The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Delimit — API Governance for AI Coding Assistants listing page.
</> DelimitThe merge gate for AI-written code, with signed, replayable attestation.
Wrap any AI coding assistant (Claude Code, Codex, Cursor, Gemini CLI) with a governance chain that runs your gates, records what changed, and signs a replayable receipt for every merge.
Every wrapped run emits a local delimit.attestation.v1 bundle: repo head before/after, changed files, gate results, and an HMAC-SHA256 signature. Verify it offline with delimit seal-verify; hosted replay is not available yet. Advisory by default; flip to enforcing when you're ready.
delimit checkZero-config PR safety gate. No init, no setup, no account, no keys — run it on any repo and it applies deterministic checks (breaking API changes + leaked secrets) to your staged or modified files.
When a check finds a breaking change or a leaked secret, it prints the offending file and the issue and exits non-zero — so it drops straight into a pre-commit hook or CI step.
Common options:
--record writes a content-pinned record of the check to .delimit/records/check-<ts>.json (or a path you name). That record is the precursor to the signed, replayable Seal attestation — the same evidence shape, pinned to the exact content you checked.
Methodology · cal.com v2 worked example · Workflow guide · Website
Real, reproducible merge-gate runs against public API specs:
See the full index at delimit.ai/reports. For the schema and signing methodology behind every report, see delimit.ai/methodology/mcp-attestation.
The merge gate for AI-written code, end to end: lint a spec, see exactly what breaks, classify the bump, settle the hard calls with multiple models, and walk away with a signed, replayable attestation. Then keep the context that survives across sessions and models.
scan (delimit_scan) reports what Delimit can do for this repo. init (delimit_init) drops in the policy preset and merge-gate config. No account, no keys.
Lint the spec change (the gate). Baseline vs. proposed, with policy applied — one pass/fail verdict.
See exactly what breaks. Pure structural diff — added/removed/modified endpoints, schemas, params, no policy.
Classify the bump. Deterministic MAJOR/MINOR/PATCH/NONE — same input, same answer, every time.
Settle the hard calls. When the gate verdict is a judgment call, put it to multiple models and let them debate to consensus.
delimit setup gives the Codex MCP server a 30-minute tool timeout so a
multi-round panel can return its completed transcript instead of being detached
by the client while its models are still responding.
Capture the signed, replayable attestation. After a gate event (deploy / security / test / audit), record the evidence bundle and verify it any time.
Every receipt is offline-verifiable with npx delimit-cli seal-verify <receipt.json>. Hosted receipt replay is not available yet.
Decisions, constraints, and tasks persist across sessions and across AI assistants — switch from Claude Code to Codex, Cursor, or Gemini CLI without losing the thread.
Memory — persist and recall the why, not just the diff.
For semantic recall by meaning across sessions, the assistant calls delimit_memory_search (Pro) directly.
Ledger — one task list, shared across every assistant and session.
That's the loop: gate the change, sign the proof, keep the context. Run it once on a real spec and you've used the whole merge gate.
Beyond the merge gate, Delimit orchestrates multi-model deliberation and autonomous builds. delimit think dispatches a strategic question to Claude, Codex, Gemini, and Grok; delimit build activates a background daemon that executes ledger tasks through the gate chain. delimit vault manages local secrets (AES-256).
Works across any configuration, from a single model on a budget to a full panel.
No API keys. No account. No config files.
Protect my API — catch breaking changes before merge:
Watch for drift — detect spec changes without review:
Run PR copilot — governance gates on every pull request:
Gate every AI-assisted invocation. Ship the receipts.
delimit wrap — pipe claude -p, cursor, aider, codex, or any AI-assisted CLI through a signed governance gate. Snapshots the git diff before/after, runs lint + tests, HMAC-signs an att_* attestation, and writes the receipt locally for offline verification. Advisory by default; --enforce blocks CI on policy violations; --max-time <s> is a kill switch that tags the attestation as a liability_incident and prints a cross-model handoff command.delimit trust-page — renders a directory of attestations into a static HTML trust page + JSON Feed 1.1 feed. Single file, no framework, offline-renderable. Deploy anywhere.delimit ai-sbom — aggregates attestations into a CycloneDX 1.6 bill-of-materials with AI-specific fields (detected models per vendor, tool-call surface, policy gate counts). Pipe straight into procurement.wrap is agnostic to the producer. Same attestation schema whether the pipe upstream is Claude Code, Cursor, Aider, Codex, or Gemini CLI. Switch producers without losing the audit chain.The highest state of AI governance — earlier features still active.
delimit doctor -- 14 prescriptive diagnostics. Every failure prints the exact command to fix it. --ci for pipelines, --fix for auto-repair.delimit simulate -- policy dry-run. See what would be blocked before you commit. The terraform plan for API governance.delimit status -- visual terminal dashboard. Policy, specs, hooks, CI, MCP, models, memory, ledger, evidence, git branch. --watch for live refresh.delimit report -- governance report. --since 7d --format md|html|json. Audit-friendly output for PRs and compliance.remember. Cross-model trust, verified on every recall.Run your question through 4 AI models simultaneously. They debate each other until unanimous agreement.
3 free deliberations, then BYOK for unlimited. Works with Grok, Gemini, Claude, GPT-4o.
server.json version fields match the package version.delimit_soul_capture / delimit_revive work without any internal modules via the public session_continuity module; captured souls carry deterministic provenance (venture, transcript identity, capture key) for reliable resume across model switches. Existing soul files load unchanged.delimit think and delimit build commandsdelimit setup configures permissions for Claude Code, Codex, and Gemini CLIZero-config -- auto-detects your OpenAPI spec:
Or with full configuration:
That's it. Delimit auto-fetches the base branch spec, diffs it, and posts a PR comment with breaking changes, semver classification, migration guides, and governance gate results.
View on GitHub Marketplace | See a live demo (23 breaking changes)
Breaking Changes Detected
Change Path Severity endpoint_removed DELETE /pets/{petId}error type_changed /pets:GET:200[].id(string -> integer)warning enum_value_removed /pets:GET:200[].statuswarning Semver: MAJOR (1.0.0 -> 2.0.0)
Migration Guide: 3 steps to update your integration
Governance Gates
Gate Status Chain API Lint Pass/Fail lint -> semver -> gov_evaluate Policy Compliance Pass/Fail policy -> evidence_collect Security Audit Pass security_audit -> evidence_collect Deploy Readiness Ready/Blocked deploy_plan -> security_audit
You don't have to trust a large tool surface on day one. The safe on-ramp:
Phase 1 — read-only governance (free, no account). Start with the tools that
only read your repo and write reports: delimit_lint, delimit_diff,
delimit_semver, delimit_policy, delimit_explain, delimit_scan, and
delimit_seal_verify. If your MCP client supports per-tool allowlists, grant
exactly those. Nothing in this set executes, deploys, or posts anywhere.
Phase 2 — opt into side effects deliberately. Tools that write evidence
bundles, open PR comments, or run deploys (delimit_security_audit,
delimit_deploy_*, agent orchestration) are tier-gated; enable them once
phase 1 has earned its keep in your CI.
Pin the Action to a commit SHA. @v1 is a floating tag. For
supply-chain-sensitive pipelines, pin the exact commit and bump on review:
Keep BYOK keys out of plaintext config. If you bring your own model keys
for deliberation, store them with delimit_secret_store (encrypted vault,
access-logged via delimit_secret_access_log) rather than in dotfiles.
Our own releases ship under the same discipline: every release carries a
signed, replayable Seal receipt (see the latest
release assets —
verify with npx delimit-cli seal-verify <receipt.json>), plus SLSA
provenance on npm.
When installed into your AI coding assistant, Delimit provides tools across two tiers:
28 change types (17 breaking, 11 non-breaking) -- deterministic rules, not AI inference. Same input always produces the same result.
| # | Change Type | Example |
|---|---|---|
| 1 | endpoint_removed | DELETE /users/{id} removed entirely |
| 2 | method_removed | PATCH /orders no longer exists |
| 3 | required_param_added | New required header on GET /items |
| 4 | param_removed | sort query parameter removed |
| 5 | response_removed | 200 OK response dropped |
| 6 | required_field_added | Request body now requires tenant_id |
| 7 | field_removed | email dropped from response object |
| 8 | type_changed | id went from string to integer |
| 9 | format_changed | date-time changed to date |
| 10 | enum_value_removed | status: "pending" no longer valid |
| 11 | param_type_changed | Query param limit changed from integer to string |
| 12 | param_required_changed | filter param became required |
| 13 | response_type_changed | Response data changed from array to object |
| 14 | security_removed | OAuth2 security scheme removed |
| 15 | security_scope_removed | write:pets scope removed from OAuth2 |
| 16 | max_length_decreased | name maxLength reduced from 255 to 100 |
| 17 | min_length_increased | code minLength increased from 1 to 5 |
| # | Change Type | Example |
|---|---|---|
| 18 | endpoint_added | New POST /webhooks endpoint |
| 19 | method_added | PATCH /users/{id} method added |
| 20 | optional_param_added | Optional format query param added |
| 21 | response_added | 201 Created response added |
| 22 | optional_field_added | Optional nickname field added to response |
| 23 | enum_value_added | status: "archived" value added |
| 24 | description_changed | Updated description for /health endpoint |
| 25 | security_added | API key security scheme added |
| 26 | deprecated_added | GET /v1/users marked as deprecated |
| 27 | default_changed | Default value for page_size changed from 10 to 20 |
| 28 | field_requirement_relaxed | Required field nickname became optional (context-aware severity) |
Or write custom rules in .delimit/policies.yml:
How does this compare to Obsidian Mind?
Obsidian Mind is a great Obsidian vault template for Claude Code users who want persistent memory via markdown files. Delimit takes a different approach: it's an MCP server that works across Claude Code, Codex, Gemini CLI, and Cursor. Your memory, ledger, and governance travel with you when you switch models. Delimit also adds API governance (28-type breaking change detection), CI gates, git hooks, and policy enforcement that Obsidian Mind doesn't cover. Use Obsidian Mind if you're all-in on Claude + Obsidian. Use Delimit if you switch between models or need governance.
Does this work without Claude Code?
Yes. Delimit works with Claude Code, Codex (OpenAI), Gemini CLI (Google), and Cursor. The remember/recall commands work standalone with zero config. The MCP server integrates with any client that supports the Model Context Protocol.
Is this free?
The free tier includes API governance, persistent memory, zero-spec extraction, project scanning, and 3 multi-model deliberations. Pro ($10/mo) adds unlimited deliberation, security audit, test verification, deploy pipeline, and agent orchestration. Premium ($50-100/mo) adds priority support and team features. Enterprise is custom: see delimit.ai/pricing.
Short version: none by default. Nothing leaves your machine unless you explicitly configure it.
What's always local (source of truth):
~/.delimit/events/events-YYYY-MM-DD.jsonl — per-tool-call events (tool name, timestamp, status, model id, session id, trace id). No source code, no prompts, no responses.~/.delimit/ledger/ — your ledger items, work orders, deliberation transcripts.~/.delimit/attestations/ — delimit wrap output bundles.What's OPT-IN (requires you to provide your own Supabase project credentials):
gateway/ai/supabase_sync.py mirrors the local event + ledger + work-order + deliberation rows into a Supabase project you own so you can view them in app.delimit.ai. It only activates if you set SUPABASE_URL + SUPABASE_SERVICE_ROLE_KEY environment variables OR provide ~/.delimit/secrets/supabase.json with those credentials. No URL or key is hardcoded in the published package (verify with grep -r aqbdqxnhzqzswdxifksc $(npm root -g)/delimit-cli/ — zero hits).Kill switch:
Set DELIMIT_DISABLE_CLOUD_SYNC=1 in your environment to force all sync operations to no-op even if credentials are present. Local files continue to work normally.
Webhook notifications:
gateway/ai/notify.py emits governance events to a webhook endpoint only if you configure DELIMIT_WEBHOOK_URL explicitly. Unset by default.
If you spot another code path that could phone home without disclosure, file an issue. This section is maintained as ship-truth, not aspirational.
MIT License