Public read-only API

Read-only JSON endpoints for third-party data reuse (a Team-plan benefit). They return the conclusion layer only — the same aggregation that powers the public pages. Never base URLs, never API keys, never detection inputs.

Auth & rate limits

  • Header: Authorization: Bearer lai_… (tokens are created in the workbench and shown exactly once)
  • Rate limit: per token, equals your plan value (Team 60 rpm; over the limit you get 429)
  • Every response carries x-request-id — quote it when you contact support

GET /api/public/board

Leaderboard conclusion layer. Params: limit (1–100, default 20),offset, protocol (openai / anthropic / gemini).

{
  "version": "rank-v2.1",
  "generatedAt": "2026-10-04T12:00:00.000Z",
  "rows": [{
    "domainNorm": "api.example.com",
    "rank": 1,
    "protocols": ["openai"],
    "medianScore": 87.4,
    "rankKey": 71.2,
    "confidenceLowerBound": 82.9,
    "criticalRateUpper": 0.04,
    "sampleCount": 24,
    "insufficientEvidence": false,
    "lastFinishedAt": "2026-10-03T09:12:00.000Z"
  }]
}

GET /api/public/site/{domain}

Site aggregate plus the 20 most recent public detections (model / tier / score / verdict / official flag). Returns 404 when no public data exists — insufficient evidence ≠ problematic.

Caching & stability

  • Responses are share-cacheable (s-maxage=60 + stale-while-revalidate=300): the payload is token-independent and identical for every caller
  • Fields are additive; deprecated fields stay for at least a quarter and are announced here
  • Semantics of the three score languages are in the glossary (medianScore ≠ rankKey ≠ pass rate — not interchangeable)

Red line: this API serves exactly the same data as the public pages — subscriptions and payment never change any score, verdict or ranking (architecture-assertion tests run in CI).