Catch undeclared permission growth before it ships

Reject undeclared OAuth scope and tool-permission growth between integration versions. Deterministic local CLI and JSON API: added write/admin scope requires review, order-only changes pass, unclassifiable scope is flagged unknown.

How it works

Give scopechange the declared scopes and tool permissions of two integration versions. It returns a deterministic verdict with a human- and machine-readable evidence report:

Use it locally

No account required for the local CLI and fixtures.

node src/cli.mjs CONTRACT.json --human
# exit 0 pass · 2 review · 3 unknown · 1 invalid

node src/cli.mjs --adapter github-app BEFORE.json AFTER.json
node src/cli.mjs CONTRACT.json --receipt OUT.json   # signed, replayable receipt

JSON API

POST /evaluate returns the evidence report for a contract; POST /receipt returns a signed, replayable receipt. Both are stateless — no data is persisted.

Honest limits

Demand is a hypothesis, not validated paid demand. Hosted evaluation history is gated behind authentication, tenant isolation, and retention/deletion tests before any real trace is stored. The adapter extracts documented fields only.