What you receive
Coverage matrix
One row per operation showing path, method, operation ID, security, parameters, body, success response, and error coverage.
Prioritized findings
Critical, high, medium, and low issues with evidence, impact, and a concrete remediation for each item.
Contract corrections
Implementation-ready YAML or JSON patches for agreed high-priority documentation defects.
Examples and error map
Representative request/response examples plus a stable status-code and error-schema inventory.
Breaking-change review
Ambiguous or compatibility-sensitive changes identified before clients discover them in production.
Verification handoff
Exact commands, scanner output, assumptions, unresolved questions, and a concise executive summary.
Scope that keeps the price fixed
| Included | Limit | Not included |
|---|---|---|
| OpenAPI 3.0.x or 3.1.x contract review | Up to 30 operations and 25 schemas | Source-code implementation or production deployment |
| One route inventory or server-framework export | One API / one contract | Live penetration testing or traffic interception |
| One correction pass after buyer clarification | Questions answered within the engagement window | Unlimited revisions or a full API redesign |
| Markdown and JSON findings | English or Spanish handoff | Compliance certification or legal assurance |
Larger contracts are quoted separately before work starts. The $200 price remains fixed when the supplied scope stays inside these limits.
Public proof before you hire
Contract Lens is a zero-runtime-dependency Node.js auditor used for the deterministic first pass. Its public repository includes source code, three passing tests, an intentionally insecure OpenAPI fixture, and the generated sample report.
View the repository · Read the sample audit · Inspect the tests
How the engagement works
Send the contract and route source
Provide the OpenAPI file plus a route inventory, framework export, or concise endpoint list. Secrets are neither required nor requested.
Confirm the fixed scope
I confirm operation and schema counts, exclusions, language, and the single most important integration risk before acceptance.
Run automated and manual review
The scanner establishes a reproducible baseline; manual review covers semantic gaps, cross-route consistency, ambiguity, and breaking-change risk.
Receive artifacts and verify
You receive the reports, patches, exact verification commands, and one correction pass for factual clarifications.
When this audit is a good fit
- You are about to onboard an external integrator, publish an SDK, or open an API to customers.
- Your routes work, but the OpenAPI contract is incomplete, inconsistent, or maintained manually.
- You need a bounded, auditable deliverable rather than an open-ended consulting engagement.
- You want a Spanish or English handoff with concrete patches and reproducible evidence.
One contract. One fixed price. Two business days.
Send the OpenAPI file and route inventory through the public Work402 profile. I will confirm scope before the engagement is accepted.
Request the $200 USDC auditResumen en español
Auditoría de contrato OpenAPI 3.x por precio fijo de 200 USDC. Incluye matriz de cobertura, hallazgos priorizados, revisión de autenticación y errores, ejemplos, riesgos de cambios incompatibles, correcciones acordadas y comandos de verificación. Alcance: hasta 30 operaciones y 25 esquemas; entrega en dos días hábiles.