Server definition
- Hash
- sha256:06492dfa912e37457d25d4776b2dc60c3acffafeee5892ff01dcdb6ab799e589
- What it is
- What a remote MCP server returned when asked what it offers: 3 tools
The blob, as servednamed by its sha256
{
"instructions": "Signed, offline-verifiable authorization for API-contract changes. Only a granted change can proceed. Three tools: preflight_change_set, verify_receipt, get_decision_details. Analyze is not permission; branch on execution_action.",
"tools": [
{
"description": "Retrieve a PAST CodeRifts decision by exactly one identifier\n(case_id | decision_id | fingerprint): full report, breaking changes, scores,\nand linked receipt metadata if stored.\n\nUse this when:\n- You have a decision_id (or fingerprint) from a previous preflight, PR\n comment, or CI log and need to inspect or explain that past decision.\n- You are auditing why a prior ALLOW/WARN/BLOCK was issued.\n- You are NOT requesting a new analysis of current before/after specs.\n\nDo not use when:\n- You need a decision for the CURRENT uncommitted or PR head change set —\n call coderifts.preflight_change_set with the current artifacts.\n- You hold a receipt token and only need cryptographic/lifecycle verification —\n use coderifts.verify_receipt.\n- You have no identifier — run preflight first to create one.\n\nInputs: exactly one of case_id, decision_id, or fingerprint. {} → INVALID_INPUT;\ntwo identifiers → LOOKUP_IDENTIFIER_CONFLICT; case_id → CASE_NOT_FOUND\n(lookup never opens a case). Returns the stored document or not_found.\n\nScoping — fingerprint lookup returns only YOUR OWN decisions. A fingerprint is\nderived from content, not from an account, so two callers who preflight\nbyte-identical specs derive the same one; the lookup is therefore constrained\nto the decisions your credential can prove it owns.\n\nA decision that exists but is not yours returns the SAME not_found as one that\nwas never issued. This is deliberate: a distinguishable \"exists but forbidden\"\nwould confirm to any caller that a given content hash had been decided on by\nsomeone, which is the fact the scoping exists to withhold. Do not read\nnot_found as proof that no such decision exists anywhere.\n\nDecisions persisted without context.repository cannot currently be attributed\nto an account, and are not retrievable by fingerprint at all — not by their\nowner either. Retrieve those by decision_id, which is unchanged and unscoped.\nThis is a limitation of what older stored rows carry, not a property of the\nlookup: rows written from now on record the account directly, so the gap\nnarrows as older rows age out. If a fingerprint you expect returns not_found,\nuse the decision_id before concluding the decision is missing.\n\nWhen the stored envelope carries control fields, control_envelope.next_agent_step\nis structured remediation guidance the agent MAY follow for non-CONTINUE\nexecution_action values (null on CONTINUE*). Still branch on execution_action;\nnext_agent_step is a suggestion, not permission.",
"inputSchema": {
"additionalProperties": false,
"description": "Closed exclusive identifier union: exactly one of case_id | decision_id | fingerprint. Encoded as minProperties=1 + maxProperties=1 + additionalProperties=false, NOT as a top-level oneOf/anyOf/allOf — Anthropic (and other strict tool APIs) reject those combinators at the root of input_schema and then refuse the entire tools array (measured: test/mcp-input-oneof-honesty.test.js, mcp-streamable.js comment). The server enforces the same mutex with named codes: empty {} → INVALID_INPUT; two or more identifiers → LOOKUP_IDENTIFIER_CONFLICT; case_id alone → CASE_NOT_FOUND (no case store yet; lookup never opens a case).",
"maxProperties": 1,
"minProperties": 1,
"properties": {
"case_id": {
"description": "A case identifier. Lookup never opens a case. Until the case store exists this returns CASE_NOT_FOUND.",
"minLength": 1,
"type": "string"
},
"decision_id": {
"description": "The decision_id from a prior decision_result envelope. Provide exactly one identifier.",
"minLength": 1,
"type": "string"
},
"fingerprint": {
"description": "A verdict fingerprint (sha256:...); returns the latest matching decision you own. Provide exactly one identifier.",
"minLength": 1,
"type": "string"
}
},
"type": "object"
},
"name": "get_decision_details",
"outputSchema": {
"additionalProperties": true,
"description": "A stored CodeRifts decision: the original decision_result.v1 envelope + lookup meta. Retrieval-path control fields (safe_for_agent/execution_action/verdict_fingerprint/control_envelope) mirror the fresh preflight response and are present only when the stored envelope carries their source field. additionalProperties true: additive fields may appear and are not permission. Compatibility rule (single source): https://coderifts.com/schemas/decision-result.v1.consumer.json schema description.",
"properties": {
"breaking_changes": {
"minimum": 0,
"type": "integer"
},
"chain_receipt": {
"type": "string"
},
"coderifts_version": {
"type": "string"
},
"control_envelope": {
"description": "Control envelope (control/1.0) derived from the stored decision_result. Includes next_agent_step (structured remediation SUGGESTION for non-CONTINUE execution_action; null on CONTINUE*; not permission — still branch on execution_action).",
"type": "object"
},
"decision": {
"enum": [
"ALLOW",
"WARN",
"REQUIRE_APPROVAL",
"BLOCK"
],
"type": "string"
},
"decision_result": {
"additionalProperties": true,
"description": "decision-result.v1 envelope (control enums closed). Additive fields may appear and are not permission. Full schema: https://coderifts.com/schemas/decision-result.v1.consumer.json (producer: https://coderifts.com/schemas/decision-result.v1.producer.json).",
"properties": {
"audience": {
"type": [
"string",
"null"
]
},
"authority": {
"description": "Additive. { audience, tenant_scope: bound|unbound, binding_proven_at? }. Informational — not permission, not a verify-receipt gate, not an ACL.",
"type": [
"object",
"null"
]
},
"base": {
"type": [
"string",
"null"
]
},
"blast_radius": {
"description": "Additive COUNTS (not a score). Not permission.",
"properties": {
"consumers_declared": {
"minimum": 0,
"type": "integer"
},
"consumers_observed": {
"minimum": 0,
"type": "integer"
},
"endpoints": {
"minimum": 0,
"type": "integer"
},
"fields": {
"minimum": 0,
"type": "integer"
},
"graph_source": {
"type": "string"
},
"params": {
"minimum": 0,
"type": "integer"
}
},
"type": "object"
},
"decision": {
"enum": [
"ALLOW",
"WARN",
"REQUIRE_APPROVAL",
"BLOCK"
],
"type": "string"
},
"decision_body_hash": {
"type": [
"string",
"null"
]
},
"decision_id": {
"type": "string"
},
"derivation": {
"description": "Additive. Present only when derivation:\"server\" produced this envelope. { source, platform?, base_sha, head_sha }. Covered by body_hash; not fingerprint.",
"type": [
"object",
"null"
]
},
"environment": {
"type": [
"string",
"null"
]
},
"execution_action": {
"enum": [
"CONTINUE",
"CONTINUE_WITH_MONITORING",
"REQUEST_APPROVAL",
"STOP"
],
"type": "string"
},
"expires_at": {
"type": "string"
},
"fingerprint": {
"type": "string"
},
"head": {
"type": [
"string",
"null"
]
},
"input_fingerprint": {
"type": "string"
},
"operation": {
"type": [
"string",
"null"
]
},
"receipt": {
"type": "object"
},
"repository": {
"type": [
"string",
"null"
]
},
"safe_for_agent": {
"type": "boolean"
},
"spec_version": {
"pattern": "^decision-result\\.v1(\\.[0-9]+)?$",
"type": "string"
}
},
"type": "object"
},
"decision_semantic_hash": {
"type": "string"
},
"decision_spec_version": {
"type": "string"
},
"evidence": {
"type": [
"object",
"array",
"null"
]
},
"evidence_quality": {
"type": "string"
},
"execution_action": {
"enum": [
"CONTINUE",
"CONTINUE_WITH_MONITORING",
"REQUEST_APPROVAL",
"STOP"
],
"type": "string"
},
"meta": {
"additionalProperties": true,
"properties": {
"created_at": {
"type": "string"
},
"decision_id": {
"type": "string"
},
"omitted_sections": {
"type": "array"
},
"retrieval_mode": {
"enum": [
"stored"
],
"type": "string"
},
"source": {
"type": "string"
}
},
"type": "object"
},
"operation": {
"type": "string"
},
"pattern_sources": {
"type": "array"
},
"patterns": {
"items": {
"type": "string"
},
"type": "array"
},
"preflight_mode": {
"enum": [
"analyze",
"authorize"
],
"type": "string"
},
"receipt_kind": {
"enum": [
"NONE",
"operation_authorization"
],
"type": "string"
},
"required_action_core": {
"description": "Branchable required-action core { type, reason_code, recheck_required } when present on the envelope.",
"type": "object"
},
"requires_migration": {
"type": "boolean"
},
"risk_score": {
"maximum": 100,
"minimum": 0,
"type": "integer"
},
"safe_for_agent": {
"type": "boolean"
},
"timestamp": {
"type": "string"
},
"verdict_fingerprint": {
"type": "string"
}
},
"required": [
"decision_result",
"meta"
],
"type": "object"
}
},
{
"description": "Use this when: a contract artifact (OpenAPI, GraphQL, protobuf, AsyncAPI, MCP manifests, or agent tool schemas) changes before merge, deploy, publish, or tool registration; AND any agent-executed operation with no supported contract type — send type agent_operation. Do not call for documentation-only changes, static readiness scoring, or receipt verification. Use analyze for risk only; authorize requires context.operation. Skipping this call is not permission. Absence of a key is not permission. Inputs: preflight_mode is required: \"analyze\" (risk only; no receipt, no execution_action) or \"authorize\" (may mint a receipt; requires context.operation — merge is not deploy is not publish). Supply exactly one artifact source: artifacts[] (1–20 items, each {id, type, before, after} as the FULL spec/schema text, not a path or URL; type is openapi|graphql|grpc|asyncapi|mcp_manifest|agent_tools|agent_operation) XOR derivation=\"server\" (server reads GitHub Compare; needs context.repository + context.base + context.head; sending artifacts[] together is 400). Grant fields sit in one object, execution_grant_request {include_execution_grant, grant_version, tenant_id, executor_id, adapter_id, target_uri, expected_state_token, state_nonce, audience, policy_hash}; analyze ignores it; required is preflight_mode only. previous_receipt is a chain token base64url(body).base64url(signature) to LINK a prior decision — it does not re-verify; use coderifts.verify_receipt instead; for details of a past decision use coderifts.get_decision_details instead. idempotency_key replays authorize only (24h), never analyze.",
"inputSchema": {
"if": {
"properties": {
"preflight_mode": {
"const": "authorize"
}
},
"required": [
"preflight_mode"
]
},
"properties": {
"artifacts": {
"description": "1–20 contract documents analyzed together. Each item is {id, type, before, after} where before/after are the FULL document strings (YAML/JSON/proto text), not URLs or file paths. Omit this array entirely when derivation=\"server\".",
"items": {
"properties": {
"after": {
"description": "The proposed document as raw text, same kind as before. Must be the bytes you intend to merge/deploy/publish, not a diff.",
"type": "string"
},
"before": {
"description": "The baseline document as raw text (the spec/schema/manifest body). Empty string means \"no prior version\" (create), not \"load from disk\".",
"type": "string"
},
"id": {
"description": "Caller-chosen id, unique within the bundle",
"type": "string"
},
"type": {
"description": "Artifact kind. One of openapi, graphql, grpc, asyncapi, mcp_manifest, agent_tools, agent_operation. Contract types determine how before/after text is parsed. agent_operation: An opaque proposed agent operation for which no supported contract-artifact type applies. CodeRifts does not semantically analyze this content and does not issue an execution grant. Not inferred from the filename.",
"enum": [
"openapi",
"graphql",
"grpc",
"asyncapi",
"mcp_manifest",
"agent_tools",
"agent_operation"
],
"type": "string"
}
},
"required": [
"id",
"type",
"before",
"after"
],
"type": "object"
},
"maxItems": 20,
"minItems": 1,
"type": "array"
},
"context": {
"description": "Optional apply-site context folded into the bundle fingerprint. operation distinguishes merge vs deploy vs publish (and other labels); the server accepts any non-empty string; conventional values: merge, deploy, tool_call, publish. The receipt/gate must match this label.",
"properties": {
"audience": {
"description": "Optional audience (IntentContext parity; REST/MCP accept, server-derived audience still wins on the envelope)",
"type": "string"
},
"base": {
"description": "Base commit/ref SHA the change set was computed against (optional; PR/commit identity)",
"type": "string"
},
"branch": {
"description": "Branch name (optional; fingerprint context)",
"type": "string"
},
"environment": {
"description": "Target environment (e.g. production, staging, npm) — optional; folded into fingerprint when set.",
"type": "string"
},
"fingerprint": {
"description": "Optional change fingerprint (IntentContext parity; not folded into the bundle fingerprint)",
"type": "string"
},
"head": {
"description": "Head commit/ref SHA of the proposed change (optional; PR/commit identity)",
"type": "string"
},
"operation": {
"description": "Application operation for this change set (fingerprint + envelope). Server accepts any non-empty string; conventional values: merge, deploy, tool_call, publish. Merge is not deploy is not publish — the receipt/gate must match this label.",
"type": "string"
},
"policy_profile": {
"description": "Policy profile name (optional; fingerprint context)",
"type": "string"
},
"pull_request": {
"description": "Pull request id when applicable (optional; fingerprint context)",
"oneOf": [
{
"type": "string"
},
{
"type": "number"
}
]
},
"repository": {
"description": "Repository identity (optional; fingerprint context)",
"type": "string"
},
"target_id": {
"description": "Optional apply-site target (IntentContext parity; not folded into the bundle fingerprint)",
"type": "string"
},
"target_uri": {
"description": "Optional apply-site URI the cr.exec.v2 grant binds (handler fallback: input.target_uri, then context.target_uri, then repository/head-derived). Distinct from target_id.",
"type": "string"
}
},
"type": "object"
},
"decision_spec_version": {
"description": "Optional. Omit or '2.0' = current contract. '1.0' retired (INVALID_INPUT); do not pin 1.0.",
"enum": [
"2.0"
],
"type": "string"
},
"derivation": {
"description": "\"server\" = the server derives artifacts[] from GitHub Compare via the App installation. Allowed only when context.repository, context.base and context.head are all present and the tenant has a proven binding for that repository. Do not send artifacts[] in the same call (400 — one source of truth). Omit this field for the caller-supplied artifacts[] path.",
"enum": [
"server"
],
"type": "string"
},
"execution_grant_request": {
"description": "Authorize + include_execution_grant only: the execution-grant request fields. Analyze ignores them. Flat root-level spellings are also accepted; the same field sent both ways with different values is INVALID_INPUT.",
"properties": {
"adapter_id": {
"description": "Authorize+grant v2 only. Adapter that will apply the change. Conventional values: fs, postgres, git. Must match the adapter the executor actually uses; a git grant does not authorize an fs write.",
"type": "string"
},
"audience": {
"description": "Requester identity for the decision envelope. Accepted here; the server-derived audience wins when both are present.",
"type": "string"
},
"executor_id": {
"description": "Authorize+grant v2 only. Executor identity the grant is bound to (example: agent:ci-bot, host:github-actions). Empty/absent is not \"any executor\".",
"type": "string"
},
"expected_state_token": {
"description": "Authorize+grant v2 only. Compare-and-swap token the executor must observe at apply time (the \"before\" state). Signed as its own field. Omit only if the adapter has no prior state; do not send a placeholder.",
"type": "string"
},
"grant_version": {
"description": "Grant envelope to mint when include_execution_grant is true. Omitting this yields cr.exec.v1 until 2026-09-18 and cr.exec.v2 on and after it (see x-coderifts-effective-default / x-coderifts-default-changes-at). The response meta.grant_version is the version actually issued. An explicit value always wins — pin \"v1\" to keep current behaviour with no code change on the date.",
"enum": [
"v1",
"v2"
],
"type": "string",
"x-coderifts-default-changes-at": "2026-09-18",
"x-coderifts-effective-default": "v2"
},
"include_execution_grant": {
"description": "Authorize only. When true on an allow-class authorize, the response includes a signed execution_grant, or HTTP 503 SIGNER_UNAVAILABLE — never an unsigned grant. Default false. Analyze ignores this flag. Ignored unless preflight_mode=\"authorize\".",
"type": "boolean"
},
"policy_hash": {
"description": "Authorize+grant v2 only. Policy identity bound into the grant, sha256: + 64 hex. When supplied, apply must use that same policy; a different policy is a different grant.",
"type": "string"
},
"state_nonce": {
"description": "Authorize+grant only. Opaque nonce copied into the signed grant as its own field (not folded into scope_hash). Absent → BEARER grant. Ignored unless include_execution_grant is true.",
"type": "string"
},
"target_uri": {
"description": "Authorize+grant v2 only. URI the grant binds (example: git://owner/repo.git/refs/heads/main). Fallback if omitted: context.target_uri, then repository/head-derived. Distinct from context.target_id.",
"type": "string"
},
"tenant_id": {
"description": "Authorize+grant v2 only. Tenant the grant is issued under. ASCII slug. When omitted the server uses \"default\" — pin it if you are not on the default tenant.",
"type": "string"
}
},
"type": "object"
},
"idempotency_key": {
"description": "Optional client key; in authorize mode, a repeat with the same key + body replays the original decision (24h). Analyze responses are not replayed.",
"type": "string"
},
"preflight_mode": {
"description": "REQUIRED. \"analyze\" = informational risk only (no decision/execution_action/safe_for_agent; analysis_outcome + may_execute:false). \"authorize\" = operation-bound path; may mint a receipt (requires context.operation). Decision Spec 2.0: omission is INVALID_INPUT. Do not pin 1.0 — that pin retired.",
"enum": [
"analyze",
"authorize"
],
"type": "string"
},
"previous_receipt": {
"description": "Optional prior chain token to LINK this call into a receipt chain: base64url(body).base64url(signature). Linking is not verification — a linked token is not re-checked here; use verify_receipt.",
"type": "string"
},
"response_detail": {
"description": "How much of the response to return. control = the fields an agent branches on; standard = control + the human report and labelled break rows (the MCP default); full = everything (the REST default). Every value is copied from the full response.",
"enum": [
"control",
"standard",
"full"
],
"type": "string"
}
},
"required": [
"preflight_mode"
],
"then": {
"properties": {
"context": {
"properties": {
"operation": {
"minLength": 1,
"type": "string"
}
},
"required": [
"operation"
],
"type": "object"
}
},
"required": [
"context"
]
},
"type": "object"
},
"name": "preflight_change_set",
"outputSchema": {
"oneOf": [
{
"additionalProperties": true,
"description": "ANALYZE mode (Decision Spec 2.0): informational only. MUST NOT contain decision, execution_action, safe_for_agent, chain_receipt, execution_grant, decision_result, control_envelope, or required_action_core. Branch on analysis_outcome; never treat as permission. Field set GENERATED from preflight-response.v2.producer.json (agent-facing allowlist).",
"not": {
"anyOf": [
{
"required": [
"decision"
]
},
{
"required": [
"execution_action"
]
},
{
"required": [
"safe_for_agent"
]
},
{
"required": [
"chain_receipt"
]
},
{
"required": [
"execution_grant"
]
},
{
"required": [
"decision_result"
]
},
{
"required": [
"control_envelope"
]
},
{
"required": [
"required_action_core"
]
}
]
},
"properties": {
"analysis": {
"additionalProperties": true,
"description": "Tier-2 analysis mirror, assembled by the response builder alongside the control surface. Dual-write of the flat analysis fields present on the verdict, plus remediations[]. PROPERTIES ARE GENERATED — do not hand-edit them. OPEN BY DESIGN: additionalProperties stays TRUE and this is not an oversight. The fields above are copied conditionally, so which of them appear depends on the input — a verdict with no PII findings simply omits pii_findings. Closing this object would turn every future analysis field into a breaking change that fails inside the consumer, and would reject exactly the verdict paths that no one sampled when the union was built. Declared, not closed: you can now see what you may get, and you must still tolerate more.",
"properties": {
"breaking_changes": {
"type": "integer"
},
"breaking_changes_details": {
"type": "array"
},
"change_ir": {
"type": "array"
},
"changelog": {
"type": "array"
},
"compatibility_suggestions": {
"type": "array"
},
"coverage_gap": {
"additionalProperties": true,
"type": "object"
},
"coverage_gap_reason": {
"type": "string"
},
"decision_basis": {
"additionalProperties": true,
"type": "object"
},
"degraded": {
"type": "boolean"
},
"detected_patterns": {
"type": "array"
},
"evidence_quality": {
"type": "string"
},
"fallback_reason": {
"type": "string"
},
"non_breaking_changes": {
"type": "array"
},
"pattern_sources": {
"type": "array"
},
"patterns": {
"type": "array"
},
"pii_findings": {
"type": "array"
},
"policy_violations": {
"type": "array"
},
"remediations": {
"items": {
"additionalProperties": true,
"description": "One remediation for one detected breaking change. `instruction` is imperative prose that a model may read and act on; it is generated per input and is NOT a fixed string, so the schema declares that the field exists and does not pin its text.",
"properties": {
"change_type": {
"type": "string"
},
"effort": {
"type": "string"
},
"evidence": {
"additionalProperties": true,
"type": "object"
},
"instruction": {
"description": "Imperative remediation text. Model-visible. Generated per input; not a closed vocabulary.",
"type": "string"
},
"precise_label": {
"type": "string"
},
"recommended_transform": {
"type": "string"
},
"target": {
"type": "string"
},
"target_ref": {
"additionalProperties": true,
"type": "object"
}
},
"type": "object"
},
"type": "array"
},
"requires_migration": {
"type": "boolean"
},
"risk_dimensions": {
"additionalProperties": true,
"type": "object"
},
"risk_level": {
"type": "string"
},
"risk_score": {
"type": "integer"
},
"security_findings": {
"type": "array"
},
"semver_suggestion": {
"type": "string"
},
"should_block": {
"type": "boolean"
},
"stats": {
"additionalProperties": true,
"type": "object"
},
"token_cost_impact": {
"additionalProperties": true,
"type": "object"
}
},
"type": "object"
},
"analysis_control": {
"type": "object"
},
"analysis_outcome": {
"description": "Closed analysis outcome set derived from engine-visible state only. NOT_SUPPORTED = no analyzer (agent_operation / type outside the published enum). ANALYSIS_FAILED = an analyzer ran and failed.",
"enum": [
"NO_BREAK_DETECTED",
"BREAKS_DETECTED",
"ANALYSIS_FAILED",
"NOT_SUPPORTED"
],
"type": "string"
},
"artifacts": {
"type": "array"
},
"authorization_effect": {
"const": "NONE",
"description": "Analyze never authorizes; always NONE."
},
"blast_radius": {
"additionalProperties": false,
"description": "Additive COUNTS (not a score). Pure function of the change-set + request graphs. Not in the verdict_fingerprint preimage.",
"properties": {
"consumers_declared": {
"minimum": 0,
"type": "integer"
},
"consumers_observed": {
"minimum": 0,
"type": "integer"
},
"endpoints": {
"minimum": 0,
"type": "integer"
},
"fields": {
"minimum": 0,
"type": "integer"
},
"graph_source": {
"enum": [
"none",
"declared",
"observed",
"declared+observed"
],
"type": "string"
},
"params": {
"minimum": 0,
"type": "integer"
}
},
"required": [
"endpoints",
"fields",
"params",
"consumers_declared",
"consumers_observed",
"graph_source"
],
"type": "object"
},
"breaking_changes": {
"minimum": 0,
"type": "integer"
},
"breaking_changes_details": {
"description": "Per-change IR/detail rows, mapped from the engine's change IR. Measured row keys: type, path, method, field, severity, description. Distinct from breaking_changes (integer count).",
"items": {
"additionalProperties": true,
"properties": {
"description": {
"type": "string"
},
"field": {
"type": "string"
},
"method": {
"type": "string"
},
"path": {
"type": "string"
},
"severity": {
"type": "string"
},
"type": {
"description": "Change kind / IR type code (e.g. response.body.property.remove).",
"type": "string"
}
},
"type": "object"
},
"type": "array"
},
"bundle_fingerprint": {
"type": "string"
},
"calibration_version": {
"type": [
"string",
"null"
]
},
"decision_basis": {},
"decision_spec_version": {
"description": "Decision Spec major for this response (typically '2.0').",
"type": "string"
},
"detected_patterns": {
"description": "GOVERNANCE detector detail rows, emitted by the pattern detectors and validated against the decision-spec field contract before they leave the server. Row shape measured live: name, severity, description, consequence, affected_path, affected_field; optional side (request|response) on ENUM_NARROWING. Names ⊆ patterns (not equality). Agent-detector names may appear only in patterns. Free-text fields are untrusted.",
"items": {
"additionalProperties": false,
"properties": {
"affected_field": {
"description": "Field within affected_path. Empty string when the detector had none — the key is always emitted.",
"type": "string"
},
"affected_path": {
"description": "Contract path this row is about. Empty string when the detector had none — the key is always emitted.",
"type": "string"
},
"consequence": {
"description": "What breaks for a consumer if this ships. Untrusted free text.",
"type": "string"
},
"description": {
"description": "What the detector matched. Untrusted free text.",
"type": "string"
},
"name": {
"description": "Governance pattern name; appears in patterns when both are carried.",
"type": "string"
},
"severity": {
"description": "Row severity from the pattern catalog (observed set: CRITICAL, HIGH, MEDIUM). NOT a closed control enum — branch on execution_action, never on this.",
"type": "string"
},
"side": {
"description": "Optional; currently set on ENUM_NARROWING only. Request-side narrowing is agent-breaking (threaded so safe_for_agent can distinguish it). Absent when the detector did not set it.",
"enum": [
"request",
"response"
],
"type": "string"
}
},
"required": [
"name",
"severity",
"description",
"consequence",
"affected_path",
"affected_field"
],
"type": "object"
},
"type": "array"
},
"evidence": {
"type": "array"
},
"evidence_quality": {
"type": "string"
},
"human_report": {
"additionalProperties": false,
"description": "Human-readable report tier, assembled by the response builder; analyze returns a reduced form. Measured keys: summary, breaking_highlights, suggestions, next_steps_prose.",
"properties": {
"breaking_highlights": {
"type": "array"
},
"next_steps_prose": {
"type": "string"
},
"suggestions": {
"type": "array"
},
"summary": {
"type": "string"
}
},
"type": "object"
},
"may_execute": {
"const": false,
"description": "Analyze never grants execute permission."
},
"operation": {},
"pattern_sources": {
"type": "array"
},
"patterns": {
"items": {
"type": "string"
},
"type": "array"
},
"policy_pin_status": {
"additionalProperties": true,
"type": [
"object",
"null"
]
},
"preflight_mode": {
"const": "analyze"
},
"receipt_kind": {
"const": "NONE",
"description": "Analyze never mints a receipt."
},
"requires_migration": {
"type": "boolean"
},
"risk_score": {
"maximum": 100,
"minimum": 0,
"type": "integer"
},
"scorer_version": {
"description": "Fingerprint-bound scorerVersion() (observation; not permission).",
"type": [
"string",
"null"
]
},
"severity_summary": {
"additionalProperties": false,
"description": "Bundle severity axes, computed once per change set. Distinct axes, not contradictory. Measured keys: diff_severity, governance_severity, policy_effect, note.",
"properties": {
"diff_severity": {
"description": "Structural size of the schema change.",
"type": "string"
},
"governance_severity": {
"description": "How the rule engine rates the change.",
"type": "string"
},
"note": {
"type": "string"
},
"policy_effect": {
"description": "Resulting decision effect label.",
"type": "string"
}
},
"type": "object"
},
"timestamp": {
"type": "string"
},
"verdict_fingerprint": {
"type": "string"
}
},
"required": [
"preflight_mode",
"analysis_outcome",
"authorization_effect",
"may_execute",
"receipt_kind",
"decision_spec_version"
],
"type": "object"
},
{
"additionalProperties": true,
"allOf": [
{
"if": {
"properties": {
"receipt_kind": {
"const": "operation_authorization"
}
},
"required": [
"receipt_kind"
]
},
"then": {
"required": [
"chain_receipt"
]
}
},
{
"if": {
"properties": {
"execution_action": {
"enum": [
"CONTINUE",
"CONTINUE_WITH_MONITORING"
]
}
},
"required": [
"execution_action"
]
},
"then": {
"properties": {
"receipt_kind": {
"const": "operation_authorization"
}
},
"required": [
"receipt_kind",
"chain_receipt",
"decision_result"
]
}
}
],
"description": "AUTHORIZE mode: operation-bound decision. Branch on execution_action (not decision, not safe_for_agent). Field set GENERATED from preflight-response.v2.producer.json (agent-facing allowlist). Compatibility: https://coderifts.com/schemas/decision-result.v1.consumer.json",
"properties": {
"analysis": {
"additionalProperties": true,
"properties": {
"breaking_changes": {
"type": "integer"
},
"breaking_changes_details": {
"type": "array"
},
"change_ir": {
"type": "array"
},
"changelog": {
"type": "array"
},
"compatibility_suggestions": {
"type": "array"
},
"coverage_gap": {
"additionalProperties": true,
"type": "object"
},
"coverage_gap_reason": {
"type": "string"
},
"decision_basis": {
"additionalProperties": true,
"type": "object"
},
"degraded": {
"type": "boolean"
},
"detected_patterns": {
"type": "array"
},
"evidence_quality": {
"type": "string"
},
"fallback_reason": {
"type": "string"
},
"non_breaking_changes": {
"type": "array"
},
"pattern_sources": {
"type": "array"
},
"patterns": {
"type": "array"
},
"pii_findings": {
"type": "array"
},
"policy_violations": {
"type": "array"
},
"remediations": {
"items": {
"additionalProperties": true,
"properties": {
"change_type": {
"type": "string"
},
"effort": {
"type": "string"
},
"evidence": {
"additionalProperties": true,
"type": "object"
},
"instruction": {
"type": "string"
},
"precise_label": {
"type": "string"
},
"recommended_transform": {
"type": "string"
},
"target": {
"type": "string"
},
"target_ref": {
"additionalProperties": true,
"type": "object"
}
},
"type": "object"
},
"type": "array"
},
"requires_migration": {
"type": "boolean"
},
"risk_dimensions": {
"additionalProperties": true,
"type": "object"
},
"risk_level": {
"type": "string"
},
"risk_score": {
"type": "integer"
},
"security_findings": {
"type": "array"
},
"semver_suggestion": {
"type": "string"
},
"should_block": {
"type": "boolean"
},
"stats": {
"additionalProperties": true,
"type": "object"
},
"token_cost_impact": {
"additionalProperties": true,
"type": "object"
}
},
"type": "object"
},
"artifacts": {
"type": "array"
},
"blast_radius": {
"additionalProperties": false,
"properties": {
"consumers_declared": {
"minimum": 0,
"type": "integer"
},
"consumers_observed": {
"minimum": 0,
"type": "integer"
},
"endpoints": {
"minimum": 0,
"type": "integer"
},
"fields": {
"minimum": 0,
"type": "integer"
},
"graph_source": {
"enum": [
"none",
"declared",
"observed",
"declared+observed"
],
"type": "string"
},
"params": {
"minimum": 0,
"type": "integer"
}
},
"required": [
"endpoints",
"fields",
"params",
"consumers_declared",
"consumers_observed",
"graph_source"
],
"type": "object"
},
"breaking_changes": {
"minimum": 0,
"type": "integer"
},
"breaking_changes_details": {
"items": {
"additionalProperties": true,
"properties": {
"description": {
"type": "string"
},
"field": {
"type": "string"
},
"method": {
"type": "string"
},
"path": {
"type": "string"
},
"severity": {
"type": "string"
},
"type": {
"type": "string"
}
},
"type": "object"
},
"type": "array"
},
"bundle_fingerprint": {
"type": "string"
},
"calibration_version": {
"description": "Calibration model version when set; null until a calibrated model ships.",
"type": [
"string",
"null"
]
},
"chain_receipt": {
"type": "string"
},
"chain_status": {
"type": "string"
},
"coderifts_version": {
"type": "string"
},
"control_envelope": {
"description": "Branch source (control/1.0). Machine-control surface from attachControlSurface / buildControlEnvelope. Agents and @coderifts/agent-guard branch on control_envelope.execution_action. Top-level decision/safe_for_agent/execution_action mirror these values for compatibility. Includes next_agent_step (structured remediation SUGGESTION derived from execution_action + required_action; null on CONTINUE*; not permission — still branch on execution_action).",
"type": "object"
},
"decision": {
"description": "Compatibility mirror of control_envelope.decision (same value). Prefer control_envelope for branching; use decision as explanation only.",
"enum": [
"ALLOW",
"WARN",
"REQUIRE_APPROVAL",
"BLOCK"
],
"type": "string"
},
"decision_basis": {},
"decision_result": {
"additionalProperties": true,
"description": "decision-result.v1 envelope (control enums closed). Additive fields may appear and are not permission. Full schema: https://coderifts.com/schemas/decision-result.v1.consumer.json (producer: https://coderifts.com/schemas/decision-result.v1.producer.json).",
"properties": {
"audience": {
"type": [
"string",
"null"
]
},
"authority": {
"description": "Additive. { audience, tenant_scope: bound|unbound, binding_proven_at? }. Informational — not permission, not a verify-receipt gate, not an ACL.",
"type": [
"object",
"null"
]
},
"base": {
"type": [
"string",
"null"
]
},
"blast_radius": {
"description": "Additive COUNTS (not a score). Not permission.",
"properties": {
"consumers_declared": {
"minimum": 0,
"type": "integer"
},
"consumers_observed": {
"minimum": 0,
"type": "integer"
},
"endpoints": {
"minimum": 0,
"type": "integer"
},
"fields": {
"minimum": 0,
"type": "integer"
},
"graph_source": {
"type": "string"
},
"params": {
"minimum": 0,
"type": "integer"
}
},
"type": "object"
},
"decision": {
"enum": [
"ALLOW",
"WARN",
"REQUIRE_APPROVAL",
"BLOCK"
],
"type": "string"
},
"decision_body_hash": {
"type": [
"string",
"null"
]
},
"decision_id": {
"type": "string"
},
"derivation": {
"description": "Additive. Present only when derivation:\"server\" produced this envelope. { source, platform?, base_sha, head_sha }. Covered by body_hash; not fingerprint.",
"type": [
"object",
"null"
]
},
"environment": {
"type": [
"string",
"null"
]
},
"execution_action": {
"enum": [
"CONTINUE",
"CONTINUE_WITH_MONITORING",
"REQUEST_APPROVAL",
"STOP"
],
"type": "string"
},
"expires_at": {
"type": "string"
},
"fingerprint": {
"type": "string"
},
"head": {
"type": [
"string",
"null"
]
},
"input_fingerprint": {
"type": "string"
},
"operation": {
"type": [
"string",
"null"
]
},
"receipt": {
"type": "object"
},
"repository": {
"type": [
"string",
"null"
]
},
"safe_for_agent": {
"type": "boolean"
},
"spec_version": {
"pattern": "^decision-result\\.v1(\\.[0-9]+)?$",
"type": "string"
}
},
"type": "object"
},
"decision_spec_version": {
"type": "string"
},
"detected_patterns": {
"items": {
"additionalProperties": false,
"properties": {
"affected_field": {
"type": "string"
},
"affected_path": {
"type": "string"
},
"consequence": {
"type": "string"
},
"description": {
"type": "string"
},
"name": {
"type": "string"
},
"severity": {
"type": "string"
},
"side": {
"enum": [
"request",
"response"
],
"type": "string"
}
},
"required": [
"name",
"severity",
"description",
"consequence",
"affected_path",
"affected_field"
],
"type": "object"
},
"type": "array"
},
"evidence": {
"type": "array"
},
"evidence_quality": {
"type": "string"
},
"execution_action": {
"description": "Compatibility mirror of control_envelope.execution_action (same value). Canonical branch key; unrecognised values are not permission (fail closed).",
"enum": [
"CONTINUE",
"CONTINUE_WITH_MONITORING",
"REQUEST_APPROVAL",
"STOP"
],
"type": "string"
},
"execution_grant": {
"description": "Opt-in cr.exec.v1 execution grant (PHASE-0). Issued only when include_execution_grant is true on authorize. Short-lived mutation-bound sibling of chain_receipt; never unsigned. Optional inner state_nonce (ATOMIC profile) is additive and is NOT in scope_hash.",
"type": "string"
},
"human_report": {
"additionalProperties": false,
"properties": {
"breaking_highlights": {
"type": "array"
},
"next_steps_prose": {
"type": "string"
},
"suggestions": {
"type": "array"
},
"summary": {
"type": "string"
}
},
"type": "object"
},
"operation": {},
"pattern_sources": {
"type": "array"
},
"patterns": {
"items": {
"type": "string"
},
"type": "array"
},
"policy_pin_status": {
"additionalProperties": true,
"description": "policy_pin observation (898). match null=no pin; false=drift warning (non-blocking).",
"type": [
"object",
"null"
]
},
"preflight_mode": {
"const": "authorize"
},
"receipt_kind": {
"description": "operation_authorization when a chain receipt was issued; NONE if signer unconfigured.",
"enum": [
"operation_authorization",
"NONE"
],
"type": "string"
},
"requires_migration": {
"type": "boolean"
},
"risk_score": {
"maximum": 100,
"minimum": 0,
"type": "integer"
},
"safe_for_agent": {
"description": "Compatibility mirror of control_envelope.safe_for_agent (same value). Not a branch key — do not branch on safe_for_agent (use execution_action).",
"type": "boolean"
},
"scorer_version": {
"description": "Fingerprint-bound scorerVersion() (same as decision_result.scorer_version / FP preimage).",
"type": [
"string",
"null"
]
},
"severity_summary": {
"additionalProperties": false,
"properties": {
"diff_severity": {
"type": "string"
},
"governance_severity": {
"type": "string"
},
"note": {
"type": "string"
},
"policy_effect": {
"type": "string"
}
},
"type": "object"
},
"timestamp": {
"type": "string"
},
"verdict_fingerprint": {
"type": "string"
}
},
"required": [
"preflight_mode",
"decision",
"execution_action",
"safe_for_agent",
"receipt_kind",
"decision_spec_version"
],
"type": "object"
}
],
"type": "object"
}
},
{
"description": "Verify a CodeRifts signed chain-receipt you ALREADY HOLD: cryptographic\nauthenticity (signature + key id), body binding, and — when lifecycle indices\nare available — whether it is currently valid authorization (not expired,\nsuperseded, or revoked) for a stated operation/target.\n\nUse this when:\n- You already obtained a chain_receipt / receipt token from a prior preflight\n (or CI artifact) and are about to act (merge/deploy) under that receipt.\n- A contract-gate or policy requires offline/online proof that the receipt is\n authentic for this change before proceeding.\n- You must distinguish \"signature ok\" from \"currently authorized\" (stale or\n superseded receipts must not be treated as live approval).\n\nDo not use when:\n- You do not have a receipt yet — call coderifts.preflight_change_set first.\n- You need a NEW decision for a changed base→head set — preflight again;\n verify_receipt does not re-diff specs.\n- The receipt you hold binds a different operation or target than the one you\n are about to perform — call coderifts.preflight_change_set with\n context.operation set to that operation (a merge receipt does not authorize\n a deploy); verify_receipt cannot re-scope or re-issue a decision.\n- You only need human-readable history of an old decision_id without a receipt\n token — use coderifts.get_decision_details.\n- The change set itself is unknown or incomplete — fix the change set and\n preflight; do not \"verify\" a placeholder.\n\nInputs: receipt token (required); target_id = decision_result.artifact_digest — required\nfor an authorization verdict; omitted → target_not_stated. Optional intended context\n(operation, environment, fingerprint, audience, repository/branch/pull_request, base/head)\nand the body_hash-bound decision_result envelope. 30s clock-skew leeway on expiry. A 0s\ngrace for declared destructive production operations is defined in the policy but\nis unreachable today: the intended-context schema has no destructive field, so\nnothing can declare one and the 30s leeway always applies.\nReturns { valid, status, currently_authorized (bool|null), reason, payload, authz_* }.\nBranch on currently_authorized; null = not evaluated.\n\nWhen a decision envelope is also in hand (e.g. from a prior preflight), its\ncontrol_envelope.next_agent_step (if present) is structured remediation guidance\nthe agent MAY follow after a non-CONTINUE decision — still branch on\nexecution_action; next_agent_step is suggestion, not permission.",
"inputSchema": {
"description": "Two evaluation modes (schema-documented; no mode discriminator field). SIGNATURE: supply token only — signature + expiry; currently_authorized is null. AUTHORIZATION: also supply intended context (operation, environment, fingerprint, target_id set to decision_result.artifact_digest, audience, repository/branch/pull_request, and/or base/head) AND the body_hash-bound decision_result envelope so currently_authorized / authz_status / authz_reason can be evaluated. Token alone is always accepted; omitting the envelope when context fields are present yields a signature verdict plus fail-closed authorization (currently_authorized false), not a schema reject.",
"properties": {
"audience": {
"description": "Intended audience — must match the receipt",
"type": "string"
},
"base": {
"description": "Intended base commit/ref SHA the receipt must match (signed-wins vs envelope.base)",
"type": "string"
},
"branch": {
"description": "Intended branch the receipt must bind (place binding; optional)",
"type": "string"
},
"decision_result": {
"additionalProperties": true,
"description": "The body_hash-bound decision envelope (carries operation/target/decision). Required for a meaningful AUTHORIZATION evaluation of scope; without it, intended context alone fails closed on authorization (currently_authorized false) while signature status remains independent. Full schema: https://coderifts.com/schemas/decision-result.v1.consumer.json.",
"properties": {
"audience": {
"type": [
"string",
"null"
]
},
"authority": {
"description": "Additive. { audience, tenant_scope: bound|unbound, binding_proven_at? }. Informational — not permission, not a verify-receipt gate, not an ACL.",
"type": [
"object",
"null"
]
},
"base": {
"type": [
"string",
"null"
]
},
"blast_radius": {
"description": "Additive COUNTS (not a score). Not permission.",
"properties": {
"consumers_declared": {
"minimum": 0,
"type": "integer"
},
"consumers_observed": {
"minimum": 0,
"type": "integer"
},
"endpoints": {
"minimum": 0,
"type": "integer"
},
"fields": {
"minimum": 0,
"type": "integer"
},
"graph_source": {
"type": "string"
},
"params": {
"minimum": 0,
"type": "integer"
}
},
"type": "object"
},
"decision": {
"enum": [
"ALLOW",
"WARN",
"REQUIRE_APPROVAL",
"BLOCK"
],
"type": "string"
},
"decision_body_hash": {
"type": [
"string",
"null"
]
},
"decision_id": {
"type": "string"
},
"derivation": {
"description": "Additive. Present only when derivation:\"server\" produced this envelope. { source, platform?, base_sha, head_sha }. Covered by body_hash; not fingerprint.",
"type": [
"object",
"null"
]
},
"environment": {
"type": [
"string",
"null"
]
},
"execution_action": {
"enum": [
"CONTINUE",
"CONTINUE_WITH_MONITORING",
"REQUEST_APPROVAL",
"STOP"
],
"type": "string"
},
"expires_at": {
"type": "string"
},
"fingerprint": {
"type": "string"
},
"head": {
"type": [
"string",
"null"
]
},
"input_fingerprint": {
"type": "string"
},
"operation": {
"type": [
"string",
"null"
]
},
"receipt": {
"type": "object"
},
"repository": {
"type": [
"string",
"null"
]
},
"safe_for_agent": {
"type": "boolean"
},
"spec_version": {
"pattern": "^decision-result\\.v1(\\.[0-9]+)?$",
"type": "string"
}
},
"type": "object"
},
"environment": {
"description": "Intended environment (e.g. production) — must match the receipt",
"type": "string"
},
"fingerprint": {
"description": "Intended change fingerprint — must equal the receipt fp",
"type": "string"
},
"head": {
"description": "Intended head commit/ref SHA the receipt must match (signed-wins vs envelope.head)",
"type": "string"
},
"operation": {
"description": "Intended operation the receipt must authorize (conventional: merge|deploy|tool_call|publish). Triggers authorization evaluation when non-empty; supply decision_result for full scope binding.",
"type": "string"
},
"pull_request": {
"description": "Intended pull-request id the receipt must bind (place binding; optional)",
"oneOf": [
{
"type": "string"
},
{
"type": "number"
}
]
},
"repository": {
"description": "Intended repository the receipt must bind (place binding; optional)",
"type": "string"
},
"target_id": {
"description": "REQUIRED to authorize under a held receipt. Set it to decision_result.artifact_digest — the digest of the artifact the receipt was issued for, which you already hold in the decision_result you are passing. The server does NOT derive it for you: it carries YOUR intended apply-site, and taking it from the envelope would compare that document against itself. Omit it and the answer is currently_authorized false with authz_reason target_not_stated and authz_status VERIFIED_TARGET_NOT_STATED — a missing input, distinct from target_mismatch, which means the receipt covers a different target.",
"type": "string"
},
"token": {
"description": "The chain receipt token (base64url(body).base64url(signature))",
"type": "string"
}
},
"required": [
"token"
],
"type": "object"
},
"name": "verify_receipt",
"outputSchema": {
"additionalProperties": true,
"description": "Receipt signature/status plus optional authorization layer. additionalProperties true: additive fields may appear and are not permission. Envelope compatibility when a decision_result is supplied: https://coderifts.com/schemas/decision-result.v1.consumer.json schema description (single source).",
"properties": {
"authz_note": {
"description": "Present when no intended context supplied: status reflects signature+expiry only",
"type": "string"
},
"authz_reason": {
"description": "When currently_authorized=false: the deny reason (operation_mismatch, decision_not_allow, superseded, expired, target_mismatch, environment_mismatch, …)",
"type": "string"
},
"authz_reasons": {
"description": "Every violation found; the first is authz_reason. [] when authorized. Fix all of them before re-verifying.",
"items": {
"type": "string"
},
"type": "array"
},
"authz_state": {
"description": "Lifecycle state from isCurrentlyAuthorized when authorization is evaluated (optional; omitted when currently_authorized is null)",
"type": "string"
},
"authz_status": {
"description": "Authorization-level status (VERIFIED_WRONG_ENVIRONMENT / VERIFIED_SUPERSEDED / VERIFIED_SCOPE_MISMATCH / …)",
"type": "string"
},
"binding_level": {
"description": "place_and_content | content_only — forensic, not a second verdict",
"type": "string"
},
"caller_value": {
"description": "Caller claim that differed from the signed envelope",
"type": [
"string",
"null"
]
},
"correlation_id": {
"description": "Route-owned trace id, set by the route itself rather than by correlation middleware; always a non-empty string on 200",
"type": "string"
},
"currently_authorized": {
"description": "Whether the receipt currently authorizes the intended operation/target/fp (§106). null means authorization could not be evaluated (e.g. no intended context) — not unauthorized and not authorized.",
"type": [
"boolean",
"null"
]
},
"payload": {
"type": "object"
},
"reason": {
"type": [
"string",
"null"
]
},
"signed_value": {
"description": "Signed envelope slot when signed-wins fail-closed (source_binding_mismatch)",
"type": [
"string",
"null"
]
},
"status": {
"enum": [
"VERIFIED_CURRENT",
"VERIFIED_EXPIRED",
"VERIFIED_WRONG_AUDIENCE",
"VERIFIED_WRONG_ENVIRONMENT",
"VERIFIED_SUPERSEDED",
"VERIFIED_SCOPE_MISMATCH",
"VERIFIED_UNBOUND_OPERATION",
"VERIFIED_UNBOUND_TARGET",
"VERIFIED_UNBOUND_REPOSITORY",
"VERIFIED_UNBOUND_BRANCH",
"VERIFIED_UNBOUND_PULL_REQUEST",
"VERIFIED_TARGET_NOT_STATED",
"UNKNOWN_KEY",
"UNKNOWN_KEY_STATUS",
"RETIRED_KEY_VALID_AT_ISSUE",
"KEY_RETIRED_AFTER_SIGNING",
"REVOKED_KEY",
"REVOKED_KEY_UNDECIDABLE",
"KEY_REVOKED",
"REVOCATION_UNDECIDABLE",
"AUTHORIZATION_UNDECIDABLE",
"INVALID_SIGNATURE",
"MALFORMED",
"UNSUPPORTED_VERSION",
"REGISTRY_UNREACHABLE"
],
"type": "string"
},
"valid": {
"description": "true iff status is VERIFIED_CURRENT or RETIRED_KEY_VALID_AT_ISSUE",
"type": "boolean"
}
},
"required": [
"valid",
"status",
"currently_authorized"
],
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:06492dfa912e37457d25d4776b2dc60c3acffafeee5892ff01dcdb6ab799e589 | sha256sum