Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,070Paid calls: 1,526Letters: 13Defects: 1,322counted 1 min ago
teppi

Server definition

Hash
sha256:06492dfa912e37457d25d4776b2dc60c3acffafeee5892ff01dcdb6ab799e589
What it is
What a remote MCP server returned when asked what it offers: 3 tools

The blob, as servednamed by its sha256

{ "instructions": "Signed, offline-verifiable authorization for API-contract changes. Only a granted change can proceed. Three tools: preflight_change_set, verify_receipt, get_decision_details. Analyze is not permission; branch on execution_action.", "tools": [ { "description": "Retrieve a PAST CodeRifts decision by exactly one identifier\n(case_id | decision_id | fingerprint): full report, breaking changes, scores,\nand linked receipt metadata if stored.\n\nUse this when:\n- You have a decision_id (or fingerprint) from a previous preflight, PR\n comment, or CI log and need to inspect or explain that past decision.\n- You are auditing why a prior ALLOW/WARN/BLOCK was issued.\n- You are NOT requesting a new analysis of current before/after specs.\n\nDo not use when:\n- You need a decision for the CURRENT uncommitted or PR head change set —\n call coderifts.preflight_change_set with the current artifacts.\n- You hold a receipt token and only need cryptographic/lifecycle verification —\n use coderifts.verify_receipt.\n- You have no identifier — run preflight first to create one.\n\nInputs: exactly one of case_id, decision_id, or fingerprint. {} → INVALID_INPUT;\ntwo identifiers → LOOKUP_IDENTIFIER_CONFLICT; case_id → CASE_NOT_FOUND\n(lookup never opens a case). Returns the stored document or not_found.\n\nScoping — fingerprint lookup returns only YOUR OWN decisions. A fingerprint is\nderived from content, not from an account, so two callers who preflight\nbyte-identical specs derive the same one; the lookup is therefore constrained\nto the decisions your credential can prove it owns.\n\nA decision that exists but is not yours returns the SAME not_found as one that\nwas never issued. This is deliberate: a distinguishable \"exists but forbidden\"\nwould confirm to any caller that a given content hash had been decided on by\nsomeone, which is the fact the scoping exists to withhold. Do not read\nnot_found as proof that no such decision exists anywhere.\n\nDecisions persisted without context.repository cannot currently be attributed\nto an account, and are not retrievable by fingerprint at all — not by their\nowner either. Retrieve those by decision_id, which is unchanged and unscoped.\nThis is a limitation of what older stored rows carry, not a property of the\nlookup: rows written from now on record the account directly, so the gap\nnarrows as older rows age out. If a fingerprint you expect returns not_found,\nuse the decision_id before concluding the decision is missing.\n\nWhen the stored envelope carries control fields, control_envelope.next_agent_step\nis structured remediation guidance the agent MAY follow for non-CONTINUE\nexecution_action values (null on CONTINUE*). Still branch on execution_action;\nnext_agent_step is a suggestion, not permission.", "inputSchema": { "additionalProperties": false, "description": "Closed exclusive identifier union: exactly one of case_id | decision_id | fingerprint. Encoded as minProperties=1 + maxProperties=1 + additionalProperties=false, NOT as a top-level oneOf/anyOf/allOf — Anthropic (and other strict tool APIs) reject those combinators at the root of input_schema and then refuse the entire tools array (measured: test/mcp-input-oneof-honesty.test.js, mcp-streamable.js comment). The server enforces the same mutex with named codes: empty {} → INVALID_INPUT; two or more identifiers → LOOKUP_IDENTIFIER_CONFLICT; case_id alone → CASE_NOT_FOUND (no case store yet; lookup never opens a case).", "maxProperties": 1, "minProperties": 1, "properties": { "case_id": { "description": "A case identifier. Lookup never opens a case. Until the case store exists this returns CASE_NOT_FOUND.", "minLength": 1, "type": "string" }, "decision_id": { "description": "The decision_id from a prior decision_result envelope. Provide exactly one identifier.", "minLength": 1, "type": "string" }, "fingerprint": { "description": "A verdict fingerprint (sha256:...); returns the latest matching decision you own. Provide exactly one identifier.", "minLength": 1, "type": "string" } }, "type": "object" }, "name": "get_decision_details", "outputSchema": { "additionalProperties": true, "description": "A stored CodeRifts decision: the original decision_result.v1 envelope + lookup meta. Retrieval-path control fields (safe_for_agent/execution_action/verdict_fingerprint/control_envelope) mirror the fresh preflight response and are present only when the stored envelope carries their source field. additionalProperties true: additive fields may appear and are not permission. Compatibility rule (single source): https://coderifts.com/schemas/decision-result.v1.consumer.json schema description.", "properties": { "breaking_changes": { "minimum": 0, "type": "integer" }, "chain_receipt": { "type": "string" }, "coderifts_version": { "type": "string" }, "control_envelope": { "description": "Control envelope (control/1.0) derived from the stored decision_result. Includes next_agent_step (structured remediation SUGGESTION for non-CONTINUE execution_action; null on CONTINUE*; not permission — still branch on execution_action).", "type": "object" }, "decision": { "enum": [ "ALLOW", "WARN", "REQUIRE_APPROVAL", "BLOCK" ], "type": "string" }, "decision_result": { "additionalProperties": true, "description": "decision-result.v1 envelope (control enums closed). Additive fields may appear and are not permission. Full schema: https://coderifts.com/schemas/decision-result.v1.consumer.json (producer: https://coderifts.com/schemas/decision-result.v1.producer.json).", "properties": { "audience": { "type": [ "string", "null" ] }, "authority": { "description": "Additive. { audience, tenant_scope: bound|unbound, binding_proven_at? }. Informational — not permission, not a verify-receipt gate, not an ACL.", "type": [ "object", "null" ] }, "base": { "type": [ "string", "null" ] }, "blast_radius": { "description": "Additive COUNTS (not a score). Not permission.", "properties": { "consumers_declared": { "minimum": 0, "type": "integer" }, "consumers_observed": { "minimum": 0, "type": "integer" }, "endpoints": { "minimum": 0, "type": "integer" }, "fields": { "minimum": 0, "type": "integer" }, "graph_source": { "type": "string" }, "params": { "minimum": 0, "type": "integer" } }, "type": "object" }, "decision": { "enum": [ "ALLOW", "WARN", "REQUIRE_APPROVAL", "BLOCK" ], "type": "string" }, "decision_body_hash": { "type": [ "string", "null" ] }, "decision_id": { "type": "string" }, "derivation": { "description": "Additive. Present only when derivation:\"server\" produced this envelope. { source, platform?, base_sha, head_sha }. Covered by body_hash; not fingerprint.", "type": [ "object", "null" ] }, "environment": { "type": [ "string", "null" ] }, "execution_action": { "enum": [ "CONTINUE", "CONTINUE_WITH_MONITORING", "REQUEST_APPROVAL", "STOP" ], "type": "string" }, "expires_at": { "type": "string" }, "fingerprint": { "type": "string" }, "head": { "type": [ "string", "null" ] }, "input_fingerprint": { "type": "string" }, "operation": { "type": [ "string", "null" ] }, "receipt": { "type": "object" }, "repository": { "type": [ "string", "null" ] }, "safe_for_agent": { "type": "boolean" }, "spec_version": { "pattern": "^decision-result\\.v1(\\.[0-9]+)?$", "type": "string" } }, "type": "object" }, "decision_semantic_hash": { "type": "string" }, "decision_spec_version": { "type": "string" }, "evidence": { "type": [ "object", "array", "null" ] }, "evidence_quality": { "type": "string" }, "execution_action": { "enum": [ "CONTINUE", "CONTINUE_WITH_MONITORING", "REQUEST_APPROVAL", "STOP" ], "type": "string" }, "meta": { "additionalProperties": true, "properties": { "created_at": { "type": "string" }, "decision_id": { "type": "string" }, "omitted_sections": { "type": "array" }, "retrieval_mode": { "enum": [ "stored" ], "type": "string" }, "source": { "type": "string" } }, "type": "object" }, "operation": { "type": "string" }, "pattern_sources": { "type": "array" }, "patterns": { "items": { "type": "string" }, "type": "array" }, "preflight_mode": { "enum": [ "analyze", "authorize" ], "type": "string" }, "receipt_kind": { "enum": [ "NONE", "operation_authorization" ], "type": "string" }, "required_action_core": { "description": "Branchable required-action core { type, reason_code, recheck_required } when present on the envelope.", "type": "object" }, "requires_migration": { "type": "boolean" }, "risk_score": { "maximum": 100, "minimum": 0, "type": "integer" }, "safe_for_agent": { "type": "boolean" }, "timestamp": { "type": "string" }, "verdict_fingerprint": { "type": "string" } }, "required": [ "decision_result", "meta" ], "type": "object" } }, { "description": "Use this when: a contract artifact (OpenAPI, GraphQL, protobuf, AsyncAPI, MCP manifests, or agent tool schemas) changes before merge, deploy, publish, or tool registration; AND any agent-executed operation with no supported contract type — send type agent_operation. Do not call for documentation-only changes, static readiness scoring, or receipt verification. Use analyze for risk only; authorize requires context.operation. Skipping this call is not permission. Absence of a key is not permission. Inputs: preflight_mode is required: \"analyze\" (risk only; no receipt, no execution_action) or \"authorize\" (may mint a receipt; requires context.operation — merge is not deploy is not publish). Supply exactly one artifact source: artifacts[] (1–20 items, each {id, type, before, after} as the FULL spec/schema text, not a path or URL; type is openapi|graphql|grpc|asyncapi|mcp_manifest|agent_tools|agent_operation) XOR derivation=\"server\" (server reads GitHub Compare; needs context.repository + context.base + context.head; sending artifacts[] together is 400). Grant fields sit in one object, execution_grant_request {include_execution_grant, grant_version, tenant_id, executor_id, adapter_id, target_uri, expected_state_token, state_nonce, audience, policy_hash}; analyze ignores it; required is preflight_mode only. previous_receipt is a chain token base64url(body).base64url(signature) to LINK a prior decision — it does not re-verify; use coderifts.verify_receipt instead; for details of a past decision use coderifts.get_decision_details instead. idempotency_key replays authorize only (24h), never analyze.", "inputSchema": { "if": { "properties": { "preflight_mode": { "const": "authorize" } }, "required": [ "preflight_mode" ] }, "properties": { "artifacts": { "description": "1–20 contract documents analyzed together. Each item is {id, type, before, after} where before/after are the FULL document strings (YAML/JSON/proto text), not URLs or file paths. Omit this array entirely when derivation=\"server\".", "items": { "properties": { "after": { "description": "The proposed document as raw text, same kind as before. Must be the bytes you intend to merge/deploy/publish, not a diff.", "type": "string" }, "before": { "description": "The baseline document as raw text (the spec/schema/manifest body). Empty string means \"no prior version\" (create), not \"load from disk\".", "type": "string" }, "id": { "description": "Caller-chosen id, unique within the bundle", "type": "string" }, "type": { "description": "Artifact kind. One of openapi, graphql, grpc, asyncapi, mcp_manifest, agent_tools, agent_operation. Contract types determine how before/after text is parsed. agent_operation: An opaque proposed agent operation for which no supported contract-artifact type applies. CodeRifts does not semantically analyze this content and does not issue an execution grant. Not inferred from the filename.", "enum": [ "openapi", "graphql", "grpc", "asyncapi", "mcp_manifest", "agent_tools", "agent_operation" ], "type": "string" } }, "required": [ "id", "type", "before", "after" ], "type": "object" }, "maxItems": 20, "minItems": 1, "type": "array" }, "context": { "description": "Optional apply-site context folded into the bundle fingerprint. operation distinguishes merge vs deploy vs publish (and other labels); the server accepts any non-empty string; conventional values: merge, deploy, tool_call, publish. The receipt/gate must match this label.", "properties": { "audience": { "description": "Optional audience (IntentContext parity; REST/MCP accept, server-derived audience still wins on the envelope)", "type": "string" }, "base": { "description": "Base commit/ref SHA the change set was computed against (optional; PR/commit identity)", "type": "string" }, "branch": { "description": "Branch name (optional; fingerprint context)", "type": "string" }, "environment": { "description": "Target environment (e.g. production, staging, npm) — optional; folded into fingerprint when set.", "type": "string" }, "fingerprint": { "description": "Optional change fingerprint (IntentContext parity; not folded into the bundle fingerprint)", "type": "string" }, "head": { "description": "Head commit/ref SHA of the proposed change (optional; PR/commit identity)", "type": "string" }, "operation": { "description": "Application operation for this change set (fingerprint + envelope). Server accepts any non-empty string; conventional values: merge, deploy, tool_call, publish. Merge is not deploy is not publish — the receipt/gate must match this label.", "type": "string" }, "policy_profile": { "description": "Policy profile name (optional; fingerprint context)", "type": "string" }, "pull_request": { "description": "Pull request id when applicable (optional; fingerprint context)", "oneOf": [ { "type": "string" }, { "type": "number" } ] }, "repository": { "description": "Repository identity (optional; fingerprint context)", "type": "string" }, "target_id": { "description": "Optional apply-site target (IntentContext parity; not folded into the bundle fingerprint)", "type": "string" }, "target_uri": { "description": "Optional apply-site URI the cr.exec.v2 grant binds (handler fallback: input.target_uri, then context.target_uri, then repository/head-derived). Distinct from target_id.", "type": "string" } }, "type": "object" }, "decision_spec_version": { "description": "Optional. Omit or '2.0' = current contract. '1.0' retired (INVALID_INPUT); do not pin 1.0.", "enum": [ "2.0" ], "type": "string" }, "derivation": { "description": "\"server\" = the server derives artifacts[] from GitHub Compare via the App installation. Allowed only when context.repository, context.base and context.head are all present and the tenant has a proven binding for that repository. Do not send artifacts[] in the same call (400 — one source of truth). Omit this field for the caller-supplied artifacts[] path.", "enum": [ "server" ], "type": "string" }, "execution_grant_request": { "description": "Authorize + include_execution_grant only: the execution-grant request fields. Analyze ignores them. Flat root-level spellings are also accepted; the same field sent both ways with different values is INVALID_INPUT.", "properties": { "adapter_id": { "description": "Authorize+grant v2 only. Adapter that will apply the change. Conventional values: fs, postgres, git. Must match the adapter the executor actually uses; a git grant does not authorize an fs write.", "type": "string" }, "audience": { "description": "Requester identity for the decision envelope. Accepted here; the server-derived audience wins when both are present.", "type": "string" }, "executor_id": { "description": "Authorize+grant v2 only. Executor identity the grant is bound to (example: agent:ci-bot, host:github-actions). Empty/absent is not \"any executor\".", "type": "string" }, "expected_state_token": { "description": "Authorize+grant v2 only. Compare-and-swap token the executor must observe at apply time (the \"before\" state). Signed as its own field. Omit only if the adapter has no prior state; do not send a placeholder.", "type": "string" }, "grant_version": { "description": "Grant envelope to mint when include_execution_grant is true. Omitting this yields cr.exec.v1 until 2026-09-18 and cr.exec.v2 on and after it (see x-coderifts-effective-default / x-coderifts-default-changes-at). The response meta.grant_version is the version actually issued. An explicit value always wins — pin \"v1\" to keep current behaviour with no code change on the date.", "enum": [ "v1", "v2" ], "type": "string", "x-coderifts-default-changes-at": "2026-09-18", "x-coderifts-effective-default": "v2" }, "include_execution_grant": { "description": "Authorize only. When true on an allow-class authorize, the response includes a signed execution_grant, or HTTP 503 SIGNER_UNAVAILABLE — never an unsigned grant. Default false. Analyze ignores this flag. Ignored unless preflight_mode=\"authorize\".", "type": "boolean" }, "policy_hash": { "description": "Authorize+grant v2 only. Policy identity bound into the grant, sha256: + 64 hex. When supplied, apply must use that same policy; a different policy is a different grant.", "type": "string" }, "state_nonce": { "description": "Authorize+grant only. Opaque nonce copied into the signed grant as its own field (not folded into scope_hash). Absent → BEARER grant. Ignored unless include_execution_grant is true.", "type": "string" }, "target_uri": { "description": "Authorize+grant v2 only. URI the grant binds (example: git://owner/repo.git/refs/heads/main). Fallback if omitted: context.target_uri, then repository/head-derived. Distinct from context.target_id.", "type": "string" }, "tenant_id": { "description": "Authorize+grant v2 only. Tenant the grant is issued under. ASCII slug. When omitted the server uses \"default\" — pin it if you are not on the default tenant.", "type": "string" } }, "type": "object" }, "idempotency_key": { "description": "Optional client key; in authorize mode, a repeat with the same key + body replays the original decision (24h). Analyze responses are not replayed.", "type": "string" }, "preflight_mode": { "description": "REQUIRED. \"analyze\" = informational risk only (no decision/execution_action/safe_for_agent; analysis_outcome + may_execute:false). \"authorize\" = operation-bound path; may mint a receipt (requires context.operation). Decision Spec 2.0: omission is INVALID_INPUT. Do not pin 1.0 — that pin retired.", "enum": [ "analyze", "authorize" ], "type": "string" }, "previous_receipt": { "description": "Optional prior chain token to LINK this call into a receipt chain: base64url(body).base64url(signature). Linking is not verification — a linked token is not re-checked here; use verify_receipt.", "type": "string" }, "response_detail": { "description": "How much of the response to return. control = the fields an agent branches on; standard = control + the human report and labelled break rows (the MCP default); full = everything (the REST default). Every value is copied from the full response.", "enum": [ "control", "standard", "full" ], "type": "string" } }, "required": [ "preflight_mode" ], "then": { "properties": { "context": { "properties": { "operation": { "minLength": 1, "type": "string" } }, "required": [ "operation" ], "type": "object" } }, "required": [ "context" ] }, "type": "object" }, "name": "preflight_change_set", "outputSchema": { "oneOf": [ { "additionalProperties": true, "description": "ANALYZE mode (Decision Spec 2.0): informational only. MUST NOT contain decision, execution_action, safe_for_agent, chain_receipt, execution_grant, decision_result, control_envelope, or required_action_core. Branch on analysis_outcome; never treat as permission. Field set GENERATED from preflight-response.v2.producer.json (agent-facing allowlist).", "not": { "anyOf": [ { "required": [ "decision" ] }, { "required": [ "execution_action" ] }, { "required": [ "safe_for_agent" ] }, { "required": [ "chain_receipt" ] }, { "required": [ "execution_grant" ] }, { "required": [ "decision_result" ] }, { "required": [ "control_envelope" ] }, { "required": [ "required_action_core" ] } ] }, "properties": { "analysis": { "additionalProperties": true, "description": "Tier-2 analysis mirror, assembled by the response builder alongside the control surface. Dual-write of the flat analysis fields present on the verdict, plus remediations[]. PROPERTIES ARE GENERATED — do not hand-edit them. OPEN BY DESIGN: additionalProperties stays TRUE and this is not an oversight. The fields above are copied conditionally, so which of them appear depends on the input — a verdict with no PII findings simply omits pii_findings. Closing this object would turn every future analysis field into a breaking change that fails inside the consumer, and would reject exactly the verdict paths that no one sampled when the union was built. Declared, not closed: you can now see what you may get, and you must still tolerate more.", "properties": { "breaking_changes": { "type": "integer" }, "breaking_changes_details": { "type": "array" }, "change_ir": { "type": "array" }, "changelog": { "type": "array" }, "compatibility_suggestions": { "type": "array" }, "coverage_gap": { "additionalProperties": true, "type": "object" }, "coverage_gap_reason": { "type": "string" }, "decision_basis": { "additionalProperties": true, "type": "object" }, "degraded": { "type": "boolean" }, "detected_patterns": { "type": "array" }, "evidence_quality": { "type": "string" }, "fallback_reason": { "type": "string" }, "non_breaking_changes": { "type": "array" }, "pattern_sources": { "type": "array" }, "patterns": { "type": "array" }, "pii_findings": { "type": "array" }, "policy_violations": { "type": "array" }, "remediations": { "items": { "additionalProperties": true, "description": "One remediation for one detected breaking change. `instruction` is imperative prose that a model may read and act on; it is generated per input and is NOT a fixed string, so the schema declares that the field exists and does not pin its text.", "properties": { "change_type": { "type": "string" }, "effort": { "type": "string" }, "evidence": { "additionalProperties": true, "type": "object" }, "instruction": { "description": "Imperative remediation text. Model-visible. Generated per input; not a closed vocabulary.", "type": "string" }, "precise_label": { "type": "string" }, "recommended_transform": { "type": "string" }, "target": { "type": "string" }, "target_ref": { "additionalProperties": true, "type": "object" } }, "type": "object" }, "type": "array" }, "requires_migration": { "type": "boolean" }, "risk_dimensions": { "additionalProperties": true, "type": "object" }, "risk_level": { "type": "string" }, "risk_score": { "type": "integer" }, "security_findings": { "type": "array" }, "semver_suggestion": { "type": "string" }, "should_block": { "type": "boolean" }, "stats": { "additionalProperties": true, "type": "object" }, "token_cost_impact": { "additionalProperties": true, "type": "object" } }, "type": "object" }, "analysis_control": { "type": "object" }, "analysis_outcome": { "description": "Closed analysis outcome set derived from engine-visible state only. NOT_SUPPORTED = no analyzer (agent_operation / type outside the published enum). ANALYSIS_FAILED = an analyzer ran and failed.", "enum": [ "NO_BREAK_DETECTED", "BREAKS_DETECTED", "ANALYSIS_FAILED", "NOT_SUPPORTED" ], "type": "string" }, "artifacts": { "type": "array" }, "authorization_effect": { "const": "NONE", "description": "Analyze never authorizes; always NONE." }, "blast_radius": { "additionalProperties": false, "description": "Additive COUNTS (not a score). Pure function of the change-set + request graphs. Not in the verdict_fingerprint preimage.", "properties": { "consumers_declared": { "minimum": 0, "type": "integer" }, "consumers_observed": { "minimum": 0, "type": "integer" }, "endpoints": { "minimum": 0, "type": "integer" }, "fields": { "minimum": 0, "type": "integer" }, "graph_source": { "enum": [ "none", "declared", "observed", "declared+observed" ], "type": "string" }, "params": { "minimum": 0, "type": "integer" } }, "required": [ "endpoints", "fields", "params", "consumers_declared", "consumers_observed", "graph_source" ], "type": "object" }, "breaking_changes": { "minimum": 0, "type": "integer" }, "breaking_changes_details": { "description": "Per-change IR/detail rows, mapped from the engine's change IR. Measured row keys: type, path, method, field, severity, description. Distinct from breaking_changes (integer count).", "items": { "additionalProperties": true, "properties": { "description": { "type": "string" }, "field": { "type": "string" }, "method": { "type": "string" }, "path": { "type": "string" }, "severity": { "type": "string" }, "type": { "description": "Change kind / IR type code (e.g. response.body.property.remove).", "type": "string" } }, "type": "object" }, "type": "array" }, "bundle_fingerprint": { "type": "string" }, "calibration_version": { "type": [ "string", "null" ] }, "decision_basis": {}, "decision_spec_version": { "description": "Decision Spec major for this response (typically '2.0').", "type": "string" }, "detected_patterns": { "description": "GOVERNANCE detector detail rows, emitted by the pattern detectors and validated against the decision-spec field contract before they leave the server. Row shape measured live: name, severity, description, consequence, affected_path, affected_field; optional side (request|response) on ENUM_NARROWING. Names ⊆ patterns (not equality). Agent-detector names may appear only in patterns. Free-text fields are untrusted.", "items": { "additionalProperties": false, "properties": { "affected_field": { "description": "Field within affected_path. Empty string when the detector had none — the key is always emitted.", "type": "string" }, "affected_path": { "description": "Contract path this row is about. Empty string when the detector had none — the key is always emitted.", "type": "string" }, "consequence": { "description": "What breaks for a consumer if this ships. Untrusted free text.", "type": "string" }, "description": { "description": "What the detector matched. Untrusted free text.", "type": "string" }, "name": { "description": "Governance pattern name; appears in patterns when both are carried.", "type": "string" }, "severity": { "description": "Row severity from the pattern catalog (observed set: CRITICAL, HIGH, MEDIUM). NOT a closed control enum — branch on execution_action, never on this.", "type": "string" }, "side": { "description": "Optional; currently set on ENUM_NARROWING only. Request-side narrowing is agent-breaking (threaded so safe_for_agent can distinguish it). Absent when the detector did not set it.", "enum": [ "request", "response" ], "type": "string" } }, "required": [ "name", "severity", "description", "consequence", "affected_path", "affected_field" ], "type": "object" }, "type": "array" }, "evidence": { "type": "array" }, "evidence_quality": { "type": "string" }, "human_report": { "additionalProperties": false, "description": "Human-readable report tier, assembled by the response builder; analyze returns a reduced form. Measured keys: summary, breaking_highlights, suggestions, next_steps_prose.", "properties": { "breaking_highlights": { "type": "array" }, "next_steps_prose": { "type": "string" }, "suggestions": { "type": "array" }, "summary": { "type": "string" } }, "type": "object" }, "may_execute": { "const": false, "description": "Analyze never grants execute permission." }, "operation": {}, "pattern_sources": { "type": "array" }, "patterns": { "items": { "type": "string" }, "type": "array" }, "policy_pin_status": { "additionalProperties": true, "type": [ "object", "null" ] }, "preflight_mode": { "const": "analyze" }, "receipt_kind": { "const": "NONE", "description": "Analyze never mints a receipt." }, "requires_migration": { "type": "boolean" }, "risk_score": { "maximum": 100, "minimum": 0, "type": "integer" }, "scorer_version": { "description": "Fingerprint-bound scorerVersion() (observation; not permission).", "type": [ "string", "null" ] }, "severity_summary": { "additionalProperties": false, "description": "Bundle severity axes, computed once per change set. Distinct axes, not contradictory. Measured keys: diff_severity, governance_severity, policy_effect, note.", "properties": { "diff_severity": { "description": "Structural size of the schema change.", "type": "string" }, "governance_severity": { "description": "How the rule engine rates the change.", "type": "string" }, "note": { "type": "string" }, "policy_effect": { "description": "Resulting decision effect label.", "type": "string" } }, "type": "object" }, "timestamp": { "type": "string" }, "verdict_fingerprint": { "type": "string" } }, "required": [ "preflight_mode", "analysis_outcome", "authorization_effect", "may_execute", "receipt_kind", "decision_spec_version" ], "type": "object" }, { "additionalProperties": true, "allOf": [ { "if": { "properties": { "receipt_kind": { "const": "operation_authorization" } }, "required": [ "receipt_kind" ] }, "then": { "required": [ "chain_receipt" ] } }, { "if": { "properties": { "execution_action": { "enum": [ "CONTINUE", "CONTINUE_WITH_MONITORING" ] } }, "required": [ "execution_action" ] }, "then": { "properties": { "receipt_kind": { "const": "operation_authorization" } }, "required": [ "receipt_kind", "chain_receipt", "decision_result" ] } } ], "description": "AUTHORIZE mode: operation-bound decision. Branch on execution_action (not decision, not safe_for_agent). Field set GENERATED from preflight-response.v2.producer.json (agent-facing allowlist). Compatibility: https://coderifts.com/schemas/decision-result.v1.consumer.json", "properties": { "analysis": { "additionalProperties": true, "properties": { "breaking_changes": { "type": "integer" }, "breaking_changes_details": { "type": "array" }, "change_ir": { "type": "array" }, "changelog": { "type": "array" }, "compatibility_suggestions": { "type": "array" }, "coverage_gap": { "additionalProperties": true, "type": "object" }, "coverage_gap_reason": { "type": "string" }, "decision_basis": { "additionalProperties": true, "type": "object" }, "degraded": { "type": "boolean" }, "detected_patterns": { "type": "array" }, "evidence_quality": { "type": "string" }, "fallback_reason": { "type": "string" }, "non_breaking_changes": { "type": "array" }, "pattern_sources": { "type": "array" }, "patterns": { "type": "array" }, "pii_findings": { "type": "array" }, "policy_violations": { "type": "array" }, "remediations": { "items": { "additionalProperties": true, "properties": { "change_type": { "type": "string" }, "effort": { "type": "string" }, "evidence": { "additionalProperties": true, "type": "object" }, "instruction": { "type": "string" }, "precise_label": { "type": "string" }, "recommended_transform": { "type": "string" }, "target": { "type": "string" }, "target_ref": { "additionalProperties": true, "type": "object" } }, "type": "object" }, "type": "array" }, "requires_migration": { "type": "boolean" }, "risk_dimensions": { "additionalProperties": true, "type": "object" }, "risk_level": { "type": "string" }, "risk_score": { "type": "integer" }, "security_findings": { "type": "array" }, "semver_suggestion": { "type": "string" }, "should_block": { "type": "boolean" }, "stats": { "additionalProperties": true, "type": "object" }, "token_cost_impact": { "additionalProperties": true, "type": "object" } }, "type": "object" }, "artifacts": { "type": "array" }, "blast_radius": { "additionalProperties": false, "properties": { "consumers_declared": { "minimum": 0, "type": "integer" }, "consumers_observed": { "minimum": 0, "type": "integer" }, "endpoints": { "minimum": 0, "type": "integer" }, "fields": { "minimum": 0, "type": "integer" }, "graph_source": { "enum": [ "none", "declared", "observed", "declared+observed" ], "type": "string" }, "params": { "minimum": 0, "type": "integer" } }, "required": [ "endpoints", "fields", "params", "consumers_declared", "consumers_observed", "graph_source" ], "type": "object" }, "breaking_changes": { "minimum": 0, "type": "integer" }, "breaking_changes_details": { "items": { "additionalProperties": true, "properties": { "description": { "type": "string" }, "field": { "type": "string" }, "method": { "type": "string" }, "path": { "type": "string" }, "severity": { "type": "string" }, "type": { "type": "string" } }, "type": "object" }, "type": "array" }, "bundle_fingerprint": { "type": "string" }, "calibration_version": { "description": "Calibration model version when set; null until a calibrated model ships.", "type": [ "string", "null" ] }, "chain_receipt": { "type": "string" }, "chain_status": { "type": "string" }, "coderifts_version": { "type": "string" }, "control_envelope": { "description": "Branch source (control/1.0). Machine-control surface from attachControlSurface / buildControlEnvelope. Agents and @coderifts/agent-guard branch on control_envelope.execution_action. Top-level decision/safe_for_agent/execution_action mirror these values for compatibility. Includes next_agent_step (structured remediation SUGGESTION derived from execution_action + required_action; null on CONTINUE*; not permission — still branch on execution_action).", "type": "object" }, "decision": { "description": "Compatibility mirror of control_envelope.decision (same value). Prefer control_envelope for branching; use decision as explanation only.", "enum": [ "ALLOW", "WARN", "REQUIRE_APPROVAL", "BLOCK" ], "type": "string" }, "decision_basis": {}, "decision_result": { "additionalProperties": true, "description": "decision-result.v1 envelope (control enums closed). Additive fields may appear and are not permission. Full schema: https://coderifts.com/schemas/decision-result.v1.consumer.json (producer: https://coderifts.com/schemas/decision-result.v1.producer.json).", "properties": { "audience": { "type": [ "string", "null" ] }, "authority": { "description": "Additive. { audience, tenant_scope: bound|unbound, binding_proven_at? }. Informational — not permission, not a verify-receipt gate, not an ACL.", "type": [ "object", "null" ] }, "base": { "type": [ "string", "null" ] }, "blast_radius": { "description": "Additive COUNTS (not a score). Not permission.", "properties": { "consumers_declared": { "minimum": 0, "type": "integer" }, "consumers_observed": { "minimum": 0, "type": "integer" }, "endpoints": { "minimum": 0, "type": "integer" }, "fields": { "minimum": 0, "type": "integer" }, "graph_source": { "type": "string" }, "params": { "minimum": 0, "type": "integer" } }, "type": "object" }, "decision": { "enum": [ "ALLOW", "WARN", "REQUIRE_APPROVAL", "BLOCK" ], "type": "string" }, "decision_body_hash": { "type": [ "string", "null" ] }, "decision_id": { "type": "string" }, "derivation": { "description": "Additive. Present only when derivation:\"server\" produced this envelope. { source, platform?, base_sha, head_sha }. Covered by body_hash; not fingerprint.", "type": [ "object", "null" ] }, "environment": { "type": [ "string", "null" ] }, "execution_action": { "enum": [ "CONTINUE", "CONTINUE_WITH_MONITORING", "REQUEST_APPROVAL", "STOP" ], "type": "string" }, "expires_at": { "type": "string" }, "fingerprint": { "type": "string" }, "head": { "type": [ "string", "null" ] }, "input_fingerprint": { "type": "string" }, "operation": { "type": [ "string", "null" ] }, "receipt": { "type": "object" }, "repository": { "type": [ "string", "null" ] }, "safe_for_agent": { "type": "boolean" }, "spec_version": { "pattern": "^decision-result\\.v1(\\.[0-9]+)?$", "type": "string" } }, "type": "object" }, "decision_spec_version": { "type": "string" }, "detected_patterns": { "items": { "additionalProperties": false, "properties": { "affected_field": { "type": "string" }, "affected_path": { "type": "string" }, "consequence": { "type": "string" }, "description": { "type": "string" }, "name": { "type": "string" }, "severity": { "type": "string" }, "side": { "enum": [ "request", "response" ], "type": "string" } }, "required": [ "name", "severity", "description", "consequence", "affected_path", "affected_field" ], "type": "object" }, "type": "array" }, "evidence": { "type": "array" }, "evidence_quality": { "type": "string" }, "execution_action": { "description": "Compatibility mirror of control_envelope.execution_action (same value). Canonical branch key; unrecognised values are not permission (fail closed).", "enum": [ "CONTINUE", "CONTINUE_WITH_MONITORING", "REQUEST_APPROVAL", "STOP" ], "type": "string" }, "execution_grant": { "description": "Opt-in cr.exec.v1 execution grant (PHASE-0). Issued only when include_execution_grant is true on authorize. Short-lived mutation-bound sibling of chain_receipt; never unsigned. Optional inner state_nonce (ATOMIC profile) is additive and is NOT in scope_hash.", "type": "string" }, "human_report": { "additionalProperties": false, "properties": { "breaking_highlights": { "type": "array" }, "next_steps_prose": { "type": "string" }, "suggestions": { "type": "array" }, "summary": { "type": "string" } }, "type": "object" }, "operation": {}, "pattern_sources": { "type": "array" }, "patterns": { "items": { "type": "string" }, "type": "array" }, "policy_pin_status": { "additionalProperties": true, "description": "policy_pin observation (898). match null=no pin; false=drift warning (non-blocking).", "type": [ "object", "null" ] }, "preflight_mode": { "const": "authorize" }, "receipt_kind": { "description": "operation_authorization when a chain receipt was issued; NONE if signer unconfigured.", "enum": [ "operation_authorization", "NONE" ], "type": "string" }, "requires_migration": { "type": "boolean" }, "risk_score": { "maximum": 100, "minimum": 0, "type": "integer" }, "safe_for_agent": { "description": "Compatibility mirror of control_envelope.safe_for_agent (same value). Not a branch key — do not branch on safe_for_agent (use execution_action).", "type": "boolean" }, "scorer_version": { "description": "Fingerprint-bound scorerVersion() (same as decision_result.scorer_version / FP preimage).", "type": [ "string", "null" ] }, "severity_summary": { "additionalProperties": false, "properties": { "diff_severity": { "type": "string" }, "governance_severity": { "type": "string" }, "note": { "type": "string" }, "policy_effect": { "type": "string" } }, "type": "object" }, "timestamp": { "type": "string" }, "verdict_fingerprint": { "type": "string" } }, "required": [ "preflight_mode", "decision", "execution_action", "safe_for_agent", "receipt_kind", "decision_spec_version" ], "type": "object" } ], "type": "object" } }, { "description": "Verify a CodeRifts signed chain-receipt you ALREADY HOLD: cryptographic\nauthenticity (signature + key id), body binding, and — when lifecycle indices\nare available — whether it is currently valid authorization (not expired,\nsuperseded, or revoked) for a stated operation/target.\n\nUse this when:\n- You already obtained a chain_receipt / receipt token from a prior preflight\n (or CI artifact) and are about to act (merge/deploy) under that receipt.\n- A contract-gate or policy requires offline/online proof that the receipt is\n authentic for this change before proceeding.\n- You must distinguish \"signature ok\" from \"currently authorized\" (stale or\n superseded receipts must not be treated as live approval).\n\nDo not use when:\n- You do not have a receipt yet — call coderifts.preflight_change_set first.\n- You need a NEW decision for a changed base→head set — preflight again;\n verify_receipt does not re-diff specs.\n- The receipt you hold binds a different operation or target than the one you\n are about to perform — call coderifts.preflight_change_set with\n context.operation set to that operation (a merge receipt does not authorize\n a deploy); verify_receipt cannot re-scope or re-issue a decision.\n- You only need human-readable history of an old decision_id without a receipt\n token — use coderifts.get_decision_details.\n- The change set itself is unknown or incomplete — fix the change set and\n preflight; do not \"verify\" a placeholder.\n\nInputs: receipt token (required); target_id = decision_result.artifact_digest — required\nfor an authorization verdict; omitted → target_not_stated. Optional intended context\n(operation, environment, fingerprint, audience, repository/branch/pull_request, base/head)\nand the body_hash-bound decision_result envelope. 30s clock-skew leeway on expiry. A 0s\ngrace for declared destructive production operations is defined in the policy but\nis unreachable today: the intended-context schema has no destructive field, so\nnothing can declare one and the 30s leeway always applies.\nReturns { valid, status, currently_authorized (bool|null), reason, payload, authz_* }.\nBranch on currently_authorized; null = not evaluated.\n\nWhen a decision envelope is also in hand (e.g. from a prior preflight), its\ncontrol_envelope.next_agent_step (if present) is structured remediation guidance\nthe agent MAY follow after a non-CONTINUE decision — still branch on\nexecution_action; next_agent_step is suggestion, not permission.", "inputSchema": { "description": "Two evaluation modes (schema-documented; no mode discriminator field). SIGNATURE: supply token only — signature + expiry; currently_authorized is null. AUTHORIZATION: also supply intended context (operation, environment, fingerprint, target_id set to decision_result.artifact_digest, audience, repository/branch/pull_request, and/or base/head) AND the body_hash-bound decision_result envelope so currently_authorized / authz_status / authz_reason can be evaluated. Token alone is always accepted; omitting the envelope when context fields are present yields a signature verdict plus fail-closed authorization (currently_authorized false), not a schema reject.", "properties": { "audience": { "description": "Intended audience — must match the receipt", "type": "string" }, "base": { "description": "Intended base commit/ref SHA the receipt must match (signed-wins vs envelope.base)", "type": "string" }, "branch": { "description": "Intended branch the receipt must bind (place binding; optional)", "type": "string" }, "decision_result": { "additionalProperties": true, "description": "The body_hash-bound decision envelope (carries operation/target/decision). Required for a meaningful AUTHORIZATION evaluation of scope; without it, intended context alone fails closed on authorization (currently_authorized false) while signature status remains independent. Full schema: https://coderifts.com/schemas/decision-result.v1.consumer.json.", "properties": { "audience": { "type": [ "string", "null" ] }, "authority": { "description": "Additive. { audience, tenant_scope: bound|unbound, binding_proven_at? }. Informational — not permission, not a verify-receipt gate, not an ACL.", "type": [ "object", "null" ] }, "base": { "type": [ "string", "null" ] }, "blast_radius": { "description": "Additive COUNTS (not a score). Not permission.", "properties": { "consumers_declared": { "minimum": 0, "type": "integer" }, "consumers_observed": { "minimum": 0, "type": "integer" }, "endpoints": { "minimum": 0, "type": "integer" }, "fields": { "minimum": 0, "type": "integer" }, "graph_source": { "type": "string" }, "params": { "minimum": 0, "type": "integer" } }, "type": "object" }, "decision": { "enum": [ "ALLOW", "WARN", "REQUIRE_APPROVAL", "BLOCK" ], "type": "string" }, "decision_body_hash": { "type": [ "string", "null" ] }, "decision_id": { "type": "string" }, "derivation": { "description": "Additive. Present only when derivation:\"server\" produced this envelope. { source, platform?, base_sha, head_sha }. Covered by body_hash; not fingerprint.", "type": [ "object", "null" ] }, "environment": { "type": [ "string", "null" ] }, "execution_action": { "enum": [ "CONTINUE", "CONTINUE_WITH_MONITORING", "REQUEST_APPROVAL", "STOP" ], "type": "string" }, "expires_at": { "type": "string" }, "fingerprint": { "type": "string" }, "head": { "type": [ "string", "null" ] }, "input_fingerprint": { "type": "string" }, "operation": { "type": [ "string", "null" ] }, "receipt": { "type": "object" }, "repository": { "type": [ "string", "null" ] }, "safe_for_agent": { "type": "boolean" }, "spec_version": { "pattern": "^decision-result\\.v1(\\.[0-9]+)?$", "type": "string" } }, "type": "object" }, "environment": { "description": "Intended environment (e.g. production) — must match the receipt", "type": "string" }, "fingerprint": { "description": "Intended change fingerprint — must equal the receipt fp", "type": "string" }, "head": { "description": "Intended head commit/ref SHA the receipt must match (signed-wins vs envelope.head)", "type": "string" }, "operation": { "description": "Intended operation the receipt must authorize (conventional: merge|deploy|tool_call|publish). Triggers authorization evaluation when non-empty; supply decision_result for full scope binding.", "type": "string" }, "pull_request": { "description": "Intended pull-request id the receipt must bind (place binding; optional)", "oneOf": [ { "type": "string" }, { "type": "number" } ] }, "repository": { "description": "Intended repository the receipt must bind (place binding; optional)", "type": "string" }, "target_id": { "description": "REQUIRED to authorize under a held receipt. Set it to decision_result.artifact_digest — the digest of the artifact the receipt was issued for, which you already hold in the decision_result you are passing. The server does NOT derive it for you: it carries YOUR intended apply-site, and taking it from the envelope would compare that document against itself. Omit it and the answer is currently_authorized false with authz_reason target_not_stated and authz_status VERIFIED_TARGET_NOT_STATED — a missing input, distinct from target_mismatch, which means the receipt covers a different target.", "type": "string" }, "token": { "description": "The chain receipt token (base64url(body).base64url(signature))", "type": "string" } }, "required": [ "token" ], "type": "object" }, "name": "verify_receipt", "outputSchema": { "additionalProperties": true, "description": "Receipt signature/status plus optional authorization layer. additionalProperties true: additive fields may appear and are not permission. Envelope compatibility when a decision_result is supplied: https://coderifts.com/schemas/decision-result.v1.consumer.json schema description (single source).", "properties": { "authz_note": { "description": "Present when no intended context supplied: status reflects signature+expiry only", "type": "string" }, "authz_reason": { "description": "When currently_authorized=false: the deny reason (operation_mismatch, decision_not_allow, superseded, expired, target_mismatch, environment_mismatch, …)", "type": "string" }, "authz_reasons": { "description": "Every violation found; the first is authz_reason. [] when authorized. Fix all of them before re-verifying.", "items": { "type": "string" }, "type": "array" }, "authz_state": { "description": "Lifecycle state from isCurrentlyAuthorized when authorization is evaluated (optional; omitted when currently_authorized is null)", "type": "string" }, "authz_status": { "description": "Authorization-level status (VERIFIED_WRONG_ENVIRONMENT / VERIFIED_SUPERSEDED / VERIFIED_SCOPE_MISMATCH / …)", "type": "string" }, "binding_level": { "description": "place_and_content | content_only — forensic, not a second verdict", "type": "string" }, "caller_value": { "description": "Caller claim that differed from the signed envelope", "type": [ "string", "null" ] }, "correlation_id": { "description": "Route-owned trace id, set by the route itself rather than by correlation middleware; always a non-empty string on 200", "type": "string" }, "currently_authorized": { "description": "Whether the receipt currently authorizes the intended operation/target/fp (§106). null means authorization could not be evaluated (e.g. no intended context) — not unauthorized and not authorized.", "type": [ "boolean", "null" ] }, "payload": { "type": "object" }, "reason": { "type": [ "string", "null" ] }, "signed_value": { "description": "Signed envelope slot when signed-wins fail-closed (source_binding_mismatch)", "type": [ "string", "null" ] }, "status": { "enum": [ "VERIFIED_CURRENT", "VERIFIED_EXPIRED", "VERIFIED_WRONG_AUDIENCE", "VERIFIED_WRONG_ENVIRONMENT", "VERIFIED_SUPERSEDED", "VERIFIED_SCOPE_MISMATCH", "VERIFIED_UNBOUND_OPERATION", "VERIFIED_UNBOUND_TARGET", "VERIFIED_UNBOUND_REPOSITORY", "VERIFIED_UNBOUND_BRANCH", "VERIFIED_UNBOUND_PULL_REQUEST", "VERIFIED_TARGET_NOT_STATED", "UNKNOWN_KEY", "UNKNOWN_KEY_STATUS", "RETIRED_KEY_VALID_AT_ISSUE", "KEY_RETIRED_AFTER_SIGNING", "REVOKED_KEY", "REVOKED_KEY_UNDECIDABLE", "KEY_REVOKED", "REVOCATION_UNDECIDABLE", "AUTHORIZATION_UNDECIDABLE", "INVALID_SIGNATURE", "MALFORMED", "UNSUPPORTED_VERSION", "REGISTRY_UNREACHABLE" ], "type": "string" }, "valid": { "description": "true iff status is VERIFIED_CURRENT or RETIRED_KEY_VALID_AT_ISSUE", "type": "boolean" } }, "required": [ "valid", "status", "currently_authorized" ], "type": "object" } } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:06492dfa912e37457d25d4776b2dc60c3acffafeee5892ff01dcdb6ab799e589 | sha256sum