POST /api/validate scores an arbitrary system prompt against the same rubric as /validate and the MCP server's validate_prompt tool — all three go through one guard chain and share one rate limit, so a status you get from curl matches what the page would show.
bash
1curl -X POST https://app.rubricary.com/api/validate \
2 -H"Content-Type: application/json" \
3 -d'{"text": "You are a support agent for Acme..."}'
A successful call returns the score, the criteria it was checked against, and how many free runs remain:
json
1{
2"score":78,
3"band":"good",
4"findings":[ /* one entry per rubric criterion */ ],
5"freeRemaining":1
6}
No key is required and none is accepted — the endpoint is anonymous by design, metered by IP and account instead:
Status
Reason
Meaning
400
—
Request body is missing or empty text.
401
sign_in_required
The 2 free anonymous validations are used up.
413
too_long
Prompt text is over 12,000 characters.
429
ip_quota / user_quota
Daily quota reached — 10 per IP, 50 per signed-in account. Resets at midnight UTC.
503
budget_exhausted
The validator's model budget for the period is spent.