Skip to main content
Every pack, evaluation, dataset, and webhook belongs to one user. The server takes userId from the credential. It does not take it from the body. If a request to a product route includes an API key, the session is not used.

API keys

Create, rotate, and revoke keys on the Integrations page. There is no /api/keys route. The secret is shown once, in the create dialog. After you dismiss it, only the name, prefix, created time, and last-used time remain. Send the secret on each request:
Authorization: Bearer $JUDGED_API_KEY is the same key. POST /api/judge and POST /api/webhooks/inbound require a key. A session cookie on those two routes is 401.

Permissions

A key is checked per route. A missing permission is 403 with missing permission {resource}:{action}. A signed-in session has every permission above. An MCP OAuth token uses that same set. A new API key is created with that same default set.

MCP OAuth

An MCP client opens {origin}/mcp. The client is sent to /login if needed, then to /consent to approve or deny. An API key is not accepted on /mcp. See MCP.

Completion signatures

The completion secret is separate from the API key. It is returned once when you save POST /api/webhook-endpoints. Verify X-Judged-Signature over the raw body. See Webhooks.