Contract-change authorization for AI agents. Signed receipts verify offline.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Only a granted change can proceed. Before a contract change merges, deploys or registers, CodeRifts decides whether it is authorized β and the check is red without a grant.
One grant binds three things: the authorization, its single use, and the target state the change moves to. The decision is signed, and the receipt verifies offline β you do not have to trust our database to check what was authorized.
Every decision also names what it does not prove.
https://app.coderifts.com/mcphttps://coderifts.com/mcp.json β the canonical published document. The mcp.json
at the root of this repository is a pointer to it, not a second copy.io.github.coderifts/api-governancehttps://coderifts.comhttps://github.com/coderifts/demo/pull/4GitHub Copilot reads the same server under three different root keys β servers in
.vscode/mcp.json, mcpServers in the cloud agent's MCP settings, and mcp-servers in a custom
agent's frontmatter β and npx coderifts copilot-setup writes all three (details below).
A key is needed only to authorize; get one at https://app.coderifts.com/api/signup.
Install the CodeRifts marketplace, then the api-governance plugin (MCP server + skill).
Requires CODERIFTS_API_KEY for tool calls.
Local checkout (after clone):
The plugin wires the hosted MCP at https://app.coderifts.com/mcp and the
api-governance skill. Tools exposed: preflight_change_set, verify_receipt,
get_decision_details only.
Cursor Plugin package (measured Cursor layout: .cursor-plugin/plugin.json +
skills/ + rules/ + mcp.json + hooks/hooks.json). Same hosted MCP and the
same three tools as the Claude plugin β no fourth tool. Deterministic /
signed / fail-closed β not an AI compatibility scan.
| Path | Role | Source of truth |
|---|---|---|
plugins/api-governance-cursor/.cursor-plugin/plugin.json | Cursor Plugin manifest | cursor/plugins plugin.schema.json |
plugins/api-governance-cursor/skills/coderifts-api-governance/SKILL.md | Skill | Website .well-known/agent-skills/coderifts-api-governance/SKILL.md |
plugins/api-governance-cursor/rules/coderifts.mdc | Cursor rule | Generated β generate-agent-host-files.js |
plugins/api-governance-cursor/mcp.json | Streamable HTTP MCP wiring | Same endpoint as Claude .mcp.json (not the website tool-card) |
plugins/api-governance-cursor/hooks/hooks.json | PreToolUse adapter | Existing CLI coderifts claude-hook (ID912) |
.cursor-plugin/marketplace.json | Cursor marketplace entry | Cursor marketplace.schema.json |
Validate:
The generated-rule check is LIVE when CODERIFTS_APP_ROOT (default ~/coderifts-app)
has generated/agent-host/.cursor/rules/coderifts.mdc, and RECORDED against
fixtures/recorded/app-generator when it does not (weaker, named). A missing or
corrupt snapshot still exits 1 β no silent skip.
Codex plugin package (measured OpenAI Codex layout: .codex-plugin/plugin.json +
.mcp.json + skills/ + AGENTS.md). Same hosted MCP and the same three tools
as the Claude plugin β no fourth tool.
| Path | Role | Source of truth |
|---|---|---|
plugins/api-governance-openai/.codex-plugin/plugin.json | Codex plugin manifest | Codex plugin-json-spec (scaffold skill) |
plugins/api-governance-openai/.mcp.json | Streamable HTTP MCP wiring | Same endpoint as Claude .mcp.json |
plugins/api-governance-openai/skills/api-governance/SKILL.md | Skill + tool list | Trigger wording from agent-setup rule; tool names/descriptions from generated mcp.json |
plugins/api-governance-openai/AGENTS.md | Agent rules file | Generated β coderifts agent-setup / generate-agent-host-files.js |
plugins/api-governance-openai/openai-agent-instructions.md | OpenAI Agents SDK instructions | Generated β same generator |
plugins/api-governance-openai/docs/openai-production-pattern.md | Production pattern (ID108) β host dispatch loop with executeOpenAIToolCall | Hand-authored recipe on shipped @coderifts/agent-guard β₯ 6.4.0 (first npm release that exports executeOpenAIToolCall; current npm 17.3.3) |
plugins/api-governance-openai/scripts/smoke-execute-openai-tool-call.mjs | Offline smoke (ALLOW + BLOCK; no OpenAI key) | Real dispatcher + stub client |
.agents/plugins/marketplace.json | Codex marketplace entry | Codex marketplace schema |
OpenAIβs model only emits tool_call JSON; your app executes it. Wire governance at
that host loop β not as a Claude-style PreToolUse hook. Full steps + one canonical loop:
β plugins/api-governance-openai/docs/openai-production-pattern.md
β Still failing on the same one assertion, re-measured 2026-09-24: ALLOW factory ran β execute() did not run. The other eight assertions pass (4 ALLOW, 5 BLOCK), and the BLOCK side β the side that matters for a gate β is fully green: the factory does not run, the content is the gate denial with no fabricated success, and the decision identity is surfaced. The failing assertion is on the ALLOW path, where the dispatch wrapper returns the function result without having invoked the injected factory.
The 2026-09-14 version of this note ended "Investigation is in progress." That was dropped rather than re-dated: ten days on, it is a claim about activity that nothing here can verify, and a README that reports its own diligence is reporting the one thing a reader cannot check. What a reader can check is the assertion name and today's date.
Local checkout in Codex (team marketplace path):
Validate package consistency (manifest, tool parity, AGENTS.md empty-diff vs regeneration):
AGENTS.md regeneration is LIVE when ~/coderifts-app (or CODERIFTS_APP_ROOT) exists,
and RECORDED against fixtures/recorded/app-generator when it does not (weaker, named).
A missing or corrupt snapshot still exits 1. Directory listing / account submission steps are
not automated here.
Reference copies of the generated Copilot MCP configs + instructions (single source:
coderifts-app generators). Same hosted MCP and the same three tools β no fourth tool.
Primary install (living command β prefer this over copying from the kit):
Agent-host instructions (including .github/copilot-instructions.md) come from:
From the generated guide (copilot/docs/copilot-mcp.md β do not re-author this table):
| Surface | Config location | Root key | Auth |
|---|---|---|---|
| VS Code / Copilot Chat | .vscode/mcp.json | servers | ${input:coderifts_api_key} + inputs[] |
| Copilot cloud agent + code review | Repo Settings β Copilot β MCP servers (paste JSON) | mcpServers | Agents secret COPILOT_MCP_CODERIFTS_API_KEY in headers |
| Custom agent (org/enterprise) | Agent profile .md YAML frontmatter | mcp-servers | ${{ secrets.COPILOT_MCP_CODERIFTS_API_KEY }} |
Tools allowlisted everywhere: preflight_change_set, verify_receipt, get_decision_details.
copilot/)| Path | Role | Source of truth |
|---|---|---|
copilot/.vscode/mcp.json | VS Code / Copilot Chat | Generated β generate-copilot-mcp.js |
copilot/copilot-cloud-agent-mcp.json | Cloud agent paste JSON (mcpServers) | Generated β same |
copilot/copilot-custom-agent-mcp.frontmatter.md | Custom agent YAML frontmatter | Generated β same |
copilot/docs/copilot-mcp.md | Install guide + surfaces table | Generated β same |
copilot/.github/copilot-instructions.md | Copilot coding-agent instructions | Generated β generate-agent-host-files.js |
copilot/SOURCE.md | Provenance + re-sync commands | Packaging note (this repo) |
Validate empty-diff vs regeneration + 3-tool discipline:
Empty-diff vs regeneration is LIVE when CODERIFTS_APP_ROOT has the generators, and
RECORDED against fixtures/recorded/app-generator when it does not (weaker, named).
A missing or corrupt snapshot still exits 1. The kit is a communication / distribution
mirror β npx coderifts copilot-setup remains the install path.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/api-governance-2)<a href="https://allmcps.com/mcp/api-governance-2"><img src="https://allmcps.com/api/badge/api-governance-2?style=directory" alt="API Governance on AllMCPs" /></a>