The Platform channel

codafort platform sends analysis results from the developer's machine or CI to the codafort Platform. Nothing leaves until you turn the channel on.

The Platform keeps a queue per organization, each finding's state across runs, and the before/after scoreboard.

Status (September 2026): the Platform runs as a pilot we provision; the SaaS at app.codafort.com is not online yet. Pointed there, push does not deliver: on your machine the envelope stays queued; in CI, the step fails. For a pilot, use the URL you were given (--url or CODAFORT_PLATFORM_URL).

Connect, deliver, disconnect

codafort platform login              # opens the browser; you approve this computer on the Platform
codafort platform connect            # links THIS repository to your organization
codafort engine analyze --source . --git --format json --output envelope.json
codafort platform push envelope.json # delivers (or queues, if the Platform does not answer)
codafort platform status             # session, linked repository and how many sends are queued
codafort platform disconnect         # unlinks the repository and DISCARDS the queue
codafort platform logout             # revokes the session and deletes the credential

login uses the device authorization flow (RFC 8628): the terminal shows a code, you confirm it while signed in to the Platform, and the session it creates can only deliver evidence and read work orders.

What leaves, and when

  • push of a coda-fort/1: the repository name, branch, commit and only the artifacts the Platform reads, which are issues (each finding with rule, severity, message and the code snippet where it is), dependencies and files. The rest of the envelope stays on the machine. With --with-graph, the code graph that the graph screen draws goes too. Absolute paths do not leave: everything is made relative to the repository root, and the send is refused if one remains.
  • push of another modality (coda-dast/1, coda-iast/1, coda-crash/1…): the envelope as its emitter wrote it.
  • After connect: one usage record per codafort command in this repository, with the verb, the SHA-256 digest of the arguments, how many findings were touched and the duration. When the agent proposes dismissing a finding, the proposal goes too: the finding hash, the kind and the reason it wrote, up to 500 characters. No file paths and no code.
  • Without login (or without a token in CI), push has no one to talk to. Without connect, or after disconnect, no usage record is written. connect also ties the repository to the organization: a push from another organization's session is refused before anything leaves.

In CI

export CODAFORT_PLATFORM_TOKEN=…   # the organization's ingestion token: writes only, never reads or decides
export CODAFORT_PLATFORM_URL=https://…
codafort platform push envelope.json

With the token in the environment, push delivers as a machine, without login. If the Platform does not receive it, the command fails. CI has no queue: it would be lost with the runner, and the step would be green with nothing delivered.

Without network (air-gapped)

The air-gapped build has no channel: the codafort platform verbs exist and answer that there is no channel.