Create candidate scorecard
curl --request POST \
--url https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/ \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"criteria": [
"<unknown>"
],
"total": "<string>",
"application_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"assessment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
'import requests
url = "https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/"
payload = {
"criteria": ["<unknown>"],
"total": "<string>",
"application_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"assessment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
criteria: ['<unknown>'],
total: '<string>',
application_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
assessment_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a'
})
};
fetch('https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const url = 'https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/';
const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
criteria: ['<unknown>'],
total: '<string>',
application_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
assessment_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a'
})
};
fetch(url, options)
.then(res => res.json())
.then(json => console.log(json))
.catch(err => console.error(err));package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/"
payload := strings.NewReader("{\n \"criteria\": [\n \"<unknown>\"\n ],\n \"total\": \"<string>\",\n \"application_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"assessment_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"id": "sc111111-1111-1111-1111-111111111111",
"author_id": null,
"application_id": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"assessment_id": null,
"criteria": [
{
"name": "SQL",
"score": 4.5
},
{
"name": "Communication",
"score": 4
}
],
"total": "4.25",
"created_at": "2026-09-03T11:00:00Z",
"updated_at": "2026-09-03T11:00:00Z"
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"message": "Invalid or revoked API Key.",
"code": "INVALID_API_KEY"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}Public API — Profiles
Create candidate scorecard
Required scope:
profiles:write
Creates a scorecard entry (ratings + free text) on the candidate profile.
Responses
| Status | When |
|---|---|
201 | Scorecard created |
404 | Candidate not found |
Authentication & rate limits (all endpoints)
| Status | Code | When |
|---|---|---|
401 | INVALID_API_KEY | Missing or invalid bearer token |
401 | EXPIRED_API_KEY | API key past its optional expires_at |
403 | INSUFFICIENT_SCOPE | API key lacks the required scope for this operation |
403 | IP_NOT_ALLOWED | Client IP is outside this key’s CIDR allowlist |
429 | RATE_LIMITED | Rate limit exceeded — plan-tiered reads/writes per organisation per hour |
POST
/
api
/
v1
/
public
/
candidates
/
{candidate_id}
/
scorecards
/
Create candidate scorecard
curl --request POST \
--url https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/ \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"criteria": [
"<unknown>"
],
"total": "<string>",
"application_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"assessment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
'import requests
url = "https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/"
payload = {
"criteria": ["<unknown>"],
"total": "<string>",
"application_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"assessment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
criteria: ['<unknown>'],
total: '<string>',
application_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
assessment_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a'
})
};
fetch('https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const url = 'https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/';
const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
criteria: ['<unknown>'],
total: '<string>',
application_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
assessment_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a'
})
};
fetch(url, options)
.then(res => res.json())
.then(json => console.log(json))
.catch(err => console.error(err));package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/"
payload := strings.NewReader("{\n \"criteria\": [\n \"<unknown>\"\n ],\n \"total\": \"<string>\",\n \"application_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"assessment_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"id": "sc111111-1111-1111-1111-111111111111",
"author_id": null,
"application_id": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"assessment_id": null,
"criteria": [
{
"name": "SQL",
"score": 4.5
},
{
"name": "Communication",
"score": 4
}
],
"total": "4.25",
"created_at": "2026-09-03T11:00:00Z",
"updated_at": "2026-09-03T11:00:00Z"
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"message": "Invalid or revoked API Key.",
"code": "INVALID_API_KEY"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}Authorizations
Organisation API key created in Assess → Developer → API Keys. Format: Bearer ct_live_<your-key> (live) or Bearer ct_test_<your-key> (test). Optional per-key CIDR allowlists return 403 IP_NOT_ALLOWED.
Path Parameters
Body
application/jsonapplication/x-www-form-urlencodedmultipart/form-data
Response
Pattern:
^-?\d{0,6}(?:\.\d{0,2})?$Last modified on September 5, 2026