> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mcpjam.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Waive a run gate

> Override a FAILING run's release gate until an expiry you name. This does NOT make the run pass: the run keeps its `result`, the waiver is a separate audited record, and every surface that honors it — the GitHub Check Run and the CLI's `eval gate` — reports the gate as waived, by whom, why, and until when.

Requires the manage tier; whoever launched the run gets no exception for having launched it. `reason` is stored UNREDACTED and readable by anyone who can see the suite, for as long as the suite exists.

`400` covers five distinct refusals, each with a message written for the caller: the suite belongs to no organization, the reason is blank, the reason exceeds 500 characters, the expiry is not in the future, or the expiry is more than 30 days out. `403` means the caller can see the suite but lacks the manage tier — deliberately not collapsed to `404`, which would send a legitimate member hunting for a run sitting in front of them.



## OpenAPI

````yaml /reference/openapi.json post /projects/{projectId}/eval-runs/{runId}/gate-waivers
openapi: 3.1.0
info:
  title: MCPJam API
  version: 1.0.0-preview
  description: >-
    Programmatic access to MCP servers saved in your MCPJam projects — live
    diagnostics (validate, inspect, export) and operations: call tools, render
    prompts, run eval suites asynchronously and poll their results, and import
    OAuth tokens.


    **The API is in preview**: the surface may change while we finish the
    design. Error `code` values are stable; error `message` strings are not.
    Write clients that ignore unknown response fields.
  contact:
    name: MCPJam
    url: https://github.com/MCPJam/inspector/issues
servers:
  - url: https://app.mcpjam.com/api/v1
    description: Hosted MCPJam
security:
  - bearerAuth: []
tags:
  - name: Hosts
    description: >-
      Project hosts: named model + capability profiles you run chats and eval
      suites against.
  - name: Environments
    description: >-
      Project environments: named, live-editable execution bundles (one host, an
      optional standalone server group, optionally pinned skills and plugin
      versions) that eval suites and journeys run against. Distinct from Sandbox
      images, which are Computer base images. Reads require project membership;
      every write requires project admin.
  - name: Plugins
    description: >-
      Agent Plugins imported into a project — read-only inventory and version
      detail.
  - name: Sandbox images
    description: >-
      Custom Computer images: a digest-pinned Dockerfile built into an immutable
      image your project's computers boot from.
  - name: Server diagnostics
    description: Connect-level health checks against a saved MCP server.
  - name: Primitives
    description: 'The server''s MCP primitives: tools, prompts, and resources.'
  - name: Export
    description: Full-server snapshots for diffing and CI.
  - name: Execution
    description: 'Run the server''s primitives: call tools, render prompts.'
  - name: Eval runs
    description: >-
      Asynchronous eval suite runs: create with 202, poll status, iterations,
      and traces.
  - name: Conformance runs
    description: >-
      Ingest MCP spec-conformance results from the SDK/CLI into project-owned
      history. Distinct from Eval runs (authored LLM cases) and from directory
      readiness.
  - name: Server connections
    description: >-
      Connect an MCP server URL to a project, authorizing in a browser when the
      server requires it.
  - name: OAuth
    description: 'Bring-your-own OAuth: import externally obtained tokens for a server.'
  - name: Scenarios
    description: >-
      Read-only access to the scenarios published from a project: listing,
      settings, attached servers, and share links.
  - name: Catalog
    description: >-
      Discover the resources the other routes operate on: your account,
      projects, servers, eval suites, and chat sessions.
  - name: Tunnels
    description: >-
      Relay tunnels that expose local MCP servers through a public URL,
      registered as first-class project servers (the `mcpjam cloud tunnel` CLI
      flow).
  - name: Agent
    description: >-
      Headless agent turns over the public API: send a message history, the
      server runs one assistant turn with project-scoped workspace tools (eval
      reads + suite creation) on a pinned hosted model, and returns the reply
      plus created-resource references.
  - name: Swarms
    description: >-
      Personas, journeys and swarm containers — the authoring half of Swarms —
      plus the model-backed generation that drafts them.
  - name: Swarm runs
    description: >-
      Launching journeys and reading what they produced. Launching SPENDS — see
      the per-operation notes.
  - name: Swarm insights
    description: >-
      What a swarm run revealed. The scorecard and findings are deterministic
      and free; requesting wave insights runs models and draws on your shared
      daily ledger.
  - name: User testing
    description: >-
      Publishing an environment for real visitors, and controlling who can reach
      it. Several of these NARROW access and take effect immediately.
  - name: Directory readiness
    description: >-
      Grade a saved server against a publisher's listing requirements:
      Anthropic's connector directory or OpenAI's plugin directory. Reported as
      lane status and coverage, never as a numeric score, and excluded from
      `pooledConformanceScore`. Deterministic grading is free; model-backed
      experience observations are an explicit opt-in that consumes MCPJam
      credits and can never decide a verdict.
  - name: Registry
    description: >-
      Search the scraped MCP directories (Claude, ChatGPT, and any future
      source), list curated/org registry cards, and install them into a project.
      Install writes a `servers` row and provenance — it does not open a live
      session. There is no catalog-uninstall route: delete the project server
      instead. Directory reads require a bearer (including minted guest tokens)
      but do not materialize a user. Card/connection reads and all writes are
      authed-non-guest.
paths:
  /projects/{projectId}/eval-runs/{runId}/gate-waivers:
    post:
      tags:
        - Eval runs
      summary: Waive a run gate
      description: >-
        Override a FAILING run's release gate until an expiry you name. This
        does NOT make the run pass: the run keeps its `result`, the waiver is a
        separate audited record, and every surface that honors it — the GitHub
        Check Run and the CLI's `eval gate` — reports the gate as waived, by
        whom, why, and until when.


        Requires the manage tier; whoever launched the run gets no exception for
        having launched it. `reason` is stored UNREDACTED and readable by anyone
        who can see the suite, for as long as the suite exists.


        `400` covers five distinct refusals, each with a message written for the
        caller: the suite belongs to no organization, the reason is blank, the
        reason exceeds 500 characters, the expiry is not in the future, or the
        expiry is more than 30 days out. `403` means the caller can see the
        suite but lacks the manage tier — deliberately not collapsed to `404`,
        which would send a legitimate member hunting for a run sitting in front
        of them.
      operationId: createGateWaiver
      parameters:
        - $ref: '#/components/parameters/projectId'
        - $ref: '#/components/parameters/runId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - reason
                - expiresAt
              additionalProperties: false
              properties:
                reason:
                  type: string
                  description: >-
                    Why the gate is being overridden. Non-blank, at most 500
                    characters, and THE RECORD of the decision. Stored
                    unredacted for the life of the suite.
                expiresAt:
                  type: integer
                  description: >-
                    When the waiver lapses, as epoch milliseconds. Must be in
                    the future and at most 30 days out.
      responses:
        '201':
          description: The waiver was granted.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GateWaiverWriteResult'
        '400':
          description: >-
            The waiver was refused. The message names which of the five
            conditions failed and what would fix it.
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          description: >-
            A waiver is already in force over this run. The body carries that
            EXISTING waiver; no second one was granted, because two active
            waivers would make "which reason is on the check" a race.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GateWaiverWriteResult'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
components:
  parameters:
    projectId:
      name: projectId
      in: path
      required: true
      description: ID of the hosted project that contains the server.
      schema:
        type: string
    runId:
      name: runId
      in: path
      required: true
      description: Eval run ID, as returned by `POST /eval-runs`.
      schema:
        type: string
  schemas:
    GateWaiverWriteResult:
      type: object
      description: >-
        The result of granting or revoking a waiver. `conflict` and
        `already_revoked` are IDEMPOTENT no-op successes, not failures.
      required:
        - status
        - republishedChecks
        - waiver
      properties:
        status:
          type: string
          enum:
            - created
            - conflict
            - revoked
            - already_revoked
          description: >-
            `conflict` — a waiver was already in force, and `waiver` is that
            EXISTING one rather than a second row. `already_revoked` — this
            waiver had already been revoked, and `waiver` reports the original
            revocation rather than restamping it, so the record of who actually
            ended it survives a second call.
        republishedChecks:
          type: integer
          description: >-
            GitHub Check Runs brought back in line by this write. A published
            check is a persisted verdict, not a live read, so `0` on a
            repository with checks connected means the status that gates the
            merge did not move.
        waiver:
          $ref: '#/components/schemas/GateWaiver'
    GateWaiver:
      type: object
      description: >-
        An audited, time-boxed override of an eval run's release gate. A waiver
        never changes the run's own `result` — the run keeps its verdict and
        every surface that honors the waiver says so out loud, which is what
        makes "no silent waiver" checkable rather than promised.
      required:
        - id
        - suiteId
        - runId
        - reason
        - expiresAt
        - createdAt
        - createdBy
        - createdByEmail
        - revokedAt
        - revokedBy
        - active
        - policySnapshot
      properties:
        id:
          type: string
        suiteId:
          type: string
        runId:
          type:
            - string
            - 'null'
          description: The run this waiver covers. Suite-wide waivers are not honored.
        reason:
          type: string
          description: >-
            Why the gate was overridden, as the granter wrote it. Stored
            UNREDACTED and readable by anyone who can see the suite, for as long
            as the suite exists — never put secrets, tokens, or customer data in
            it.
        expiresAt:
          type: integer
          description: >-
            Epoch ms. Always in the future when granted, and capped at 30 days
            out — there is no permanent waiver.
        createdAt:
          type: integer
        createdBy:
          type: string
        createdByEmail:
          type:
            - string
            - 'null'
          description: >-
            `null`, never absent, when it cannot be resolved — a deleted user
            must not make a waiver look authorless.
        revokedAt:
          type:
            - integer
            - 'null'
        revokedBy:
          type:
            - string
            - 'null'
        active:
          type: boolean
          description: >-
            Whether it is in force right now — neither revoked nor expired.
            Computed at read time; a client that must not honor a lapsed waiver
            should re-derive it from `expiresAt` rather than trust it.
        policySnapshot:
          type:
            - object
            - 'null'
          description: >-
            WHAT was overridden, captured at waive time so a later edit to the
            suite cannot rewrite the record. `null` for a run decided by the v2
            verdict policy, whose identity is recorded on the audit event
            instead — this shape cannot hold it, and filling it in would be a
            false record rather than an incomplete one.
          required:
            - minimumPassRate
          properties:
            minimumPassRate:
              type: number
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: string
          description: >-
            Stable, machine-readable error code. New codes may be added over
            time; treat unknown codes as non-retryable failures unless the HTTP
            status says otherwise.
          enum:
            - UNAUTHORIZED
            - FORBIDDEN
            - NOT_FOUND
            - CONFLICT
            - VALIDATION_ERROR
            - RATE_LIMITED
            - FEATURE_NOT_SUPPORTED
            - SERVER_UNREACHABLE
            - TIMEOUT
            - OAUTH_REQUIRED
            - INTERNAL_ERROR
        message:
          type: string
          description: >-
            Human-readable description. May change between releases — don't
            match on it.
        details:
          type: object
          description: Optional, unstructured context bag.
          additionalProperties: true
  responses:
    Unauthorized:
      description: >-
        Missing, invalid, revoked, or orphaned key (`UNAUTHORIZED`) — or the
        **target MCP server** needs an OAuth grant (`OAUTH_REQUIRED`), which is
        a property of the server, not your key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            badKey:
              summary: Invalid or revoked key
              value:
                code: UNAUTHORIZED
                message: Invalid API key
            oauthRequired:
              summary: Target server needs an OAuth grant
              value:
                code: OAUTH_REQUIRED
                message: Server requires OAuth authorization
    Forbidden:
      description: Key is valid but not allowed to do this.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: FORBIDDEN
            message: You do not have access to this project
    NotFound:
      description: Unknown project, server, or resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: NOT_FOUND
            message: Server not found
    RateLimited:
      description: >-
        Per-key rate limit exceeded (60 requests/minute sustained, bursts up to
        10). Honor `Retry-After` and back off with jitter.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: RATE_LIMITED
            message: API key rate limit exceeded. Slow down and retry.
    InternalError:
      description: Something failed on MCPJam's side.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: INTERNAL_ERROR
            message: Unexpected internal error
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        MCPJam API key (`sk_…`). Create one at [Settings → API
        keys](https://app.mcpjam.com/settings/api-keys). Guest sessions cannot
        use the API, and API keys cannot manage other API keys.

````