List candidate scorecards
curl --request GET \
--url https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/ \
--header 'Authorization: Bearer <token>'import requests
url = "https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const url = 'https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch(url, options)
.then(res => res.json())
.then(json => console.log(json))
.catch(err => console.error(err));package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}[
{
"id": "sc111111-1111-1111-1111-111111111111",
"author_id": null,
"application_id": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"assessment_id": null,
"criteria": [
{
"name": "SQL",
"score": 4.5
},
{
"name": "Communication",
"score": 4
}
],
"total": "4.25",
"created_at": "2026-09-03T11:00:00Z",
"updated_at": "2026-09-03T11:00:00Z"
}
]{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"message": "Invalid or revoked API Key.",
"code": "INVALID_API_KEY"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}Public API — Profiles
List candidate scorecards
Required scope:
profiles:read
Lists interviewer / recruiter scorecards for the candidate.
Responses
| Status | When |
|---|---|
200 | Scorecard list |
404 | Candidate not found |
Authentication & rate limits (all endpoints)
| Status | Code | When |
|---|---|---|
401 | INVALID_API_KEY | Missing or invalid bearer token |
401 | EXPIRED_API_KEY | API key past its optional expires_at |
403 | INSUFFICIENT_SCOPE | API key lacks the required scope for this operation |
403 | IP_NOT_ALLOWED | Client IP is outside this key’s CIDR allowlist |
429 | RATE_LIMITED | Rate limit exceeded — plan-tiered reads/writes per organisation per hour |
GET
/
api
/
v1
/
public
/
candidates
/
{candidate_id}
/
scorecards
/
List candidate scorecards
curl --request GET \
--url https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/ \
--header 'Authorization: Bearer <token>'import requests
url = "https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const url = 'https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch(url, options)
.then(res => res.json())
.then(json => console.log(json))
.catch(err => console.error(err));package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://assess.praxicraft.com/api/v1/public/candidates/{candidate_id}/scorecards/"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}[
{
"id": "sc111111-1111-1111-1111-111111111111",
"author_id": null,
"application_id": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"assessment_id": null,
"criteria": [
{
"name": "SQL",
"score": 4.5
},
{
"name": "Communication",
"score": 4
}
],
"total": "4.25",
"created_at": "2026-09-03T11:00:00Z",
"updated_at": "2026-09-03T11:00:00Z"
}
]{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"message": "Invalid or revoked API Key.",
"code": "INVALID_API_KEY"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}Authorizations
Organisation API key created in Assess → Developer → API Keys. Format: Bearer ct_live_<your-key> (live) or Bearer ct_test_<your-key> (test). Optional per-key CIDR allowlists return 403 IP_NOT_ALLOWED.
Path Parameters
Response
Pattern:
^-?\d{0,6}(?:\.\d{0,2})?$Last modified on September 5, 2026