Updrift
When Stripe ships a silent change, Updrift finds the lines that break and opens a sandbox-tested pull request before production does.
$ npx updrift scan · read-only · ~90 seconds · no signup
Providers ship OpenAPI updates and quiet behavior shifts. Updrift maps each one onto the exact handlers in your repo, then attaches fail-to-pass sandbox proof before anyone merges.
Libraries bump on their own timeline.
Your integration call sites need a different kind of watch.
Every OpenAPI shift that hits your webhooks and renewals shows up as an evidence-backed finding before customers feel it.
Renaming a field is easy. The changes that take payments down are semantic, and a lot of them never show up in a changelog. We read Stripe's OpenAPI, docs, SDKs, and deprecation headers, then spell out what each change does to your handlers.
APIs also change how they behave without bumping a version. Latency jumps. Webhooks arrive out of order. A field goes null for one region. Nothing lands in the changelog. Next up: watch how providers actually behave in the wild.
Watch, understand, map, migrate, replay, then PR. If the sandbox can't prove the fix, you get a written report instead of a guessed pull request. We do not guess with your payments code.
Same path as pnpm moat:demo
Skewed webhook signatures have to fail before the migration and pass after. Old-format traffic still has to pass. Only then do we set proved=true.
Fixture repo with real Stripe webhook usage
webhook_verification_changed shows up as silent breaking
Sandbox matrix: skewed signature fails before, passes after
Migration branch with tests. You review. You merge.
Stripe and GitHub are live. Razorpay and Notion are in beta. Everything else is on request. Every tile carries LIVE, BETA, or ON REQUEST.
Updrift analyzes in flight, then discards the clone. Secrets stay sealed. Payments teams get specifics, not slogans.
For public repos we do a shallow clone, analyze it, then delete it. Nothing sticks around after the scan. Private repos use the same model through a read-only GitHub App (Contents and Metadata only). Installation tokens and alert webhooks are sealed at rest with libsodium. We never train on customer source.
No. The free scan is read-only and emails you a drift report. Auto-fix PRs need an org opt-in for write access. Scan and PR write are separate. We never open a PR without sandbox proof and your opt-in.
Dependabot bumps package versions. Updrift watches semantic API drift in the integrations those packages call: field renames, webhook verification changes, silent pagination or retry behavior. We map the exact lines in your repo, and we only open a PR when sandbox replay proves the fix.
You get a written report with file and line evidence. No PR. The gate is hard: proved=true only when the fail-to-pass matrix holds. Otherwise you get the finding, not a guessed migration.
Run npx updrift scan locally (read-only, about 90 seconds, no signup), or paste a public GitHub URL in the free report form below. You'll get a drift report by email.
Yes. Stripe and GitHub are live. Razorpay and Notion are in beta. GitLab, Bitbucket, Confluence, GitBook, Mintlify, and India-first surfaces (Cashfree, Juspay, PhonePe, Setu, Zoho, Freshworks, Postman, Hasura, Chargebee) are available on request. Every logo in Integrations is tagged LIVE, BETA, or ON REQUEST.
Paste a public GitHub URL. We review the lines that break, the deprecations you lean on, and the undocumented bits you're exposed to, then email a drift report. No signup. Read-only. Manual review while we scale.
Read-only · report by email · public repos need no GitHub App
Drift Watch is free forever: monthly report, one repo, breaking-change alerts. Solo, Team, and Business add auto-fix PRs, continuous scans, and unlimited repos. We're onboarding design partners by hand right now.
Free forever. Monthly report, one repo, breaking-change alerts.
Auto-fix PRs, sandbox replay, weekly scans.
Continuous scans, Slack, priority queue.
Unlimited repos, audit export, invites.