e-volv

Integrations

Everynewfeatureworkswithouttheapp

Scoped API keys open a standalone surface: ingest runs, post heartbeats, read metrics, rotate secrets, publish manifests.

Each key belongs to a workspace and carries only the scopes you grant. The public routes cover the same features the app does — identity, evals, heartbeats, SLO events, metrics, secrets, MCP publishing — so a cron job, a GitHub Action or another platform can use Evolve without a browser session. Keys are shown once and stored hashed.

Early access — turned on per workspace. Ask us to enable it for yours.

  • Keys are shown once; only a SHA-256 hash is stored
  • Least-privilege scopes per key, checked per route
  • Prometheus text format for metrics scrapers
  • Signed webhooks with an HMAC header for outbound alerts

10

API scopes