MCPサーバー

api-governance

io.github.coderifts/api-governance
開発者向けツール セキュリティ 公開・接続可能 MCP 2026-07-28

このMCPでできること

Preflights API, schema, MCP manifest, and agent-operation changes, and verifies signed authorization receipts for governed changes.

get_decision_details
Retrieve a PAST CodeRifts decision by exactly one identifier (case_id | decision_id | fingerprint): full report, breaking changes, scores, and linked receipt metadata if stored. Use this when: - You have a decision_id (or fingerprint) from a previous preflight, PR comment, or CI log and need to inspect or explain that past decision. - You are auditing why a prior ALLOW/WARN/BLOCK was issued. - You are NOT requesting a new analysis of current before/after specs. Do not use when: - You need a decision for the CURRENT uncommitted or PR head change set — call coderifts.preflight_change_set with the current artifacts. - You hold a receipt token and only need cryptographic/lifecycle verification — use coderifts.verify_receipt. - You have no identifier — run preflight first to create one. Inputs: exactly one of case_id, decision_id, or fingerprint. {} → INVALID_INPUT; two identifiers → LOOKUP_IDENTIFIER_CONFLICT; case_id → CASE_NOT_FOUND (lookup never opens a case). Returns the stored document or not_found. Scoping — fingerprint lookup returns only YOUR OWN decisions. A fingerprint is derived from content, not from an account, so two callers who preflight byte-identical specs derive the same one; the lookup is therefore constrained to the decisions your credential can prove it owns. A decision that exists but is not yours returns the SAME not_found as one that was never issued. This is deliberate: a distinguishable "exists but forbidden" would confirm to any caller that a given content hash had been decided on by someone, which is the fact the scoping exists to withhold. Do not read not_found as proof that no such decision exists anywhere. Decisions persisted without context.repository cannot currently be attributed to an account, and are not retrievable by fingerprint at all — not by their owner either. Retrieve those by decision_id, which is unchanged and unscoped. This is a limitation of what older stored rows carry, not a property of the lookup: rows written from now on record the account directly, so the gap narrows as older rows age out. If a fingerprint you expect returns not_found, use the decision_id before concluding the decision is missing. When the stored envelope carries control fields, control_envelope.next_agent_step is structured remediation guidance the agent MAY follow for non-CONTINUE execution_action values (null on CONTINUE*). Still branch on execution_action; next_agent_step is a suggestion, not permission.
読み取り専用
入力スキーマ
{'type': 'object', 'properties': {'case_id': {'type': 'string', 'minLength': 1, 'description': 'A case identifier. Lookup never opens a case. Until the case store exists this returns CASE_NOT_FOUND.'}, 'decision_id': {'type': 'string', 'minLength': 1, 'description': 'The decision_id from a prior decision_result envelope. Provide exactly one identifier.'}, 'fingerprint': {'type': 'string', 'minLength': 1, 'description': 'A verdict fingerprint (sha256:...); returns the latest matching decision you own. Provide exactly one identifier.'}}, 'description': 'Closed exclusive identifier union: exactly one of case_id | decision_id | fingerprint. Encoded as minProperties=1 + maxProperties=1 + additionalProperties=false, NOT as a top-level oneOf/anyOf/allOf — Anthropic (and other strict tool APIs) reject those combinators at the root of input_schema and then refuse the entire tools array (measured: test/mcp-input-oneof-honesty.test.js, mcp-streamable.js comment). The server enforces the same mutex with named codes: empty {} → INVALID_INPUT; two or more identifiers → LOOKUP_IDENTIFIER_CONFLICT; case_id alone → CASE_NOT_FOUND (no case store yet; lookup never opens a case).', 'maxProperties': 1, 'minProperties': 1, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'required': ['decision_result', 'meta'], 'properties': {'meta': {'type': 'object', 'properties': {'source': {'type': 'string'}, 'created_at': {'type': 'string'}, 'decision_id': {'type': 'string'}, 'retrieval_mode': {'enum': ['stored'], 'type': 'string'}, 'omitted_sections': {'type': 'array'}}, 'additionalProperties': True}, 'decision': {'enum': ['ALLOW', 'WARN', 'REQUIRE_APPROVAL', 'BLOCK'], 'type': 'string'}, 'evidence': {'type': ['object', 'array', 'null']}, 'patterns': {'type': 'array', 'items': {'type': 'string'}}, 'operation': {'type': 'string'}, 'timestamp': {'type': 'string'}, 'risk_score': {'type': 'integer', 'maximum': 100, 'minimum': 0}, 'receipt_kind': {'enum': ['NONE', 'operation_authorization'], 'type': 'string'}, 'chain_receipt': {'type': 'string'}, 'preflight_mode': {'enum': ['analyze', 'authorize'], 'type': 'string'}, 'safe_for_agent': {'type': 'boolean'}, 'decision_result': {'type': 'object', 'properties': {'base': {'type': ['string', 'null']}, 'head': {'type': ['string', 'null']}, 'receipt': {'type': 'object'}, 'audience': {'type': ['string', 'null']}, 'decision': {'enum': ['ALLOW', 'WARN', 'REQUIRE_APPROVAL', 'BLOCK'], 'type': 'string'}, 'authority': {'type': ['object', 'null'], 'description': 'Additive. { audience, tenant_scope: bound|unbound, binding_proven_at? }. Informational — not permission, not a verify-receipt gate, not an ACL.'}, 'operation': {'type': ['string', 'null']}, 'derivation': {'type': ['object', 'null'], 'description': 'Additive. Present only when derivation:"server" produced this envelope. { source, platform?, base_sha, head_sha }. Covered by body_hash; not fingerprint.'}, 'expires_at': {'type': 'string'}, 'repository': {'type': ['string', 'null']}, 'decision_id': {'type': 'string'}, 'environment': {'type': ['string', 'null']}, 'fingerprint': {'type': 'string'}, 'blast_radius': {'type': 'object', 'properties': {'fields': {'type': 'integer', 'minimum': 0}, 'params': {'type': 'integer', 'minimum': 0}, 'endpoints': {'type': 'integer', 'minimum': 0}, 'graph_source': {'type': 'string'}, 'consumers_declared': {'type': 'integer', 'minimum': 0}, 'consumers_observed': {'type': 'integer', 'minimum': 0}}, 'description': 'Additive COUNTS (not a score). Not permission.'}, 'spec_version': {'type': 'string', 'pattern': '^decision-result\\.v1(\\.[0-9]+)?$'}, 'safe_for_agent': {'type': 'boolean'}, 'execution_action': {'enum': ['CONTINUE', 'CONTINUE_WITH_MONITORING', 'REQUEST_APPROVAL', 'STOP'], 'type': 'string'}, 'input_fingerprint': {'type': 'string'}, 'decision_body_hash': {'type': ['string', 'null']}}, 'description': 'decision-result.v1 envelope (control enums closed). Additive fields may appear and are not permission. Full schema: https://coderifts.com/schemas/decision-result.v1.consumer.json (producer: https://coderifts.com/schemas/decision-result.v1.producer.json).', 'additionalProperties': True}, 'pattern_sources': {'type': 'array'}, 'breaking_changes': {'type': 'integer', 'minimum': 0}, 'control_envelope': {'type': 'object', 'description': 'Control envelope (control/1.0) derived from the stored decision_result. Includes next_agent_step (structured remediation SUGGESTION for non-CONTINUE execution_action; null on CONTINUE*; not permission — still branch on execution_action).'}, 'evidence_quality': {'type': 'string'}, 'execution_action': {'enum': ['CONTINUE', 'CONTINUE_WITH_MONITORING', 'REQUEST_APPROVAL', 'STOP'], 'type': 'string'}, 'coderifts_version': {'type': 'string'}, 'requires_migration': {'type': 'boolean'}, 'verdict_fingerprint': {'type': 'string'}, 'required_action_core': {'type': 'object', 'description': 'Branchable required-action core { type, reason_code, recheck_required } when present on the envelope.'}, 'decision_spec_version': {'type': 'string'}, 'decision_semantic_hash': {'type': 'string'}}, 'description': 'A stored CodeRifts decision: the original decision_result.v1 envelope + lookup meta. Retrieval-path control fields (safe_for_agent/execution_action/verdict_fingerprint/control_envelope) mirror the fresh preflight response and are present only when the stored envelope carries their source field. additionalProperties true: additive fields may appear and are not permission. Compatibility rule (single source): https://coderifts.com/schemas/decision-result.v1.consumer.json schema description.', 'additionalProperties': True}
preflight_change_set
Use this when: a contract artifact (OpenAPI, GraphQL, protobuf, AsyncAPI, MCP manifests, or agent tool schemas) changes before merge, deploy, publish, or tool registration; AND any agent-executed operation with no supported contract type — send type agent_operation. Do not call for documentation-only changes, static readiness scoring, or receipt verification. Use analyze for risk only; authorize requires context.operation. Skipping this call is not permission. Absence of a key is not permission. Inputs: preflight_mode is required: "analyze" (risk only; no receipt, no execution_action) or "authorize" (may mint a receipt; requires context.operation — merge is not deploy is not publish). Supply exactly one artifact source: artifacts[] (1–20 items, each {id, type, before, after} as the FULL spec/schema text, not a path or URL; type is openapi|graphql|grpc|asyncapi|mcp_manifest|agent_tools|agent_operation) XOR derivation="server" (server reads GitHub Compare; needs context.repository + context.base + context.head; sending artifacts[] together is 400). Grant fields sit in one object, execution_grant_request {include_execution_grant, grant_version, tenant_id, executor_id, adapter_id, target_uri, expected_state_token, state_nonce, audience, policy_hash}; analyze ignores it; required is preflight_mode only. previous_receipt is a chain token base64url(body).base64url(signature) to LINK a prior decision — it does not re-verify; use coderifts.verify_receipt instead; for details of a past decision use coderifts.get_decision_details instead. idempotency_key replays authorize only (24h), never analyze.
入力スキーマ
{'if': {'required': ['preflight_mode'], 'properties': {'preflight_mode': {'const': 'authorize'}}}, 'then': {'required': ['context'], 'properties': {'context': {'type': 'object', 'required': ['operation'], 'properties': {'operation': {'type': 'string', 'minLength': 1}}}}}, 'type': 'object', 'required': ['preflight_mode'], 'properties': {'context': {'type': 'object', 'properties': {'base': {'type': 'string', 'description': 'Base commit/ref SHA the change set was computed against (optional; PR/commit identity)'}, 'head': {'type': 'string', 'description': 'Head commit/ref SHA of the proposed change (optional; PR/commit identity)'}, 'branch': {'type': 'string', 'description': 'Branch name (optional; fingerprint context)'}, 'audience': {'type': 'string', 'description': 'Optional audience (IntentContext parity; REST/MCP accept, server-derived audience still wins on the envelope)'}, 'operation': {'type': 'string', 'description': 'Application operation for this change set (fingerprint + envelope). Server accepts any non-empty string; conventional values: merge, deploy, tool_call, publish. Merge is not deploy is not publish — the receipt/gate must match this label.'}, 'target_id': {'type': 'string', 'description': 'Optional apply-site target (IntentContext parity; not folded into the bundle fingerprint)'}, 'repository': {'type': 'string', 'description': 'Repository identity (optional; fingerprint context)'}, 'target_uri': {'type': 'string', 'description': 'Optional apply-site URI the cr.exec.v2 grant binds (handler fallback: input.target_uri, then context.target_uri, then repository/head-derived). Distinct from target_id.'}, 'environment': {'type': 'string', 'description': 'Target environment (e.g. production, staging, npm) — optional; folded into fingerprint when set.'}, 'fingerprint': {'type': 'string', 'description': 'Optional change fingerprint (IntentContext parity; not folded into the bundle fingerprint)'}, 'pull_request': {'oneOf': [{'type': 'string'}, {'type': 'number'}], 'description': 'Pull request id when applicable (optional; fingerprint context)'}, 'policy_profile': {'type': 'string', 'description': 'Policy profile name (optional; fingerprint context)'}}, 'description': 'Optional apply-site context folded into the bundle fingerprint. operation distinguishes merge vs deploy vs publish (and other labels); the server accepts any non-empty string; conventional values: merge, deploy, tool_call, publish. The receipt/gate must match this label.'}, 'artifacts': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'type', 'before', 'after'], 'properties': {'id': {'type': 'string', 'description': 'Caller-chosen id, unique within the bundle'}, 'type': {'enum': ['openapi', 'graphql', 'grpc', 'asyncapi', 'mcp_manifest', 'agent_tools', 'agent_operation'], 'type': 'string', 'description': 'Artifact kind. One of openapi, graphql, grpc, asyncapi, mcp_manifest, agent_tools, agent_operation. Contract types determine how before/after text is parsed. agent_operation: An opaque proposed agent operation for which no supported contract-artifact type applies. CodeRifts does not semantically analyze this content and does not issue an execution grant. Not inferred from the filename.'}, 'after': {'type': 'string', 'description': 'The proposed document as raw text, same kind as before. Must be the bytes you intend to merge/deploy/publish, not a diff.'}, 'before': {'type': 'string', 'description': 'The baseline document as raw text (the spec/schema/manifest body). Empty string means "no prior version" (create), not "load from disk".'}}}, 'maxItems': 20, 'minItems': 1, 'description': '1–20 contract documents analyzed together. Each item is {id, type, before, after} where before/after are the FULL document strings (YAML/JSON/proto text), not URLs or file paths. Omit this array entirely when derivation="server".'}, 'derivation': {'enum': ['server'], 'type': 'string', 'description': '"server" = the server derives artifacts[] from GitHub Compare via the App installation. Allowed only when context.repository, context.base and context.head are all present and the tenant has a proven binding for that repository. Do not send artifacts[] in the same call (400 — one source of truth). Omit this field for the caller-supplied artifacts[] path.'}, 'preflight_mode': {'enum': ['analyze', 'authorize'], 'type': 'string', 'description': 'REQUIRED. "analyze" = informational risk only (no decision/execution_action/safe_for_agent; analysis_outcome + may_execute:false). "authorize" = operation-bound path; may mint a receipt (requires context.operation). Decision Spec 2.0: omission is INVALID_INPUT. Do not pin 1.0 — that pin retired.'}, 'idempotency_key': {'type': 'string', 'description': 'Optional client key; in authorize mode, a repeat with the same key + body replays the original decision (24h). Analyze responses are not replayed.'}, 'response_detail': {'enum': ['control', 'standard', 'full'], 'type': 'string', 'description': 'How much of the response to return. control = the fields an agent branches on; standard = control + the human report and labelled break rows (the MCP default); full = everything (the REST default). Every value is copied from the full response.'}, 'previous_receipt': {'type': 'string', 'description': 'Optional prior chain token to LINK this call into a receipt chain: base64url(body).base64url(signature). Linking is not verification — a linked token is not re-checked here; use verify_receipt.'}, 'decision_spec_version': {'enum': ['2.0'], 'type': 'string', 'description': "Optional. Omit or '2.0' = current contract. '1.0' retired (INVALID_INPUT); do not pin 1.0."}, 'execution_grant_request': {'type': 'object', 'properties': {'audience': {'type': 'string', 'description': 'Requester identity for the decision envelope. Accepted here; the server-derived audience wins when both are present.'}, 'tenant_id': {'type': 'string', 'description': 'Authorize+grant v2 only. Tenant the grant is issued under. ASCII slug. When omitted the server uses "default" — pin it if you are not on the default tenant.'}, 'adapter_id': {'type': 'string', 'description': 'Authorize+grant v2 only. Adapter that will apply the change. Conventional values: fs, postgres, git. Must match the adapter the executor actually uses; a git grant does not authorize an fs write.'}, 'target_uri': {'type': 'string', 'description': 'Authorize+grant v2 only. URI the grant binds (example: git://owner/repo.git/refs/heads/main). Fallback if omitted: context.target_uri, then repository/head-derived. Distinct from context.target_id.'}, 'executor_id': {'type': 'string', 'description': 'Authorize+grant v2 only. Executor identity the grant is bound to (example: agent:ci-bot, host:github-actions). Empty/absent is not "any executor".'}, 'policy_hash': {'type': 'string', 'description': 'Authorize+grant v2 only. Policy identity bound into the grant, sha256: + 64 hex. When supplied, apply must use that same policy; a different policy is a different grant.'}, 'state_nonce': {'type': 'string', 'description': 'Authorize+grant only. Opaque nonce copied into the signed grant as its own field (not folded into scope_hash). Absent → BEARER grant. Ignored unless include_execution_grant is true.'}, 'grant_version': {'enum': ['v1', 'v2'], 'type': 'string', 'description': 'Grant envelope to mint when include_execution_grant is true. Omitting this yields cr.exec.v1 until 2026-09-18 and cr.exec.v2 on and after it (see x-coderifts-effective-default / x-coderifts-default-changes-at). The response meta.grant_version is the version actually issued. An explicit value always wins — pin "v1" to keep current behaviour with no code change on the date.', 'x-coderifts-effective-default': 'v2', 'x-coderifts-default-changes-at': '2026-09-18'}, 'expected_state_token': {'type': 'string', 'description': 'Authorize+grant v2 only. Compare-and-swap token the executor must observe at apply time (the "before" state). Signed as its own field. Omit only if the adapter has no prior state; do not send a placeholder.'}, 'include_execution_grant': {'type': 'boolean', 'description': 'Authorize only. When true on an allow-class authorize, the response includes a signed execution_grant, or HTTP 503 SIGNER_UNAVAILABLE — never an unsigned grant. Default false. Analyze ignores this flag. Ignored unless preflight_mode="authorize".'}}, 'description': 'Authorize + include_execution_grant only: the execution-grant request fields. Analyze ignores them. Flat root-level spellings are also accepted; the same field sent both ways with different values is INVALID_INPUT.'}}}
出力スキーマ
{'type': 'object', 'oneOf': [{'not': {'anyOf': [{'required': ['decision']}, {'required': ['execution_action']}, {'required': ['safe_for_agent']}, {'required': ['chain_receipt']}, {'required': ['execution_grant']}, {'required': ['decision_result']}, {'required': ['control_envelope']}, {'required': ['required_action_core']}]}, 'type': 'object', 'required': ['preflight_mode', 'analysis_outcome', 'authorization_effect', 'may_execute', 'receipt_kind', 'decision_spec_version'], 'properties': {'analysis': {'type': 'object', 'properties': {'stats': {'type': 'object', 'additionalProperties': True}, 'degraded': {'type': 'boolean'}, 'patterns': {'type': 'array'}, 'change_ir': {'type': 'array'}, 'changelog': {'type': 'array'}, 'risk_level': {'type': 'string'}, 'risk_score': {'type': 'integer'}, 'coverage_gap': {'type': 'object', 'additionalProperties': True}, 'pii_findings': {'type': 'array'}, 'remediations': {'type': 'array', 'items': {'type': 'object', 'properties': {'effort': {'type': 'string'}, 'target': {'type': 'string'}, 'evidence': {'type': 'object', 'additionalProperties': True}, 'target_ref': {'type': 'object', 'additionalProperties': True}, 'change_type': {'type': 'string'}, 'instruction': {'type': 'string', 'description': 'Imperative remediation text. Model-visible. Generated per input; not a closed vocabulary.'}, 'precise_label': {'type': 'string'}, 'recommended_transform': {'type': 'string'}}, 'description': 'One remediation for one detected breaking change. `instruction` is imperative prose that a model may read and act on; it is generated per input and is NOT a fixed string, so the schema declares that the field exists and does not pin its text.', 'additionalProperties': True}}, 'should_block': {'type': 'boolean'}, 'decision_basis': {'type': 'object', 'additionalProperties': True}, 'fallback_reason': {'type': 'string'}, 'pattern_sources': {'type': 'array'}, 'risk_dimensions': {'type': 'object', 'additionalProperties': True}, 'breaking_changes': {'type': 'integer'}, 'evidence_quality': {'type': 'string'}, 'detected_patterns': {'type': 'array'}, 'policy_violations': {'type': 'array'}, 'security_findings': {'type': 'array'}, 'semver_suggestion': {'type': 'string'}, 'token_cost_impact': {'type': 'object', 'additionalProperties': True}, 'requires_migration': {'type': 'boolean'}, 'coverage_gap_reason': {'type': 'string'}, 'non_breaking_changes': {'type': 'array'}, 'breaking_changes_details': {'type': 'array'}, 'compatibility_suggestions': {'type': 'array'}}, 'description': 'Tier-2 analysis mirror, assembled by the response builder alongside the control surface. Dual-write of the flat analysis fields present on the verdict, plus remediations[]. PROPERTIES ARE GENERATED — do not hand-edit them. OPEN BY DESIGN: additionalProperties stays TRUE and this is not an oversight. The fields above are copied conditionally, so which of them appear depends on the input — a verdict with no PII findings simply omits pii_findings. Closing this object would turn every future analysis field into a breaking change that fails inside the consumer, and would reject exactly the verdict paths that no one sampled when the union was built. Declared, not closed: you can now see what you may get, and you must still tolerate more.', 'additionalProperties': True}, 'evidence': {'type': 'array'}, 'patterns': {'type': 'array', 'items': {'type': 'string'}}, 'artifacts': {'type': 'array'}, 'operation': {}, 'timestamp': {'type': 'string'}, 'risk_score': {'type': 'integer', 'maximum': 100, 'minimum': 0}, 'may_execute': {'const': False, 'description': 'Analyze never grants execute permission.'}, 'blast_radius': {'type': 'object', 'required': ['endpoints', 'fields', 'params', 'consumers_declared', 'consumers_observed', 'graph_source'], 'properties': {'fields': {'type': 'integer', 'minimum': 0}, 'params': {'type': 'integer', 'minimum': 0}, 'endpoints': {'type': 'integer', 'minimum': 0}, 'graph_source': {'enum': ['none', 'declared', 'observed', 'declared+observed'], 'type': 'string'}, 'consumers_declared': {'type': 'integer', 'minimum': 0}, 'consumers_observed': {'type': 'integer', 'minimum': 0}}, 'description': 'Additive COUNTS (not a score). Pure function of the change-set + request graphs. Not in the verdict_fingerprint preimage.', 'additionalProperties': False}, 'human_report': {'type': 'object', 'properties': {'summary': {'type': 'string'}, 'suggestions': {'type': 'array'}, 'next_steps_prose': {'type': 'string'}, 'breaking_highlights': {'type': 'array'}}, 'description': 'Human-readable report tier, assembled by the response builder; analyze returns a reduced form. Measured keys: summary, breaking_highlights, suggestions, next_steps_prose.', 'additionalProperties': False}, 'receipt_kind': {'const': 'NONE', 'description': 'Analyze never mints a receipt.'}, 'decision_basis': {}, 'preflight_mode': {'const': 'analyze'}, 'scorer_version': {'type': ['string', 'null'], 'description': 'Fingerprint-bound scorerVersion() (observation; not permission).'}, 'pattern_sources': {'type': 'array'}, 'analysis_control': {'type': 'object'}, 'analysis_outcome': {'enum': ['NO_BREAK_DETECTED', 'BREAKS_DETECTED', 'ANALYSIS_FAILED', 'NOT_SUPPORTED'], 'type': 'string', 'description': 'Closed analysis outcome set derived from engine-visible state only. NOT_SUPPORTED = no analyzer (agent_operation / type outside the published enum). ANALYSIS_FAILED = an analyzer ran and failed.'}, 'breaking_changes': {'type': 'integer', 'minimum': 0}, 'evidence_quality': {'type': 'string'}, 'severity_summary': {'type': 'object', 'properties': {'note': {'type': 'string'}, 'diff_severity': {'type': 'string', 'description': 'Structural size of the schema change.'}, 'policy_effect': {'type': 'string', 'description': 'Resulting decision effect label.'}, 'governance_severity': {'type': 'string', 'description': 'How the rule engine rates the change.'}}, 'description': 'Bundle severity axes, computed once per change set. Distinct axes, not contradictory. Measured keys: diff_severity, governance_severity, policy_effect, note.', 'additionalProperties': False}, 'detected_patterns': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'severity', 'description', 'consequence', 'affected_path', 'affected_field'], 'properties': {'name': {'type': 'string', 'description': 'Governance pattern name; appears in patterns when both are carried.'}, 'side': {'enum': ['request', 'response'], 'type': 'string', 'description': 'Optional; currently set on ENUM_NARROWING only. Request-side narrowing is agent-breaking (threaded so safe_for_agent can distinguish it). Absent when the detector did not set it.'}, 'severity': {'type': 'string', 'description': 'Row severity from the pattern catalog (observed set: CRITICAL, HIGH, MEDIUM). NOT a closed control enum — branch on execution_action, never on this.'}, 'consequence': {'type': 'string', 'description': 'What breaks for a consumer if this ships. Untrusted free text.'}, 'description': {'type': 'string', 'description': 'What the detector matched. Untrusted free text.'}, 'affected_path': {'type': 'string', 'description': 'Contract path this row is about. Empty string when the detector had none — the key is always emitted.'}, 'affected_field': {'type': 'string', 'description': 'Field within affected_path. Empty string when the detector had none — the key is always emitted.'}}, 'additionalProperties': False}, 'description': 'GOVERNANCE detector detail rows, emitted by the pattern detectors and validated against the decision-spec field contract before they leave the server. Row shape measured live: name, severity, description, consequence, affected_path, affected_field; optional side (request|response) on ENUM_NARROWING. Names ⊆ patterns (not equality). Agent-detector names may appear only in patterns. Free-text fields are untrusted.'}, 'policy_pin_status': {'type': ['object', 'null'], 'additionalProperties': True}, 'bundle_fingerprint': {'type': 'string'}, 'requires_migration': {'type': 'boolean'}, 'calibration_version': {'type': ['string', 'null']}, 'verdict_fingerprint': {'type': 'string'}, 'authorization_effect': {'const': 'NONE', 'description': 'Analyze never authorizes; always NONE.'}, 'decision_spec_version': {'type': 'string', 'description': "Decision Spec major for this response (typically '2.0')."}, 'breaking_changes_details': {'type': 'array', 'items': {'type': 'object', 'properties': {'path': {'type': 'string'}, 'type': {'type': 'string', 'description': 'Change kind / IR type code (e.g. response.body.property.remove).'}, 'field': {'type': 'string'}, 'method': {'type': 'string'}, 'severity': {'type': 'string'}, 'description': {'type': 'string'}}, 'additionalProperties': True}, 'description': "Per-change IR/detail rows, mapped from the engine's change IR. Measured row keys: type, path, method, field, severity, description. Distinct from breaking_changes (integer count)."}}, 'description': 'ANALYZE mode (Decision Spec 2.0): informational only. MUST NOT contain decision, execution_action, safe_for_agent, chain_receipt, execution_grant, decision_result, control_envelope, or required_action_core. Branch on analysis_outcome; never treat as permission. Field set GENERATED from preflight-response.v2.producer.json (agent-facing allowlist).', 'additionalProperties': True}, {'type': 'object', 'allOf': [{'if': {'required': ['receipt_kind'], 'properties': {'receipt_kind': {'const': 'operation_authorization'}}}, 'then': {'required': ['chain_receipt']}}, {'if': {'required': ['execution_action'], 'properties': {'execution_action': {'enum': ['CONTINUE', 'CONTINUE_WITH_MONITORING']}}}, 'then': {'required': ['receipt_kind', 'chain_receipt', 'decision_result'], 'properties': {'receipt_kind': {'const': 'operation_authorization'}}}}], 'required': ['preflight_mode', 'decision', 'execution_action', 'safe_for_agent', 'receipt_kind', 'decision_spec_version'], 'properties': {'analysis': {'type': 'object', 'properties': {'stats': {'type': 'object', 'additionalProperties': True}, 'degraded': {'type': 'boolean'}, 'patterns': {'type': 'array'}, 'change_ir': {'type': 'array'}, 'changelog': {'type': 'array'}, 'risk_level': {'type': 'string'}, 'risk_score': {'type': 'integer'}, 'coverage_gap': {'type': 'object', 'additionalProperties': True}, 'pii_findings': {'type': 'array'}, 'remediations': {'type': 'array', 'items': {'type': 'object', 'properties': {'effort': {'type': 'string'}, 'target': {'type': 'string'}, 'evidence': {'type': 'object', 'additionalProperties': True}, 'target_ref': {'type': 'object', 'additionalProperties': True}, 'change_type': {'type': 'string'}, 'instruction': {'type': 'string'}, 'precise_label': {'type': 'string'}, 'recommended_transform': {'type': 'string'}}, 'additionalProperties': True}}, 'should_block': {'type': 'boolean'}, 'decision_basis': {'type': 'object', 'additionalProperties': True}, 'fallback_reason': {'type': 'string'}, 'pattern_sources': {'type': 'array'}, 'risk_dimensions': {'type': 'object', 'additionalProperties': True}, 'breaking_changes': {'type': 'integer'}, 'evidence_quality': {'type': 'string'}, 'detected_patterns': {'type': 'array'}, 'policy_violations': {'type': 'array'}, 'security_findings': {'type': 'array'}, 'semver_suggestion': {'type': 'string'}, 'token_cost_impact': {'type': 'object', 'additionalProperties': True}, 'requires_migration': {'type': 'boolean'}, 'coverage_gap_reason': {'type': 'string'}, 'non_breaking_changes': {'type': 'array'}, 'breaking_changes_details': {'type': 'array'}, 'compatibility_suggestions': {'type': 'array'}}, 'additionalProperties': True}, 'decision': {'enum': ['ALLOW', 'WARN', 'REQUIRE_APPROVAL', 'BLOCK'], 'type': 'string', 'description': 'Compatibility mirror of control_envelope.decision (same value). Prefer control_envelope for branching; use decision as explanation only.'}, 'evidence': {'type': 'array'}, 'patterns': {'type': 'array', 'items': {'type': 'string'}}, 'artifacts': {'type': 'array'}, 'operation': {}, 'timestamp': {'type': 'string'}, 'risk_score': {'type': 'integer', 'maximum': 100, 'minimum': 0}, 'blast_radius': {'type': 'object', 'required': ['endpoints', 'fields', 'params', 'consumers_declared', 'consumers_observed', 'graph_source'], 'properties': {'fields': {'type': 'integer', 'minimum': 0}, 'params': {'type': 'integer', 'minimum': 0}, 'endpoints': {'type': 'integer', 'minimum': 0}, 'graph_source': {'enum': ['none', 'declared', 'observed', 'declared+observed'], 'type': 'string'}, 'consumers_declared': {'type': 'integer', 'minimum': 0}, 'consumers_observed': {'type': 'integer', 'minimum': 0}}, 'additionalProperties': False}, 'chain_status': {'type': 'string'}, 'human_report': {'type': 'object', 'properties': {'summary': {'type': 'string'}, 'suggestions': {'type': 'array'}, 'next_steps_prose': {'type': 'string'}, 'breaking_highlights': {'type': 'array'}}, 'additionalProperties': False}, 'receipt_kind': {'enum': ['operation_authorization', 'NONE'], 'type': 'string', 'description': 'operation_authorization when a chain receipt was issued; NONE if signer unconfigured.'}, 'chain_receipt': {'type': 'string'}, 'decision_basis': {}, 'preflight_mode': {'const': 'authorize'}, 'safe_for_agent': {'type': 'boolean', 'description': 'Compatibility mirror of control_envelope.safe_for_agent (same value). Not a branch key — do not branch on safe_for_agent (use execution_action).'}, 'scorer_version': {'type': ['string', 'null'], 'description': 'Fingerprint-bound scorerVersion() (same as decision_result.scorer_version / FP preimage).'}, 'decision_result': {'type': 'object', 'properties': {'base': {'type': ['string', 'null']}, 'head': {'type': ['string', 'null']}, 'receipt': {'type': 'object'}, 'audience': {'type': ['string', 'null']}, 'decision': {'enum': ['ALLOW', 'WARN', 'REQUIRE_APPROVAL', 'BLOCK'], 'type': 'string'}, 'authority': {'type': ['object', 'null'], 'description': 'Additive. { audience, tenant_scope: bound|unbound, binding_proven_at? }. Informational — not permission, not a verify-receipt gate, not an ACL.'}, 'operation': {'type': ['string', 'null']}, 'derivation': {'type': ['object', 'null'], 'description': 'Additive. Present only when derivation:"server" produced this envelope. { source, platform?, base_sha, head_sha }. Covered by body_hash; not fingerprint.'}, 'expires_at': {'type': 'string'}, 'repository': {'type': ['string', 'null']}, 'decision_id': {'type': 'string'}, 'environment': {'type': ['string', 'null']}, 'fingerprint': {'type': 'string'}, 'blast_radius': {'type': 'object', 'properties': {'fields': {'type': 'integer', 'minimum': 0}, 'params': {'type': 'integer', 'minimum': 0}, 'endpoints': {'type': 'integer', 'minimum': 0}, 'graph_source': {'type': 'string'}, 'consumers_declared': {'type': 'integer', 'minimum': 0}, 'consumers_observed': {'type': 'integer', 'minimum': 0}}, 'description': 'Additive COUNTS (not a score). Not permission.'}, 'spec_version': {'type': 'string', 'pattern': '^decision-result\\.v1(\\.[0-9]+)?$'}, 'safe_for_agent': {'type': 'boolean'}, 'execution_action': {'enum': ['CONTINUE', 'CONTINUE_WITH_MONITORING', 'REQUEST_APPROVAL', 'STOP'], 'type': 'string'}, 'input_fingerprint': {'type': 'string'}, 'decision_body_hash': {'type': ['string', 'null']}}, 'description': 'decision-result.v1 envelope (control enums closed). Additive fields may appear and are not permission. Full schema: https://coderifts.com/schemas/decision-result.v1.consumer.json (producer: https://coderifts.com/schemas/decision-result.v1.producer.json).', 'additionalProperties': True}, 'execution_grant': {'type': 'string', 'description': 'Opt-in cr.exec.v1 execution grant (PHASE-0). Issued only when include_execution_grant is true on authorize. Short-lived mutation-bound sibling of chain_receipt; never unsigned. Optional inner state_nonce (ATOMIC profile) is additive and is NOT in scope_hash.'}, 'pattern_sources': {'type': 'array'}, 'breaking_changes': {'type': 'integer', 'minimum': 0}, 'control_envelope': {'type': 'object', 'description': 'Branch source (control/1.0). Machine-control surface from attachControlSurface / buildControlEnvelope. Agents and @coderifts/agent-guard branch on control_envelope.execution_action. Top-level decision/safe_for_agent/execution_action mirror these values for compatibility. Includes next_agent_step (structured remediation SUGGESTION derived from execution_action + required_action; null on CONTINUE*; not permission — still branch on execution_action).'}, 'evidence_quality': {'type': 'string'}, 'execution_action': {'enum': ['CONTINUE', 'CONTINUE_WITH_MONITORING', 'REQUEST_APPROVAL', 'STOP'], 'type': 'string', 'description': 'Compatibility mirror of control_envelope.execution_action (same value). Canonical branch key; unrecognised values are not permission (fail closed).'}, 'severity_summary': {'type': 'object', 'properties': {'note': {'type': 'string'}, 'diff_severity': {'type': 'string'}, 'policy_effect': {'type': 'string'}, 'governance_severity': {'type': 'string'}}, 'additionalProperties': False}, 'coderifts_version': {'type': 'string'}, 'detected_patterns': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'severity', 'description', 'consequence', 'affected_path', 'affected_field'], 'properties': {'name': {'type': 'string'}, 'side': {'enum': ['request', 'response'], 'type': 'string'}, 'severity': {'type': 'string'}, 'consequence': {'type': 'string'}, 'description': {'type': 'string'}, 'affected_path': {'type': 'string'}, 'affected_field': {'type': 'string'}}, 'additionalProperties': False}}, 'policy_pin_status': {'type': ['object', 'null'], 'description': 'policy_pin observation (898). match null=no pin; false=drift warning (non-blocking).', 'additionalProperties': True}, 'bundle_fingerprint': {'type': 'string'}, 'requires_migration': {'type': 'boolean'}, 'calibration_version': {'type': ['string', 'null'], 'description': 'Calibration model version when set; null until a calibrated model ships.'}, 'verdict_fingerprint': {'type': 'string'}, 'decision_spec_version': {'type': 'string'}, 'breaking_changes_details': {'type': 'array', 'items': {'type': 'object', 'properties': {'path': {'type': 'string'}, 'type': {'type': 'string'}, 'field': {'type': 'string'}, 'method': {'type': 'string'}, 'severity': {'type': 'string'}, 'description': {'type': 'string'}}, 'additionalProperties': True}}}, 'description': 'AUTHORIZE mode: operation-bound decision. Branch on execution_action (not decision, not safe_for_agent). Field set GENERATED from preflight-response.v2.producer.json (agent-facing allowlist). Compatibility: https://coderifts.com/schemas/decision-result.v1.consumer.json', 'additionalProperties': True}]}
verify_receipt
Verify a CodeRifts signed chain-receipt you ALREADY HOLD: cryptographic authenticity (signature + key id), body binding, and — when lifecycle indices are available — whether it is currently valid authorization (not expired, superseded, or revoked) for a stated operation/target. Use this when: - You already obtained a chain_receipt / receipt token from a prior preflight (or CI artifact) and are about to act (merge/deploy) under that receipt. - A contract-gate or policy requires offline/online proof that the receipt is authentic for this change before proceeding. - You must distinguish "signature ok" from "currently authorized" (stale or superseded receipts must not be treated as live approval). Do not use when: - You do not have a receipt yet — call coderifts.preflight_change_set first. - You need a NEW decision for a changed base→head set — preflight again; verify_receipt does not re-diff specs. - The receipt you hold binds a different operation or target than the one you are about to perform — call coderifts.preflight_change_set with context.operation set to that operation (a merge receipt does not authorize a deploy); verify_receipt cannot re-scope or re-issue a decision. - You only need human-readable history of an old decision_id without a receipt token — use coderifts.get_decision_details. - The change set itself is unknown or incomplete — fix the change set and preflight; do not "verify" a placeholder. Inputs: receipt token (required); target_id = decision_result.artifact_digest — required for an authorization verdict; omitted → target_not_stated. Optional intended context (operation, environment, fingerprint, audience, repository/branch/pull_request, base/head) and the body_hash-bound decision_result envelope. 30s clock-skew leeway on expiry. A 0s grace for declared destructive production operations is defined in the policy but is unreachable today: the intended-context schema has no destructive field, so nothing can declare one and the 30s leeway always applies. Returns { valid, status, currently_authorized (bool|null), reason, payload, authz_* }. Branch on currently_authorized; null = not evaluated. When a decision envelope is also in hand (e.g. from a prior preflight), its control_envelope.next_agent_step (if present) is structured remediation guidance the agent MAY follow after a non-CONTINUE decision — still branch on execution_action; next_agent_step is suggestion, not permission.
読み取り専用
入力スキーマ
{'type': 'object', 'required': ['token'], 'properties': {'base': {'type': 'string', 'description': 'Intended base commit/ref SHA the receipt must match (signed-wins vs envelope.base)'}, 'head': {'type': 'string', 'description': 'Intended head commit/ref SHA the receipt must match (signed-wins vs envelope.head)'}, 'token': {'type': 'string', 'description': 'The chain receipt token (base64url(body).base64url(signature))'}, 'branch': {'type': 'string', 'description': 'Intended branch the receipt must bind (place binding; optional)'}, 'audience': {'type': 'string', 'description': 'Intended audience — must match the receipt'}, 'operation': {'type': 'string', 'description': 'Intended operation the receipt must authorize (conventional: merge|deploy|tool_call|publish). Triggers authorization evaluation when non-empty; supply decision_result for full scope binding.'}, 'target_id': {'type': 'string', 'description': 'REQUIRED to authorize under a held receipt. Set it to decision_result.artifact_digest — the digest of the artifact the receipt was issued for, which you already hold in the decision_result you are passing. The server does NOT derive it for you: it carries YOUR intended apply-site, and taking it from the envelope would compare that document against itself. Omit it and the answer is currently_authorized false with authz_reason target_not_stated and authz_status VERIFIED_TARGET_NOT_STATED — a missing input, distinct from target_mismatch, which means the receipt covers a different target.'}, 'repository': {'type': 'string', 'description': 'Intended repository the receipt must bind (place binding; optional)'}, 'environment': {'type': 'string', 'description': 'Intended environment (e.g. production) — must match the receipt'}, 'fingerprint': {'type': 'string', 'description': 'Intended change fingerprint — must equal the receipt fp'}, 'pull_request': {'oneOf': [{'type': 'string'}, {'type': 'number'}], 'description': 'Intended pull-request id the receipt must bind (place binding; optional)'}, 'decision_result': {'type': 'object', 'properties': {'base': {'type': ['string', 'null']}, 'head': {'type': ['string', 'null']}, 'receipt': {'type': 'object'}, 'audience': {'type': ['string', 'null']}, 'decision': {'enum': ['ALLOW', 'WARN', 'REQUIRE_APPROVAL', 'BLOCK'], 'type': 'string'}, 'authority': {'type': ['object', 'null'], 'description': 'Additive. { audience, tenant_scope: bound|unbound, binding_proven_at? }. Informational — not permission, not a verify-receipt gate, not an ACL.'}, 'operation': {'type': ['string', 'null']}, 'derivation': {'type': ['object', 'null'], 'description': 'Additive. Present only when derivation:"server" produced this envelope. { source, platform?, base_sha, head_sha }. Covered by body_hash; not fingerprint.'}, 'expires_at': {'type': 'string'}, 'repository': {'type': ['string', 'null']}, 'decision_id': {'type': 'string'}, 'environment': {'type': ['string', 'null']}, 'fingerprint': {'type': 'string'}, 'blast_radius': {'type': 'object', 'properties': {'fields': {'type': 'integer', 'minimum': 0}, 'params': {'type': 'integer', 'minimum': 0}, 'endpoints': {'type': 'integer', 'minimum': 0}, 'graph_source': {'type': 'string'}, 'consumers_declared': {'type': 'integer', 'minimum': 0}, 'consumers_observed': {'type': 'integer', 'minimum': 0}}, 'description': 'Additive COUNTS (not a score). Not permission.'}, 'spec_version': {'type': 'string', 'pattern': '^decision-result\\.v1(\\.[0-9]+)?$'}, 'safe_for_agent': {'type': 'boolean'}, 'execution_action': {'enum': ['CONTINUE', 'CONTINUE_WITH_MONITORING', 'REQUEST_APPROVAL', 'STOP'], 'type': 'string'}, 'input_fingerprint': {'type': 'string'}, 'decision_body_hash': {'type': ['string', 'null']}}, 'description': 'The body_hash-bound decision envelope (carries operation/target/decision). Required for a meaningful AUTHORIZATION evaluation of scope; without it, intended context alone fails closed on authorization (currently_authorized false) while signature status remains independent. Full schema: https://coderifts.com/schemas/decision-result.v1.consumer.json.', 'additionalProperties': True}}, 'description': 'Two evaluation modes (schema-documented; no mode discriminator field). SIGNATURE: supply token only — signature + expiry; currently_authorized is null. AUTHORIZATION: also supply intended context (operation, environment, fingerprint, target_id set to decision_result.artifact_digest, audience, repository/branch/pull_request, and/or base/head) AND the body_hash-bound decision_result envelope so currently_authorized / authz_status / authz_reason can be evaluated. Token alone is always accepted; omitting the envelope when context fields are present yields a signature verdict plus fail-closed authorization (currently_authorized false), not a schema reject.'}
出力スキーマ
{'type': 'object', 'required': ['valid', 'status', 'currently_authorized'], 'properties': {'valid': {'type': 'boolean', 'description': 'true iff status is VERIFIED_CURRENT or RETIRED_KEY_VALID_AT_ISSUE'}, 'reason': {'type': ['string', 'null']}, 'status': {'enum': ['VERIFIED_CURRENT', 'VERIFIED_EXPIRED', 'VERIFIED_WRONG_AUDIENCE', 'VERIFIED_WRONG_ENVIRONMENT', 'VERIFIED_SUPERSEDED', 'VERIFIED_SCOPE_MISMATCH', 'VERIFIED_UNBOUND_OPERATION', 'VERIFIED_UNBOUND_TARGET', 'VERIFIED_UNBOUND_REPOSITORY', 'VERIFIED_UNBOUND_BRANCH', 'VERIFIED_UNBOUND_PULL_REQUEST', 'VERIFIED_TARGET_NOT_STATED', 'UNKNOWN_KEY', 'UNKNOWN_KEY_STATUS', 'RETIRED_KEY_VALID_AT_ISSUE', 'KEY_RETIRED_AFTER_SIGNING', 'REVOKED_KEY', 'REVOKED_KEY_UNDECIDABLE', 'KEY_REVOKED', 'REVOCATION_UNDECIDABLE', 'AUTHORIZATION_UNDECIDABLE', 'INVALID_SIGNATURE', 'MALFORMED', 'UNSUPPORTED_VERSION', 'REGISTRY_UNREACHABLE'], 'type': 'string'}, 'payload': {'type': 'object'}, 'authz_note': {'type': 'string', 'description': 'Present when no intended context supplied: status reflects signature+expiry only'}, 'authz_state': {'type': 'string', 'description': 'Lifecycle state from isCurrentlyAuthorized when authorization is evaluated (optional; omitted when currently_authorized is null)'}, 'authz_reason': {'type': 'string', 'description': 'When currently_authorized=false: the deny reason (operation_mismatch, decision_not_allow, superseded, expired, target_mismatch, environment_mismatch, …)'}, 'authz_status': {'type': 'string', 'description': 'Authorization-level status (VERIFIED_WRONG_ENVIRONMENT / VERIFIED_SUPERSEDED / VERIFIED_SCOPE_MISMATCH / …)'}, 'caller_value': {'type': ['string', 'null'], 'description': 'Caller claim that differed from the signed envelope'}, 'signed_value': {'type': ['string', 'null'], 'description': 'Signed envelope slot when signed-wins fail-closed (source_binding_mismatch)'}, 'authz_reasons': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Every violation found; the first is authz_reason. [] when authorized. Fix all of them before re-verifying.'}, 'binding_level': {'type': 'string', 'description': 'place_and_content | content_only — forensic, not a second verdict'}, 'correlation_id': {'type': 'string', 'description': 'Route-owned trace id, set by the route itself rather than by correlation middleware; always a non-empty string on 200'}, 'currently_authorized': {'type': ['boolean', 'null'], 'description': 'Whether the receipt currently authorizes the intended operation/target/fp (§106). null means authorization could not be evaluated (e.g. no intended context) — not unauthorized and not authorized.'}}, 'description': 'Receipt signature/status plus optional authorization layer. additionalProperties true: additive fields may appear and are not permission. Envelope compatibility when a decision_result is supplied: https://coderifts.com/schemas/decision-result.v1.consumer.json schema description (single source).', 'additionalProperties': True}
変更
verify_receipt
2026年9月29日2:51
変更
preflight_change_set
2026年9月29日2:51
変更
verify_receipt
2026年9月27日2:44
変更
preflight_change_set
2026年9月27日2:44
変更
get_decision_details
2026年9月23日2:42
変更
preflight_change_set
2026年9月21日2:50
変更
preflight_change_set
2026年9月19日2:41
追加
get_decision_details
2026年9月17日12:41
追加
verify_receipt
2026年9月17日12:41
追加
preflight_change_set
2026年9月17日12:41

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…