Finds the lines in an OpenAPI file that publish an endpoint with no authentication, an API key in th
91
Finds the lines in an OpenAPI file that publish an endpoint with no authentication, an API key in the query string, or an OAuth grant RFC 9700 forbids.
docker run --rm -v "$PWD":/work getreadystack/openapi-security-contract-lint /work/file
The same 18 rules as the VS Code extension, in a container. Mount a folder on /work.
--rules lists every ruledocker run --rm -e READYSTACK_LICENSE=<key> -v "$PWD":/work getreadystack/openapi-security-contract-lint --dir /work --ci
An application-security consultant reading the same contract by hand bills $150-$250 an hour
Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:
{ "mcpServers": { "openapi-security-contract-lint": { "command": "npx", "args": ["-y", "@readystack/openapi-security-contract-lint", "--mcp"] } } }
Tools: check_text and check_file (free) · check_dir (licence; the full sweep is free for 7 days). The agent gets every finding with the line number.
- name: OpenAPI Security Contract Lint
run: npx -y @readystack/openapi-security-contract-lint --dir . --ci
(container: docker run --rm -v "$PWD:/work" getreadystack/openapi-security-contract-lint --dir /work --ci)
Try the full run free for 7 days — no key needed. Then one licence, 7-day refund, no questions. Set READYSTACK_LICENSE=<key> or run --license <key> once.
Content type
Image
Digest
sha256:565c8a6f0…
Size
46.1 MB
Last updated
4 days ago
docker pull getreadystack/openapi-security-contract-lint