runs that list: clients may cache the tool list for the life of a connection, and expiry behaviour differs by client and is undocumented (measured: anthropics/claude-code#97369; on claude.ai the saved approval is keyed on a hash of the description and top-level parameter descriptions — a type, enum or required change does not reset it)."
          ],
          "does_not_prove_scope": "platform",
          "speaks_a2a": false,
          "authentication": {
            "mechanism": "Bearer token via X-API-Key header or Authorization: Bearer",
            "key_required": {
              "analyze": false,
              "verify_receipt": false,
              "authorize": true,
              "get_decision_details": false
            }
          }
        }
      }
    ]
  },
  "securitySchemes": {
    "apiKey": {
      "apiKeySecurityScheme": {
        "description": "Bearer token via X-API-Key header or Authorization: Bearer",
        "location": "header",
        "name": "X-API-Key"
      }
    },
    "bearer": {
      "httpAuthSecurityScheme": {
        "description": "Bearer token via X-API-Key header or Authorization: Bearer",
        "scheme": "Bearer"
      }
    }
  },
  "defaultInputModes": [
    "application/json"
  ],
  "defaultOutputModes": [
    "application/json"
  ],
  "skills": [
    {
      "id": "preflight_change_set",
      "name": "preflight_change_set",
      "description": "Use this when: a contract artifact (OpenAPI, GraphQL, protobuf, AsyncAPI, MCP manifests, or agent tool schemas) changes before merge, deploy, publish, or tool registration; AND any agent-executed operation with no supported contract type — send type agent_operation. Do not call for documentation-only changes, static readiness scoring, or receipt verification. Use analyze for risk only; authorize requires context.operation. Skipping this call is not permission. Absence of a key is not permission. Inputs: preflight_mode is required: \"analyze\" (risk only; no receipt, no execution_action) or \"authorize\" (may mint a receipt; requires context.operation — merge is not deploy is not publish). Supply exactly one artifact source: artifacts[] (1–20 items, each {id, type, before, after} as the FULL spec/schema text, not a path or URL; type is openapi|graphql|grpc|asyncapi|mcp_manifest|agent_tools|agent_operation) XOR derivation=\"server\" (server reads GitHub Compare; needs context.repository + context.base + context.head; sending artifacts[] together is 400). Grant fields sit in one object, execution_grant_request {include_execution_grant, grant_version, tenant_id, executor_id, adapter_id, target_uri, expected_state_token, state_nonce, audience, policy_hash}; analyze ignores it; required is preflight_mode only. previous_receipt is a chain token base64url(body).base64url(signature) to LINK a prior decision — it does not re-verify; use coderifts.verify_receipt instead; for details of a past decision use coderifts.get_decision_details instead. idempotency_key replays authorize only (24h), never analyze.",
      "tags": [
        "analyze",
        "authorize"
      ]
    },
    {
      "id": "verify_receipt",
      "name": "verify_receipt",
      "description": "Verify a CodeRifts signed chain-receipt you ALREADY HOLD: cryptographic\nauthenticity (signature + key id), body binding, and — when lifecycle indices\nare available — whether it is currently valid authorization (not expired,\nsuperseded, or revoked) for a stated operation/target.\n\nUse this when:\n- You already obtained a chain_receipt / receipt token from a prior preflight\n  (or CI artifact) and are about to act (merge/deploy) under that receipt.\n- A contract-gate or policy requires offline/online proof that the receipt is\n  authentic for this change before proceeding.\n- You must distinguish \"signature ok\" from \"currently authorized\" (stale or\n  superseded receipts must not be treated as live approval).\n\nDo not use when:\n- You do not have a receipt yet — call coderifts.preflight_change_set first.\n- You need a NEW decision for a changed base→head set — preflight again;\n  verify_receipt does not re-diff specs.\n- The receipt you hold binds a different operation or target than the one you\n  are about to perform — call coderifts.preflight_change_set with\n  context.operation set to that operation (a merge receipt does not authorize\n  a deploy); verify_receipt cannot re-scope or re-issue a decision.\n- You only need human-readable history of an old decision_id without a receipt\n  token — use coderifts.get_decision_details.\n- The change set itself is unknown or incomplete — fix the change set and\n  preflight; do not \"verify\" a placeholder.\n\nInputs: receipt token (required); target_id = decision_result.artifact_digest — required\nfor an authorization verdict; omitted → target_not_stated. Optional intended context\n(operation, environment, fingerprint, audience, repository/branch/pull_request, base/head)\nand the body_hash-bound decision_result envelope. 30s clock-skew leeway on expiry. A 0s\ngrace for declared destructive production operations is defined in the policy but\nis unreachable today: the intended-context schema has no destructive field, so\nnothing can declare one and the 30s leeway always applies.\nReturns { valid, status, currently_authorized (bool|null), reason, payload, authz_* }.\nBranch on currently_authorized; null = not evaluated.\n\nWhen a decision envelope is also in hand (e.g. from a prior preflight), its\ncontrol_envelope.next_agent_step (if present) is structured remediation guidance\nthe agent MAY follow after a non-CONTINUE decision — still branch on\nexecution_action; next_agent_step is suggestion, not permission.",
      "tags": [
        "verify",
        "receipt"
      ]
    },
    {
      "id": "get_decision_details",
      "name": "get_decision_details",
      "description": "Retrieve a PAST CodeRifts decision by exactly one identifier\n(case_id | decision_id | fingerprint): full report, breaking changes, scores,\nand linked receipt metadata if stored.\n\nUse this when:\n- You have a decision_id (or fingerprint) from a previous preflight, PR\n  comment, or CI log and need to inspect or explain that past decision.\n- You are auditing why a prior ALLOW/WARN/BLOCK was issued.\n- You are NOT requesting a new analysis of current before/after specs.\n\nDo not use when:\n- You need a decision for the CURRENT uncommitted or PR head change set —\n  call coderifts.preflight_change_set with the current artifacts.\n- You hold a receipt token and only need cryptographic/lifecycle verification —\n  use coderifts.verify_receipt.\n- You have no identifier — run preflight first to create one.\n\nInputs: exactly one of case_id, decision_id, or fingerprint. {} → INVALID_INPUT;\ntwo identifiers → LOOKUP_IDENTIFIER_CONFLICT; case_id → CASE_NOT_FOUND\n(lookup never opens a case). Returns the stored document or not_found.\n\nScoping — fingerprint lookup returns only YOUR OWN decisions. A fingerprint is\nderived from content, not from an account, so two callers who preflight\nbyte-identical specs derive the same one; the lookup is therefore constrained\nto the decisions your credential can prove it owns.\n\nA decision that exists but is not yours returns the SAME not_found as one that\nwas never issued. This is deliberate: a distinguishable \"exists but forbidden\"\nwould confirm to any caller that a given content hash had been decided on by\nsomeone, which is the fact the scoping exists to withhold. Do not read\nnot_found as proof that no such decision exists anywhere.\n\nDecisions persisted without context.repository cannot currently be attributed\nto an account, and are not retrievable by fingerprint at all — not by their\nowner either. Retrieve those by decision_id, which is unchanged and unscoped.\nThis is a limitation of what older stored rows carry, not a property of the\nlookup: rows written from now on record the account directly, so the gap\nnarrows as older rows age out. If a fingerprint you expect returns not_found,\nuse the decision_id before concluding the decision is missing.\n\nWhen the stored envelope carries control fields, control_envelope.next_agent_step\nis structured remediation guidance the agent MAY follow for non-CONTINUE\nexecution_action values (null on CONTINUE*). Still branch on execution_action;\nnext_agent_step is a suggestion, not permission.",
      "tags": [
        "decision"
      ]
    }
  ]
}
