CodeRifts provides contract-change authorization and governance for AI agents and API teams. Its diff engine checks OpenAPI 3.0 and 3.1 schemas for breaking changes such as removed endpoints, newly required fields, response-type changes, authentication changes, and parameter modifications. It can find matching OpenAPI specifications in .yaml, .yml, and .json repository files. Security analysis flags weakened authentication, and schema scans flag newly added or changed fields such as SSNs, credit-card numbers, and passports with GDPR/CCPA warnings. Teams can define YAML policies in .coderifts.yml to block merges over limits, deprecation requirements, or authentication requirements. Documented options include a GitHub App, GitHub Actions, GitLab CI, Bitbucket Pipelines, REST API, CLI, and an MCP server with three tools. Specifications are processed in memory and discarded after analysis; derived verdicts and metadata are retained rather than schema bodies or source code. The Free plan is 0.00 USD per free and includes 1,000 authorization cases/month. Team is 149.00 USD per month, billed free during beta.
Who it is for
CodeRifts suits API teams and organizations using AI agents that need policy checks before contract changes are merged. It is relevant to teams working with OpenAPI 3.0 or 3.1 schemas and repository-based CI workflows.
What is good
- Checks OpenAPI 3.0 and 3.1 for breaking changes.
- Policies can block merges.
- Flags weakened authentication and potential PII fields.
- Offers GitHub, GitLab CI, Bitbucket Pipelines, REST API, and CLI.
- Processes schemas in memory and discards them after analysis.
What to know first
- No formal SLA is in place yet.
- No SOC 2 report or third-party assessment is published.
- Public beta support has no promised response time.
- API requests are rate-limited.
Verdict
CodeRifts focuses on authorization and governance for OpenAPI contract changes, with policy enforcement and several CI options. The free tier includes 1,000 authorization cases/month; paid plan terms vary, including Team being billed free during beta.
Get started with CodeRifts
- Open the CodeRifts website.
- Choose the Free plan or a paid plan based on the required authorization boundary and case volume.
- Connect a documented CI integration or use the REST API or CLI.
- Add matching OpenAPI .yaml, .yml, or .json specifications to the repository.
- Define applicable YAML policy rules in .coderifts.yml.
What the free plan stops at
The Free plan includes 1,000 authorization cases per month. Team provides 10,000 cases per month and lists a $15 per 1,000 overage, prorated; it is billed free during beta. Enterprise uses volume-commitment authorization cases.
Questions about CodeRifts
Does CodeRifts have a free plan?
Yes. The Free plan costs 0.00 USD per free and includes 1,000 authorization cases per month; verification is always free.
What do the paid plans cost?
Team is 149.00 USD per month, billed free during beta. Enterprise is 1500.00 USD per month.
Which API formats does it govern?
It governs OpenAPI 3.0 and OpenAPI 3.1 schemas.
Which integrations are documented?
Options include the GitHub App, GitHub Actions, GitLab CI, Bitbucket Pipelines, REST API, and CLI. An MCP server exposes three tools for preflighting changes, verifying receipts, and retrieving decision details.
What data does CodeRifts retain?
It says specifications are processed in memory and discarded after analysis. It retains derived verdicts and metadata rather than schema bodies or source code.
Does CodeRifts have an SLA?
It has no formal SLA yet and targets 99.9% uptime. Public beta support is available by email, with no promised response time.
CodeRifts plans and pricing
All plansCompared on API governance software
- Free plan
- Yes
- Style guide enforcement
- Yes
- API linting
- Yes
- Governed API formats
- OpenAPI 3.0, OpenAPI 3.1
- Lifecycle controls
- Yes
- Design review workflows
- Yes
- CI/CD integration
- Yes
- Access control level
- enterprise



