Updrift watches the APIs your product depends on. When a provider ships a change (documented or not), we find the lines in your repo that break and open a sandbox-tested pull request with the fix.
Dependabot updates your dependencies.
Updrift migrates your integrations.
$ npx updrift scan · read-only, about 90 seconds, no signup
Every OpenAPI shift that hits your webhooks and renewals shows up as an evidence-backed finding before customers feel it.
Renaming a field is easy. The changes that take payments down are semantic, and a lot of them never show up in a changelog. We read Stripe's OpenAPI, docs, SDKs, and deprecation headers, then spell out what each change does to your handlers.
APIs also change how they behave without bumping a version. Latency jumps. Webhooks arrive out of order. A field goes null for one region. Nothing lands in the changelog. Next up: watch how providers actually behave in the wild.
Watch, understand, map, migrate, replay, then PR. If the sandbox can't prove the fix, you get a written report instead of a guessed pull request. We do not guess with your payments code.
Same path as pnpm moat:demo
Skewed webhook signatures have to fail before the migration and pass after. Old-format traffic still has to pass. Only then do we set proved=true.
Fixture repo with real Stripe webhook usage
webhook_verification_changed shows up as silent breaking
Sandbox matrix: skewed signature fails before, passes after
Migration branch with tests. You review. You merge.
Stripe and GitHub are live. Razorpay and Notion are in beta. Everything else is on request. Every tile carries LIVE, BETA, or ON REQUEST.
Updrift analyzes in flight, then discards the clone. Secrets stay sealed. Payments teams get specifics, not slogans.
For public repos we do a shallow clone, analyze it, then delete it. Nothing sticks around after the scan. Private repos use the same model through a read-only GitHub App (Contents and Metadata only). Installation tokens and alert webhooks are sealed at rest with libsodium. We never train on customer source.
No. The free scan is read-only and emails you a drift report. Auto-fix PRs need an org opt-in for write access. Scan and PR write are separate. We never open a PR without sandbox proof and your opt-in.
Dependabot bumps package versions. Updrift watches semantic API drift in the integrations those packages call: field renames, webhook verification changes, silent pagination or retry behavior. We map the exact lines in your repo, and we only open a PR when sandbox replay proves the fix.
You get a written report with file and line evidence. No PR. The gate is hard: proved=true only when the fail-to-pass matrix holds. Otherwise you get the finding, not a guessed migration.
Run npx updrift scan locally (read-only, about 90 seconds, no signup), or paste a public GitHub URL in the free scan form above. You'll get a drift report by email. Sign in later if you want continuous Drift Watch or auto-fix PRs.
Yes. Stripe and GitHub are live. Razorpay and Notion are in beta. GitLab, Bitbucket, Confluence, GitBook, Mintlify, and India-first surfaces (Cashfree, Juspay, PhonePe, Setu, Zoho, Freshworks, Postman, Hasura, Chargebee) are available on request. Every logo in Integrations is tagged LIVE, BETA, or ON REQUEST.
Paste a public GitHub URL. We email a drift report covering the lines that break, the deprecations you lean on, and the undocumented bits you're exposed to. Same engine we run in production. No signup. Read-only. Minutes, not days.
Read-only · report in minutes · public repos need no GitHub App
We run this engine against 5 Stripe API versions, 3 ingested pairs, and 3 payment fixtures (Express, Flask, Next). Methodology.
Drift Watch is free forever: monthly report, one repo, breaking-change alerts. Solo, Team, and Business add auto-fix PRs, continuous scans, and unlimited repos. We're onboarding design partners by hand right now.
Free forever. Monthly report, one repo, breaking-change alerts.
Auto-fix PRs, sandbox replay, weekly scans.
Continuous scans, Slack, priority queue.
Unlimited repos, audit export, invites.