open source

Join the community.

Dino's CLI and verification engine are public. Read the code, run it locally, and verify every scan result yourself. You don't have to take our word for it.

@dino-hq/clisource-availableTypeScript

The full Dino CLI is public. Read exactly what it does before you point it at your API, then run it locally against any REST or GraphQL endpoint.

One command returns a deterministic verdict on whether an API change is correct, secure, and safe to ship. Works with Claude Code, Codex, Cursor, and CI.

dino verifyofflineSigstore

Every scan Dino runs is cryptographically signed. dino verify checks any result offline: confirm the signature, recompute the SHA-256 digest, and validate the signing identity.

No access to Dino's systems required. Same evidence and same policy always produce the same verdict, and anyone can prove it.

Dino's source is available under a proprietary license: read, run, and verify the code freely. Commercial use requires a Dino subscription. See the LICENSE file on GitHub. The agent tools, analytics, and reasoning layers stay private.