Integration Gate · GATE

Did this API change introduce a risky new agent capability?

Integration Gate compares baseline and candidate Agent API Readiness reports, identifies security-relevant deltas, and returns PASS, REVIEW, or FAIL for CI policy.

Baseline → candidate

Make capability drift visible in pull requests.

A PASS requires full comparison coverage and no security-relevant regression or expansion requiring review. Partial coverage returns at least REVIEW.

BASELINEopenapi-main.yaml
KNOWN
CANDIDATEopenapi-pr.yaml
CHANGED
VERDICTFAIL
authorization_relaxed

Verdict semantics

Three outcomes with fail-closed coverage.

The configured --fail-on threshold maps the richer result into a CI exit code; it does not replace the structured verdict.

PASS

No review-level delta observed

Both sides had full coverage and no modeled change required review.

REVIEW

Capability surface changed

A new capability, risk tag, relevant finding, or incomplete comparison needs review.

FAIL

Reliable regression

A new blocker, documented authorization relaxation, or critical scanner regression was introduced.

CI/CD contract

Designed for pull requests and release gates.

Use deterministic Agent Security JSON 1.0 and choose whether REVIEW, FAIL, or neither should return a nonzero policy-threshold exit code.

speculynx agent gate
--baseline openapi-main.yaml
--candidate openapi-pr.yaml
--fail-on review

verdict FAIL
change authorization_relaxed
Gate scope: PASS does not prove runtime safety or effective authorization. It means the fully evaluated documented surface did not produce a modeled review- or fail-level delta.

Put capability changes in the review loop.

Integration Gate is a one-time purchase with the integration_gate entitlement.

Analyze your API
$249 one-time purchase.