Works with
Each row names one surface, the sentence measured for it, and where that sentence stops.
GitHub
On GitHub, a required check refuses the merge until a receipt for that diff verifies on the runner; the receipt names the operation it was granted for (merge, deploy, publish or a tool call) and expires.
a check is a lock only when it is required on the default branch, bound to the right app, bypass closed, SHA pinned — without all four it is a comment
https://github.com/marketplace/coderifts
https://github.com/marketplace/actions/coderifts-contract-gate
Claude Code
The coderifts marketplace lists plugin api-governance at version 1.1.2, and that plugin carries the skill.
The same marketplace also lists agent-hooks at version 0.2.0, which is the PreToolUse hook the install page installs.
A search of the Claude marketplace for coderifts on 2026-10-03 returned the heading No plugins for those filters.
https://github.com/coderifts/api-governance
https://claude.com/marketplace/plugins?q=coderifts
Cursor
The Cursor plugin coderifts-api-governance at version 1.0.1 is in the same repository. cursor.directory returned HTTP 429 on 2026-10-03, so this page does not say that directory lists it.
https://github.com/coderifts/api-governance/tree/main/plugins/api-governance-cursor
OpenAI
Measured 2026-09-29, ChatGPT Plus, in the EU. A personal MCP app connected to https://app.coderifts.com/mcp with no authentication. One analyze call came back. No receipt was issued.
Authorize was not called.
The Codex plugin manifest api-governance-openai at version 1.0.1 is in the repository. This round did not call Codex.
oasdiff
Built on oasdiff for OpenAPI; we add the grant at a required check, and the same gate for MCP tool manifests.
The OpenAPI 3.1 path selects oasdiff 1.11.11. The upstream LICENSE is Apache-2.0. The app THIRD_PARTY_NOTICES.md does not name oasdiff.
https://github.com/Tufin/oasdiff
https://www.oasdiff.com/pricing
Kyverno
The Kyverno policy at examples/kyverno-decision.yaml is an example in coderifts/contract-gate. This round did not measure another installation.
examples/kyverno-decision.yaml
Sigstore and in-toto
Provenance says how it was built; the receipt says whether it was allowed.
No DSSE or in-toto envelope is emitted by any published artifact.
The layout in examples/decision.layout does not verify until a second distinct public key is added.
The predicate type in examples/attest-decision.yml is https://coderifts.com/attestations/decision/v1.
Alongside
CodeRabbit runs oasdiff version 1.32.1 and reports supported breaking API changes as review comments. oasdiff is enabled by default.
CodeRabbit comments on a breaking OpenAPI change; a required CodeRifts check keeps it from merging.
The CodeRabbit page posts findings as review comments. It does not say a CodeRabbit comment blocks the merge.