Keys
Create a key. The secret is shown once. REST and the inbound webhook use it.
REST
POST /api/judge with x-api-key. The page copies a cURL and a TypeScript sample for the selected pack.Inbound
POST /api/webhooks/inbound returns 202. The URL on the page is {origin}/api/webhooks/inbound.Outbound
One HTTPS completion URL per user. Saving returns a new HMAC secret.
MCP
Server URL
{origin}/mcp. The client signs in with OAuth.Keys
Create opens a dialog with a name. The secret is rendered once. Dismiss it after you copy it or confirm you have stored it. The table then shows name, prefix, created time, and last used time. Revoke uses a confirmation, then deletes the key. A revoked key fails the next request with401.
Samples on the page
The REST sample callsPOST /api/judge with the pack you select. The key in the sample is the literal YOUR_KEY. Replace it with the secret you stored.
The inbound sample is the same { packId, ticket } body, plus an Idempotency-Key.
The MCP sample is a client config whose url is {origin}/mcp.