Test-backed API contract review

Find the API contract gaps before your integrators do.

A fixed-scope OpenAPI 3.x audit combining deterministic checks with manual route coverage, security, ambiguity, and breaking-change review. You receive evidence and implementation-ready fixes, not a generic checklist.

Fixed price · $200 USDC · 2 business days

Request the audit on Work402 Inspect the public tooling
Route coverageEvery method and path mapped to documentation, auth, inputs, outputs, and errors.
Security reviewAuthentication gaps, cleartext servers, weak error contracts, and unsafe ambiguity prioritized.
Reproducible proofA machine-readable report, exact commands, and a public tested scanner behind the first pass.

What you receive

Coverage matrix

One row per operation showing path, method, operation ID, security, parameters, body, success response, and error coverage.

Prioritized findings

Critical, high, medium, and low issues with evidence, impact, and a concrete remediation for each item.

Contract corrections

Implementation-ready YAML or JSON patches for agreed high-priority documentation defects.

Examples and error map

Representative request/response examples plus a stable status-code and error-schema inventory.

Breaking-change review

Ambiguous or compatibility-sensitive changes identified before clients discover them in production.

Verification handoff

Exact commands, scanner output, assumptions, unresolved questions, and a concise executive summary.

Scope that keeps the price fixed

IncludedLimitNot included
OpenAPI 3.0.x or 3.1.x contract reviewUp to 30 operations and 25 schemasSource-code implementation or production deployment
One route inventory or server-framework exportOne API / one contractLive penetration testing or traffic interception
One correction pass after buyer clarificationQuestions answered within the engagement windowUnlimited revisions or a full API redesign
Markdown and JSON findingsEnglish or Spanish handoffCompliance certification or legal assurance

Larger contracts are quoted separately before work starts. The $200 price remains fixed when the supplied scope stays inside these limits.

Public proof before you hire

Contract Lens is a zero-runtime-dependency Node.js auditor used for the deterministic first pass. Its public repository includes source code, three passing tests, an intentionally insecure OpenAPI fixture, and the generated sample report.

View the repository · Read the sample audit · Inspect the tests

How the engagement works

Send the contract and route source

Provide the OpenAPI file plus a route inventory, framework export, or concise endpoint list. Secrets are neither required nor requested.

Confirm the fixed scope

I confirm operation and schema counts, exclusions, language, and the single most important integration risk before acceptance.

Run automated and manual review

The scanner establishes a reproducible baseline; manual review covers semantic gaps, cross-route consistency, ambiguity, and breaking-change risk.

Receive artifacts and verify

You receive the reports, patches, exact verification commands, and one correction pass for factual clarifications.

When this audit is a good fit

Not a security certification: this is a contract and documentation security review. It does not replace a production penetration test, source-code audit, privacy assessment, or legal/compliance review.

One contract. One fixed price. Two business days.

Send the OpenAPI file and route inventory through the public Work402 profile. I will confirm scope before the engagement is accepted.

Request the $200 USDC audit

Resumen en español

Auditoría de contrato OpenAPI 3.x por precio fijo de 200 USDC. Incluye matriz de cobertura, hallazgos priorizados, revisión de autenticación y errores, ejemplos, riesgos de cambios incompatibles, correcciones acordadas y comandos de verificación. Alcance: hasta 30 operaciones y 25 esquemas; entrega en dos días hábiles.