FAQ
What does CodeRifts do, in one sentence?
On a boundary that requires it, a contract change does not cross without a signed grant for that exact change set.
/blog/receipt-dora-nis2-ai-act/
What does a receipt prove, and what does it not?
The open verifier checks it offline against a pinned key snapshot — no account, no call to us. A decision is an authorisation answer for the submitted request, not an observation that anything was merged, deployed or published.
/blog/receipt-dora-nis2-ai-act/
Do you store my code or my spec?
Repository and branch identifiers are stored; spec content is not. Core Diff reads configured specification files, and opt-in MigraGuard/ActionGuard read configured migration files, application source references and workflow YAML, in memory only; none of that file content is persisted
What happens if your server is down — does the check pass or fail?
Measured 2026-10-02 with our API unreachable, timing out, or answering 5xx: on the enforcing profile, a head commit that carries a valid signed receipt for its own diff still passes offline without calling us, and every other case fails closed (the contract-gate check concludes failure); if the CodeRifts App cannot post its `CodeRifts / issuer` run, a repository that requires that context stays blocked as "Expected — waiting for status", GitHub's documented behavior for a required check that never reports.
/docs/enforcement-status/#api-unreachable
Does it work on private repositories?
Free authorization requires a provider-verifiable public repository. Authorize and enforce private contract changes at supported boundaries.
What does it cost?
Free $0; Team $149/month after beta (Team is $0 during public beta); Enterprise from $1,500/month. No Pro tier is sold.
Which contract formats?
CodeRifts reads the diff of the contracts a pull request touches — OpenAPI, GraphQL, protobuf, AsyncAPI and MCP tool manifests, together as one change set
/blog/receipt-dora-nis2-ai-act/
How is this different from a breaking-change linter (oasdiff, Optic, Spectral)?
Use oasdiff if you only need the structural delta in a CI pipeline you assemble yourself. On GitHub, a required check refuses the merge until a receipt for that diff verifies on the runner; the receipt names the operation it was granted for (merge, deploy, publish or a tool call) and expires.
/compare/oasdiff/ /blog/receipt-dora-nis2-ai-act/
What changes in an MCP server's tools does it catch?
classifies what breaks (a removed field, a parameter that became required, a narrowed enum, a tool whose description gained an instruction)
/blog/receipt-dora-nis2-ai-act/
Who approves — does the receipt name the person?
It does not prove the receipt names a person. Line five says the approver is not in the signature.
Can I verify a receipt without you?
The open verifier checks it offline against a pinned key snapshot — no account, no call to us.
/blog/receipt-dora-nis2-ai-act/
Is it DORA / AI Act compliant?
A receipt alone does not satisfy Article 9(4)(e); it is one record inside a process that does. It does not assign or evidence human oversight.
/docs/evidence/record-keeping/ /blog/receipt-dora-nis2-ai-act/
Who requires it today?
No external repository requires the check yet.
/blog/receipt-dora-nis2-ai-act/
How do I start?
Analysis is free and needs no account; the check is on the GitHub Marketplace
/blog/receipt-dora-nis2-ai-act/ https://github.com/marketplace/actions/coderifts-contract-gate /install/