ContractRift
Open source · self-hosted · AGPL-3.0

Know when your upstream APIs change — before your users do.

ContractRift continuously probes the REST APIs, LLM APIs and MCP tool servers your product depends on. It learns what their responses look like and alerts you when they go down or silently change: a removed field, a new type, a different model behind your alias, a tool that gained a required parameter. Your API keys never leave your servers.

ContractRift dashboard showing breaking drift, a model change and an outage

Uptime checks see “200 OK”. Your code sees a missing field.

Upstream providers change response formats, tighten validation and move model aliases without notice. Unit tests use frozen mocks; uptime monitors only check the status code. ContractRift watches the contract.

REST

Structural drift

Baseline learned from real responses. Removed or re-typed fields are breaking; new nulls are warnings; additions are info. No per-field assertions to write.

LLM

Model & output drift

OpenAI-compatible and Anthropic formats. Flags when the provider reports a different model and when output assertions (text, regex, JSON Schema) stop passing.

MCP

Tool drift

Supports the 2026-07-28 stateless protocol and older servers. Detects removed tools, new required parameters and failing tool calls.

Alerts

Incidents & drift inbox

Severity-ranked drift, accept or dismiss in one click, HMAC-signed webhooks and Slack with retries.

CI

Deploy gate

One command in your pipeline fails the deploy while a tagged dependency is down or has unreviewed breaking drift.

Security

Keys stay home

Self-hosted. Secrets encrypted with AES-256-GCM, write-only in the API, key rotation, SSRF protection, audit log.

Review changes like pull requests

Every deviation lands in the drift inbox with its path, before → after and severity. Intended change? Accept and the baseline updates. Noise? Dismiss that exact change set.

Drift inbox listing breaking and warning changes

Where it fits

Uptime monitors SaaS drift monitors ContractRift
Detects silent response changes hand-written checks yes yes, learned baseline
LLM + MCP aware no partly yes
Your API keys stay on your servers self-hosted options no yes
CI deploy gate no rarely yes
Open source some no AGPL-3.0 + commercial

Get started

Docker (embedded PostgreSQL, data in a volume):

docker run -d -p 3000:3000 -v contractrift:/data \
  -e ENCRYPTION_KEY=$(openssl rand -base64 32) \
  ghcr.io/ahmedgcompany-cyber/contractrift:latest

Docker Compose with PostgreSQL 17, or Node.js 22+: see the README.

One-click cloud (Render, ~$13/month with managed PostgreSQL):

Deploy to Render

CI gate:

CONTRACTRIFT_URL=https://cr.example.com \
CONTRACTRIFT_TOKEN=cr_… \
node scripts/contractrift-gate.mjs --tags payments