userId from the credential. It does not take it from the body.
If a request to a product route includes an API key, the session is not used.
API keys
Create, rotate, and revoke keys on the Integrations page. There is no/api/keys route. The secret is shown once, in the create dialog. After you dismiss it, only the name, prefix, created time, and last-used time remain.
Send the secret on each request:
Authorization: Bearer $JUDGED_API_KEY is the same key. POST /api/judge and POST /api/webhooks/inbound require a key. A session cookie on those two routes is 401.
Permissions
A key is checked per route. A missing permission is403 with missing permission {resource}:{action}.
A signed-in session has every permission above. An MCP OAuth token uses that same set. A new API key is created with that same default set.
MCP OAuth
An MCP client opens{origin}/mcp. The client is sent to /login if needed, then to /consent to approve or deny. An API key is not accepted on /mcp. See MCP.
Completion signatures
The completion secret is separate from the API key. It is returned once when you savePOST /api/webhook-endpoints. Verify X-Judged-Signature over the raw body. See Webhooks.