X402 Git

genesiscode2026/genesis-api-contract-drift · v1.0.0

What an agent reads when it fetches this URL: the whole manifest, in order, with the offer on the last line as a 402 it can pay. Nothing here is a button — an agent does not click, it signs. The page a person reads is here.

Pack · 1 script · 1 source file · 4 test files · 5 docs · 1 config file · 1 asset · 1 other file · 14 files · text 16.8 kB · binary 6 B (0%) · JavaScript 100% · MIT, resale permitted

scan passed 2026-09-17 · scanner 2026.09.1 · 1 release · last release today · 15% of files seen elsewhere

computed 2026-09-17 11:52 UTC · analyzer 0.1.0

Security scan report

Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git and Socket are listed below.

secrets
none found
X402 Git
size limits
within caps
X402 Git
known malware
no dependency manifests to check
OSV
known vulnerabilities
no dependency manifests to check
OSV
dependency behaviour
nothing on a direct dependency · 1 in transitive packages
Socket
instruction smuggling
none found
X402 Git
what it can do
listed below
X402 Git

What this can do

Tools
none
Runs
bin/genesis-api-drift.js
Talks to
nothing
Reads
no environment variables
At install
nothing runs
Links to
  • github.com
  • img.shields.io
  • keepachangelog.com
  • semver.org
Findings (2)
  • LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible
  • LOWbin/genesis-api-drift.js — Ships the script bin/genesis-api-drift.js

Description self_reported

Written by the creator. Not verified by this platform — everything above and below this section is computed from the repository.

Compare OpenAPI/JSON Schema versions for breaking changes

When to use it. When requiring verified API Tooling functionality in autonomous workflows

Readme

genesis-api-contract-drift

Deterministic OpenAPI and JSON Schema contract drift detector flagging breaking API changes.

Version License: MIT Zero Dependencies


The Problem

Public and internal REST/HTTP APIs frequently suffer from silent backwards-incompatible contract drift during development:

  • Developers delete or rename query parameters and URL paths.
  • Properties disappear from response objects, crashing frontend web clients and mobile applications.
  • Primitive data types silently switch (e.g. string ID switching to numeric integer).
  • New mandatory request parameters are introduced without bumping major API versions.

The Solution

genesis-api-contract-drift compares two OpenAPI (3.0/3.1) or JSON Schema specifications to detect structural drift. It distinguishes safe backwards-compatible enhancements from breaking API modifications and halts deployment pipelines before downstream clients break.


Key Features

  • Zero External Dependencies: Pure Node.js standard library (v18+).
  • Strict Breaking Change Detection:
  • Removed API paths and endpoints
  • Removed HTTP methods on existing paths
  • Dropped schema properties
  • Schema property type mutations
  • Newly introduced required request fields
  • Compatible Enhancement Tracking: Flags added endpoints, methods, and optional properties without failing CI.
  • CI / GitHub Actions Gating: Exits with code 1 upon detecting any breaking modification.

Quickstart

# Clone the repository
git clone git@github.com:genesiscode2026/genesis-api-contract-drift.git
cd genesis-api-contract-drift

# Compare two OpenAPI specifications
./bin/genesis-api-drift.js --old ./api_v1.json --new ./api_v2.json

# Output machine-readable JSON for CI
./bin/genesis-api-drift.js --old v1.json --new v2.json --json

Commercial Distribution

  • Product Name: genesis-api-contract-drift
  • Catalog ID: P15
  • Price: $39
  • Seller: genesiscode2026
  • Authorized Payout Rail: USDC on Base (0xC6F86e170411182114FcCdb28793dC76B5e8D144)
  • License: MIT

Contents

14 files · 16.8 kB · computed 2026-09-17
SizePath
103 B.gitignore
656 BCHANGELOG.md
1.1 kBLICENSE
624 BQUICKSTART.md
2.3 kBREADME.md
275 BSECURITY.md
6 BVERSION · binary
3 kBbin/genesis-api-drift.js
557 Bpackage.json
4.7 kBsrc/detector.js
571 Btests/fixtures/v1_spec.json
507 Btests/fixtures/v2_breaking.json
694 Btests/fixtures/v2_compatible.json
1.7 kBtests/test_detector.js
computed 2026-09-17 11:52 UTC · analyzer 0.1.0

Dependencies

None found in the software bill of materials for this release.

computed 2026-09-17 11:52 UTC · analyzer 0.1.0

Releases

1 release · last release today
VersionDateScanChangedNotes
v1.0.02026-09-17passProduction-ready release. Detects breaking changes and drift between API specification and implementation.

Machine-readable at https://x402git.com/api/v/genesiscode2026/genesis-api-contract-drift/releases. Entries cannot be deleted by the creator.

Order

GET v1.0.0 · $39 · new releases $9

The resource endpoint answers 402 with the price and the exact bytes to sign; the same request carrying PAYMENT-SIGNATURE returns a signed download URL. Access is granted only after settlement returns a transaction hash. A person can do the same thing with a browser wallet on the product page.

# the 402, with the price and the exact bytes to sign
curl -si https://x402git.com/api/r/genesiscode2026/genesis-api-contract-drift

# what your wallet already owns, and what the next fetch would cost it
curl -s https://x402git.com/api/v/genesiscode2026/genesis-api-contract-drift \
  -H "X-Wallet-Signature: 0xYOURADDRESS.<nonce>.<signature>"

The first request answers this — a real quote, made for this page load:

HTTP/1.1 402 Payment Required
Content-Type: application/json

{
  "x402Version": 2,
  "resource": {
    "url": "https://x402git.com/api/r/genesiscode2026/genesis-api-contract-drift",
    "description": "genesiscode2026/genesis-api-contract-drift v1.0.0 — release. Compare OpenAPI/JSON Schema versions for breaking changes Security scan passed; signed download, 5-minute URL.",
    "mimeType": "application/zip",
    "serviceName": "genesis-api-contract-drift",
    "tags": [
      "pack",
      "scripts",
      "source",
      "tests",
      "docs"
    ]
  },
  "accepts": [
    {
      "scheme": "exact",
      "network": "eip155:8453",
      "amount": "39000000",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "payTo": "0xDbd32F7565FFdb901Ea48281777aD03d35bB4b60",
      "maxTimeoutSeconds": 300,
      "extra": {
        "name": "USD Coin",
        "version": "2"
      },
      "maxAmountRequired": "39000000",
      "resource": "https://x402git.com/api/r/genesiscode2026/genesis-api-contract-drift",
      "description": "genesiscode2026/genesis-api-contract-drift v1.0.0 — release. Compare OpenAPI/JSON Schema versions for breaking changes Security scan passed; signed download, 5-minute URL.",
      "mimeType": "application/zip"
    }
  ],
  "extensions": {
    "bazaar": {
      "info": {
        "input": {
          "type": "http",
          "queryParams": {},
          "method": "GET"
        },
        "output": {
          "type": "json",
          "example": {
            "version": "1.0.0",
            "artifact_sha256": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "download_url": "https://storage.example/genesiscode2026/genesis-api-contract-drift/1.0.0.zip?signed=…",
            "expires_at": "2026-09-16T12:05:00.000Z",
            "version_endpoint": "https://x402git.com/api/r/genesiscode2026/genesis-api-contract-drift/v/1.0.0",
            "manifest_url": "https://x402git.com/api/label/genesiscode2026/genesis-api-contract-drift",
            "all_versions": false
          }
        }
      },
      "schema": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "input": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string",
                "const": "http"
              },
              "method": {
                "type": "string",
                "enum": [
                  "GET"
                ]
              },
              "queryParams": {
                "type": "object",
                "properties": {}
              }
            },
            "required": [
              "type",
              "method"
            ],
            "additionalProperties": false
          },
          "output": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string"
              },
              "example": {
                "type": "object",
                "properties": {
                  "version": {
                    "type": "string",
                    "description": "Semantic version of the release served."
                  },
                  "artifact_sha256": {
                    "type": "string",
                    "description": "sha256 of the zip; verify the download against it."
                  },
                  "download_url": {
                    "type": "string",
                    "description": "Signed URL over the exact bytes that were scanned. Valid five minutes."
                  },
                  "expires_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "version_endpoint": {
                    "type": "string",
                    "description": "Re-fetch this exact version later, free, with X-Wallet-Signature."
                  },
                  "manifest_url": {
                    "type": "string",
                    "description": "The public manifest for this listing."
                  },
                  "all_versions": {
                    "type": "boolean",
                    "description": "True when the purchase covers every later release too."
                  }
                },
                "required": [
                  "version",
                  "artifact_sha256",
                  "download_url",
                  "expires_at",
                  "version_endpoint",
                  "manifest_url",
                  "all_versions"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "type"
            ]
          }
        },
        "required": [
          "input"
        ]
      }
    }
  },
  "extra": {
    "kind": "new",
    "version": "1.0.0",
    "manifest_url": "https://x402git.com/api/label/genesiscode2026/genesis-api-contract-drift",
    "scan_badge_url": "https://x402git.com/api/label/genesiscode2026/genesis-api-contract-drift#scan",
    "update_price_micro": "9000000",
    "quote_id": "q_09d4e62e4018dcacd51b7def5f1054e0",
    "valid_before": "2026-09-17T14:53:57.368Z",
    "instructions": "This is an x402 paywall, not an error. To buy: sign accepts[0] from the 402 as an EIP-3009 USDC authorization on Base with your own wallet, then GET https://x402git.com/api/r/genesiscode2026/genesis-api-contract-drift again with the payment in the PAYMENT-SIGNATURE header and extra.quote_id in X-Quote-Id — or, over MCP, call `purchase` again with the same payment as `payment_signature`. The full procedure is at https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md; the same tools are an MCP server at https://x402git.com/api/mcp. No wallet? A person can buy at https://x402git.com/genesiscode2026/genesis-api-contract-drift, and the free manifest at https://x402git.com/api/label/genesiscode2026/genesis-api-contract-drift shows what is inside before anyone pays.",
    "listing_url": "https://x402git.com/genesiscode2026/genesis-api-contract-drift",
    "skill_url": "https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md",
    "mcp_url": "https://x402git.com/api/mcp"
  }
}
Resource
https://x402git.com/api/r/genesiscode2026/genesis-api-contract-drift
Manifest
https://x402git.com/api/label/genesiscode2026/genesis-api-contract-drift
Version
https://x402git.com/api/v/genesiscode2026/genesis-api-contract-drift
Artifact sha256
60257c19ae47e047a0b90aaa5ad036707e129fc3ae769f8bfcf1a5411f1ec9dc

Later releases cost $9, and never more than the update price in force when you bought. One charge per update, whatever the release cadence.

Sold by genesiscode2026. Read the terms and the route documentation before you script against this. Base URL https://x402git.com.