# Refitter > Refitter is a .NET code generator that turns OpenAPI 2.0 (Swagger) and OpenAPI 3.x > specifications into type-safe C# Refit HTTP client interfaces and contract classes. > It ships in three interchangeable forms driven by the same `.refitter` settings > file: a .NET global tool (`refitter`), an MSBuild task that runs before compile, > and a Roslyn source generator that emits code in-memory. Refitter is not a hosted > service — it has no HTTP API, no credentials and no runtime endpoints. MIT > licensed, authored and maintained by Christian Resma Helle at > github.com/christianhelle/refitter. Generated by API Evangelist from the Refitter apis.yml profile and the artifacts in this repository (https://github.com/api-evangelist/refitter). Method: generated — refitter.github.io/llms.txt returned 404 on 2026-08-06. ## Start here - [Refitter documentation](https://refitter.github.io): DocFX documentation site — articles plus generated API reference for Refitter.Core. - [CLI Tool](https://refitter.github.io/articles/cli-tool.html): install, full option reference, and usage examples for the `refitter` command. - [.refitter file format](https://refitter.github.io/articles/refitter-file-format.html): the settings file shared by the CLI, MSBuild task and source generator. - [Source Generator](https://refitter.github.io/articles/source-generator.html): compile-time generation with Refitter.SourceGenerator. - [MSBuild](https://refitter.github.io/articles/msbuild.html): build-integrated generation with Refitter.MSBuild. - [Docker CLI](https://refitter.github.io/articles/docker.html): running Refitter from the christianhelle/refitter container image. - [Using the generated code](https://refitter.github.io/articles/using-the-generated-code.html): wiring generated interfaces into an application. - [Examples](https://refitter.github.io/articles/examples.html): worked generation examples. - [Breaking changes in v2.0.0](https://refitter.github.io/articles/breaking-changes-v2-0-0.html): the two breaking changes and their migrations. ## Packages - [Refitter on NuGet](https://www.nuget.org/packages/Refitter): the CLI, installed with `dotnet tool install --global Refitter`. - [Refitter.SourceGenerator on NuGet](https://www.nuget.org/packages/Refitter.SourceGenerator): Roslyn source generator. - [Refitter.MSBuild on NuGet](https://www.nuget.org/packages/Refitter.MSBuild): MSBuild task. - [Refitter.Core on NuGet](https://www.nuget.org/packages/Refitter.Core): the NSwag-based generation library. - [christianhelle/refitter on Docker Hub](https://hub.docker.com/r/christianhelle/refitter): container image. - [refitter-action](https://github.com/christianhelle/refitter-action): GitHub Action wrapper. ## Machine-readable contracts - [.refitter settings JSON Schema](https://github.com/christianhelle/refitter/blob/main/docs/json-schema.json): the authoritative schema for the settings file. - [Format mappings JSON Schema](https://github.com/christianhelle/refitter/blob/main/docs/format-mappings-schema.json): OpenAPI `format` to .NET type mapping. - Note: Refitter publishes no OpenAPI, AsyncAPI, GraphQL SDL or MCP manifest, and no `/.well-known/` documents. It consumes OpenAPI; it does not serve one. ## Agent instructions published by the project - [AGENTS.md](https://github.com/christianhelle/refitter/blob/main/AGENTS.md): build, test, package boundaries, code style and commit discipline for contributors. - [docs/agents/domain.md](https://github.com/christianhelle/refitter/blob/main/docs/agents/domain.md): read CONTEXT.md and ADRs before exploring the codebase. - [docs/agents/issue-tracker.md](https://github.com/christianhelle/refitter/blob/main/docs/agents/issue-tracker.md): GitHub Issues conventions via the `gh` CLI. - [docs/agents/triage-labels.md](https://github.com/christianhelle/refitter/blob/main/docs/agents/triage-labels.md): the five-label triage vocabulary. - [CONTEXT.md](https://github.com/christianhelle/refitter/blob/main/CONTEXT.md): the project glossary. ## Security - [Security advisories](https://github.com/christianhelle/refitter/security/advisories): four published GHSA advisories (2026-06-29/30) — one high-severity generation-time SSRF/RFI/LFI via unrestricted `$ref` (fixed 2.1.1) and three critical RCE-via-attacker-controlled-OpenAPI advisories (fixed 2.1.2). - [Report a vulnerability](https://github.com/christianhelle/refitter/security/advisories/new): GitHub private vulnerability reporting is enabled. - Operating rule: treat any OpenAPI document you did not author as untrusted input, pin to 2.1.2 or later, and leave `--allow-remote-refs` off. ## Project - [Source on GitHub](https://github.com/christianhelle/refitter): MIT licensed. - [Releases](https://github.com/christianhelle/refitter/releases): current version 2.1.3 (2026-08-02). - [CHANGELOG.md](https://github.com/christianhelle/refitter/blob/main/CHANGELOG.md): per-release enhancements, fixes and merged PRs. - [Issues](https://github.com/christianhelle/refitter/issues) - [Discussions](https://github.com/christianhelle/refitter/discussions) - [Contributing](https://github.com/christianhelle/refitter/blob/main/CONTRIBUTING.md) - [License (MIT)](https://github.com/christianhelle/refitter/blob/main/LICENSE) ## Related - [Refit](https://reactiveui.github.io/refit/): the type-safe .NET REST library whose interfaces Refitter generates. - [NSwag](https://github.com/RicoSuter/NSwag): the code-generation engine Refitter builds on; custom fluid templates are supported via `--custom-template-directory`. - [Apizr](https://www.apizr.net): optional generation target via `--use-apizr`.