Skip to main content

🚀 Beta: All Pro and Team features are free. Install on GitHub →

Governance features.
One PR comment.

From breaking change detection to compliance enforcement.

Prefer GIF? Open demo-pr-recording.gif

Real PR comment from coderifts/demo#2

📈

Risk and health signals

Parent module

🔍

Breaking Change Detection

Core diff engine for OpenAPI 3.0 and 3.1 schemas.

Detects endpoint removals, required field additions, response type changes, enum restrictions, auth changes, parameter modifications, and more.

Evidence

📂

Auto-Discovery

Automatically finds OpenAPI spec files in your repo.

No configuration needed. CodeRifts scans your repository for .yaml, .yml, and .json files matching OpenAPI patterns.

Evidence

🏷️

Semver Suggestion

Recommends MAJOR/MINOR/PATCH based on change severity.

Reads your current version from the spec and suggests the correct next version based on the breaking changes detected.

Evidence

📊

API Surface Stats

Docs on request

Endpoint, field, and schema counts in every PR.

Shows your total API surface area and how the PR changes it, so you always know the scope of your API.

📋

Breaking Changes Table

Structured table of every breaking change with details.

Each breaking change gets its own row with endpoint, risk level, action type, and a link to the specific diff.

Evidence

💡

Free tier

Free tier capabilities

🔄

Lifecycle Labels

Docs on request

Tags each change: new-endpoint, field-removed, deprecated, etc.

Every change in the breaking changes table gets a lifecycle icon showing whether it's new, modified, deprecated, or removed.

REST in Peace: a dedicated memorial section for removed endpoints.

✔️

Commit Consistency Check

Docs on request

Validates PR title matches the suggested version bump.

Warns when breaking changes are detected but the PR title doesn't include a version bump indicator like feat!:.

🌐

Web UI, CLI & REST API

Three ways to use CodeRifts: browser, terminal, or API.

Try in the browser with no signup, run locally via CLI, or integrate into any CI/CD pipeline via the REST API.

Evidence

📈

Risk and health signals

Parent module

🎯

4D Risk Score

Docs on request

Composite 0–100 score across severity, surface, auth, and stability.

Each PR gets a single risk number combining breaking change severity, affected surface area, authentication impact, and historical stability. Color-coded gauge included.

35/100
📏

Confidence Score

Docs on request

How certain is the analysis? 0–100 confidence rating.

Factors in spec completeness, change specificity, and engine agreement. Low confidence triggers a warning so you know when to double-check.

📐

Stability Grade

A+ to F grade based on recent breaking change history.

Tracks your API's breaking change frequency over the last 30 days. Fewer breaks = higher grade. Shown as a letter grade with trend arrow.

Evidence

A
↑ Stable
🧩

Change Intent Classifier

Docs on request

Tags each change as structural, behavioral, or security.

Uses change codes and heuristics to classify intent. Structural changes affect shape, behavioral changes affect logic, security changes affect auth.

Structural Behavioral Security
🔒

Auth Downgrade Detection

Docs on request

Flags when endpoints lose authentication requirements.

Detects when OAuth2 is downgraded to API key, when bearer tokens are removed, or when security schemes are weakened. Severity-rated.

⚠ Auth Downgrade
🔐

Scope & Permission Tracker

Docs on request

Detects OAuth scope changes and permission model shifts.

Tracks when scopes are added, removed, or renamed. Warns when permission boundaries change in ways that could affect API consumers.

🤖

AI-Generated Spec Safety

Detects when specs are AI-generated and flags common AI mistakes.

Identifies patterns typical of LLM-generated OpenAPI specs: hallucinated endpoints, inconsistent naming, missing security schemes, and overly generic descriptions.

Evidence

⚙️

Generator-Aware Risk

Adjusts risk scoring based on spec generator (Swagger Codegen, OpenAPI Generator, etc.).

Detects the generator used and adjusts confidence and risk scores based on known generator quirks and limitations.

Evidence

🛡️

PII Detection

Docs on request

Scans new fields for personally identifiable information.

Detects fields like ssn, credit_card, passport in new or modified schemas. Flags before merge with GDPR/CCPA compliance warning.

GDPR CCPA
📊

Breaking Change Density Score

Docs on request

Measures breaking changes relative to API size.

Score 0–100. A small API with 3 breaks scores higher than a large API with 3 breaks. Critical density triggers automatic block.

Density: 72/100
🧭

Pro tier

Pro tier capabilities

📏

API Design Lint

Naming conventions, pagination, error consistency checks.

8 lint rules covering camelCase, pagination patterns, error response formats, and more. Warnings shown in a collapsible section.

Evidence

📝

Auto-Changelog

Categorized changelog: breaking, added, changed, deprecated.

Every PR gets a structured changelog grouped by change type, ready to copy into your release notes.

Evidence

Deprecation Lifecycle Tracker

Docs on request

Tracks deprecated endpoints from announcement to removal.

Monitors x-deprecated and x-sunset headers. Warns when deprecated endpoints are removed without the sunset period completing.

📖

Documentation Coverage Score

Docs on request

A–F grade for spec completeness: descriptions, examples, schemas.

Scores your OpenAPI spec across 5 dimensions: descriptions, examples, error responses, schema completeness, and parameter documentation. Shows delta from base.

📄

Docs Drift Detection

Docs on request

Warns when schema changes happen without documentation updates.

Checks if README, CHANGELOG, or API docs were updated alongside schema changes. Flags PRs that skip documentation.

🏰

Heritage Mode

Docs on request

Versioning suggestions for existing endpoints.

Detects high change density PRs and recommends version bumps or deprecation plans for heavily modified endpoints.

📁

CODEOWNERS Suggestion

Docs on request

Auto-generates CODEOWNERS based on domain ownership config.

When no CODEOWNERS file exists, suggests one based on the domain ownership mapping in your .coderifts.yml.

🔀

Versioning Strategy

URL vs header versioning analysis and recommendation.

Detects your versioning approach (URL path, header, query param) and flags inconsistencies or missing version indicators.

Evidence

💡

Compatibility Mode Suggestions

Docs on request

Suggests backward-compatible alternatives to breaking changes.

When a breaking change is detected, suggests a backward-compatible alternative instead of just blocking. Includes code examples and migration paths.

📈

Risk and health signals

Parent module

📋

Migration Assessment

Docs on request

Estimates consumer migration effort: hours, complexity, affected endpoints.

For each breaking change, estimates the migration effort for API consumers. Factors in change type, endpoint popularity, and complexity.

🏆

Governance Health Grade

Docs on request

A–F grade for your API governance posture.

Composite score across policy compliance, exception usage, deprecation adherence, and documentation quality. Shown as a letter grade.

⏱️

PR Review Insights

Docs on request

Time to first review, reviewer load, PR size analysis.

Tracks review patterns for API-related PRs. Shows time to first review, number of review rounds, and PR size classification.

🚩

Feature Flag Cleanup

Detects stale feature flags across 6 languages, 19 patterns.

Scans changed files for feature flag patterns. Flags stale and aging flags with configurable thresholds.

Evidence

👻

Shadow API Detection

Docs on request

Identifies high-change-density endpoints that may be undocumented.

Flags endpoints with many changes in a single PR, suggesting they may be shadow APIs that need proper documentation.

🔄

Overlap Detection

Detects other open PRs modifying the same schema files.

Warns when multiple open PRs touch the same OpenAPI spec, preventing merge conflicts and governance gaps.

Evidence

🧠

Neural Drift Engine

6 neural patterns: latency, signal loss, noise, auth decay, token inflation, payload erosion.

Part of the traffic-capture roadmap: LATENCY_DRIFT, SIGNAL_LOSS, SYNAPTIC_NOISE_RISE, AUTH_CONDUCTION_DECAY, TOKEN_INFLATION, and PAYLOAD_EROSION require live traffic data and are not detected on static specs today. Each pattern maps API behavioral changes to neural network analogies for intuitive risk assessment.

🔍

Semantic Drift Detection

Docs on request

4 patterns: field semantic change, endpoint semantic change, response contract drift, default value drift.

Detects FIELD_SEMANTIC_CHANGE, ENDPOINT_SEMANTIC_CHANGE, RESPONSE_CONTRACT_DRIFT, and DEFAULT_VALUE_SEMANTIC_CHANGE. Goes beyond structural diff to detect when the meaning of fields or endpoints changes even if the schema stays the same.

⚖️

Synaptic Weight Engine

Docs on request

Neural hotspot map showing endpoint criticality weights.

Assigns synaptic weights to each endpoint based on usage patterns, change frequency, and downstream dependencies. Generates a neural hotspot map to visualize which endpoints carry the most risk.

👻

Shadow Agent Detection Beta — docs on request

Docs on request

Detect unauthorized or undocumented agent integrations.

POST /api/v1/shadow-agent/detect — Scans API traffic patterns and spec changes to identify shadow agents: unauthorized integrations that bypass governance controls.

📡

Axiom Monitor Beta — docs on request

Docs on request

Real-time API axiom health status dashboard.

GET /api/v1/axiom/status — Monitors core API axioms (backward compatibility, idempotency, versioning) and reports violations in real time.

📋

Policy Compliance Index Beta — docs on request

Docs on request

Aggregate compliance score across all governance rules.

GET /api/v1/compliance/index — Calculates a weighted compliance score across all active governance policies. Tracks score trends over time for audit reporting.

💰

Token Cost Engine

Docs on request

token_cost_impact field included in OpenAPI diff responses.

OpenAPI diff responses include token_cost_impact showing how API changes affect LLM token consumption. Helps teams understand the cost implications of schema changes for AI-powered consumers.

📦

SDK Surface Coverage

Docs on request

Tracks which endpoints are covered by generated SDKs.

Cross-references your OpenAPI spec with generated SDK clients. Flags endpoints missing from SDKs and new endpoints that need SDK updates.

🔄

Generated Spec Drift

Docs on request

Detects when generated specs diverge from the source of truth.

If your spec is auto-generated from code annotations, detects when manual edits create drift between the generated and committed versions.

🛡️

Policy controls and routing

Parent module

📜

Policy Engine

YAML-defined rules: max breaking changes, required deprecation periods, auth requirements.

Define governance rules in .coderifts.yml. The engine evaluates every PR against your policies and blocks merges that violate them.

Evidence

❄️

Freeze Windows

Block breaking changes during release freezes or peak traffic periods.

Configure date ranges when breaking changes are prohibited. PRs opened during freeze windows get a hard block with the freeze reason.

Evidence

Approval Matrix

Require specific approvers for high-risk changes.

Configure who must approve based on risk level: security changes need @security-team, auth changes need @platform-lead.

Evidence

🏠

Domain Ownership

Map API paths to team owners for targeted notifications.

Define which team owns which API paths. Breaking changes to /payments/* notify @payments-team automatically.

Evidence

🛡️

Exception Lifecycle Manager

Docs on request

Time-boxed exceptions for policy violations with audit trail.

Grant temporary exceptions to governance rules. Each exception has an owner, expiry date, and reason. Expired exceptions auto-revoke.

📊

Breaking Budget

Set a maximum number of allowed breaking changes per PR.

Configure a breaking change budget in your policy. PRs exceeding the budget get a policy violation with the count and limit shown.

Evidence

🌿

Branch Risk Profiles

Docs on request

Different risk tolerance per branch pattern.

hotfix/* gets 2x budget, experiment/* never blocks, main/* zero tolerance. Configure per-branch governance rules in .coderifts.yml.

🛡️

MigraGuard

Opt-in migration gate for database and schema migrations.

Reads database migration files and the application source references they touch — processed in memory, never persisted — and gates unsafe migrations before they merge.

Evidence

⚙️

ActionGuard

Opt-in workflow gate for GitHub Actions changes.

Compares the uses: action references between a workflow's base and head and reports unpinned refs, pin drift, unverifiable pin claims, major-version jumps and new third-party actions. Diff-based only — pre-existing unchanged refs are not re-flagged. Findings are WARN-tier: ActionGuard can raise a check to neutral, and never on its own to failure.

Evidence

🚫

Inhibitory Neuron Filter

Docs on request

Suppress known-safe findings to reduce noise.

POST /api/v1/findings/suppress — Mark specific findings as suppressed so they don't trigger alerts. Like inhibitory neurons in the brain, these filters prevent signal overload from known-safe changes.

🗂️

Tool Schema Registry

Version agent tool schemas and catch breaking drift before redeploy.

POST /api/v1/registry/tool-schemas registers and versions a tool schema. /check compares a new version against the registered production schema and returns ALLOW/WARN/BLOCK with the breaking changes. Breaking drift is logged as an incident (GET /api/v1/registry/incidents) and can trigger a webhook alert.

Evidence

Public trust signals

Parent module

🎖️

API Stability Badge

4 embeddable SVG badges for README: stability, streak, governance, risk.

Shields.io-style badges generated server-side. Embed in your README to show your API's governance posture.

Evidence

A+ Stability 42d Streak A Governance
🎖️

Agent-Safe Badge & Verification

Embeddable compliance badge for your README.

GET /api/v1/badge/compliant returns an SVG badge showing AGENT-SAFE, WARN, or BREAKING grade. GET /api/v1/verify/compliant returns full Decision Spec v1.0 verification — this endpoint intentionally serves the legacy v1.0 shape for backward compatibility; the platform contract is Decision Spec 2.0, and agents should branch on execution_action from the preflight API. Learn more.

Evidence

🤝

Team tier

Team tier capabilities

🌐

A2A Protocol Governance Beta — docs on request

Docs on request

Agent-to-Agent protocol diff and pipeline simulation.

POST /api/v1/a2a/diff compares A2A agent cards for breaking changes. POST /api/v1/a2a/simulate runs multi-step pipeline simulations to detect cascading failures across agent chains.

🔄

Cross-Spec Compatibility Beta — docs on request

Docs on request

Compare specs across formats: OpenAPI, AsyncAPI, GraphQL, gRPC.

POST /api/v1/cross-spec/diff — Detects breaking changes when migrating between API specification formats. Supports OpenAPI 3.x, AsyncAPI 2.x, GraphQL SDL, and Protocol Buffers.

🔌

MCP Server (Streamable HTTP)

Claude Desktop compatible MCP server over Streamable HTTP.

GET /mcp — Full Model Context Protocol server exposing exactly three MCP tools via Streamable HTTP. Compatible with Claude Desktop, Cursor, and any MCP-capable AI agent. JSON-RPC 2.0 protocol.

Evidence

📈

Risk and health signals

Parent module

🌍

External API Drift Monitor

Track third-party API specs and alert on undocumented changes.

Monitor external APIs your services depend on. Get notified when upstream providers introduce breaking changes before they hit production.

🔗

Multi-Repo Compatibility Guard

Cross-repo breaking change detection.

When a spec change in repo A breaks a consumer in repo B, CodeRifts flags it before either PR merges.

👥

Consumer-Aware Risk Scoring

Risk scoring based on actual consumer data.

Integrate with your API gateway to weight risk scores by real traffic volume, active consumers, and revenue impact.

📉

Historical Drift Intelligence

Risk time-series and stability decay tracking.

Track how your API stability evolves over weeks and months. Spot decay patterns before they become incidents.

🛡️

Policy controls and routing

Parent module

📚

Org-Level API Registry

Company-wide API catalog and portfolio view.

A single pane of glass for every API in your organization: ownership, stability grade, governance health, and change history.

📜

Compliance Ledger Beta — docs on request

Full audit trail: who changed what, when, and impact.

Immutable log of every API change, approval decision, and exception grant. SOC 2 and PCI-DSS aligned reporting.

🔌

Custom Integrations API

Webhooks and REST API for custom governance workflows.

Build custom integrations with your internal tools. Trigger workflows, sync data, and extend CodeRifts with your own logic.

🏢

Enterprise tier

8 features — 7 coming Q3 2026, notifications shipped

📢

Slack & Teams Notifications

Shipped: webhook alerts for breaking changes and BLOCK verdicts.

Configure in .coderifts.yml under notifications: Slack and Teams webhook URLs, trigger on breaking, all, or high-risk changes, mute selected repos. BLOCK decisions can also notify via environment-level webhooks with no config file.

Ready to protect your APIs?

Free during beta. No credit card required. Start with 9 features, upgrade when you need more.