Working local preview · No purchase required

Keep the AWS REST review in your own environment.

The offline CLI uses the same bounded parser, pinned OpenAPI 3.0 schema, and selected AWS REST rules as this site. It reads local files and prints reports. It has no network access code, account, telemetry, automatic repair or file overwrite.

Download the offline CLI preview

Node.js 22.12 or newer · One bundled script · JSON/YAML · 8 files per run · 1 MiB each · 4 MiB total

Try a reproducible run

  1. Unzip the CLI and the synthetic examples pack into a local folder.
  2. Read the included README and run the help command.
  3. Check an input, then compare it with its expected preview. All reports go to standard output; shell redirection creates a new report file.
node openapi-repair.cjs --help
node openapi-repair.cjs check cases/inheritance-overrides.input.json --fail-on warning
node openapi-repair.cjs check cases/nullable-manual.input.json --format sarif
node openapi-repair.cjs compare cases/inheritance-overrides.input.json cases/inheritance-overrides.preview.json

The first check returns warnings about inherited security. The comparison reports one declaration-only change: the effective OpenAPI requirements match, and the explicit public and optional overrides remain unchanged.

Choose a policy, not an import guarantee

For check runs, exit 0 means no findings at your selected severity; exit 1 means findings meet that policy; exit 2 means argument, input-reading or security-detail budget failure. The default fails on errors; --fail-on warning also fails on warnings. Always review warnings before an AWS import.

For comparisons, exit 0 allows unchanged requirements and declaration-only changes. Exit 1 marks operation, requirement or security-scheme changes for review. Exit 2 means unsupported or partial coverage. This is a security-declaration comparison, not a full API compatibility test.

Reports start with private details omitted

JSON and SARIF omit source text, filenames, API paths, operation IDs, server URLs and scheme names by default. They include rule IDs, counts and fixed next steps. Add --include-locations only if you want private API paths and JSON Pointers in the report. Review that output before uploading it to a repository or third party.

SARIF identifies inputs as input-1, input-2 and so on; it does not invent line numbers or expose local filesystem paths. Keep the input order with your own build records if you need to map a report back to a file.

Free now, paid options only if they solve repeated work

CapabilityAvailable nowPossible future paid service
Single-file diagnostics and selected root-security previewFree; no accountRemains free
Guides, synthetic examples and privacy-safe summariesFreeRemains free
Batch preflight, security comparison and local CLIFree working previewNo current payment or license gate
Saved local project history and reviewed baselinesNot implementedLocal Pro concept
Team approval records, time-limited exceptions and managed rule rolloutNot implementedTeam automation concept on your runner

There is no checkout, subscription, licensing, hosted execution or paid support plan. Future products and prices are uncommitted. The existing free checker is not being removed.

Use this alongside your existing tools

Swagger Editor, Spectral, Redocly and OpenAPI diff tools already cover editing, linting, bundling, CI and many contract changes. This preview focuses on a narrower review: AWS REST import limitations, declared security inheritance, and evidence that you can inspect locally. It is not a replacement for those tools or for an actual AWS test.

Open the browser workbench · Review the test method · Check scope and limits