Eval runs

Revoke a gate waiver

End a waiver early, putting the gate and the GitHub Check Run back. Requires the manage tier.

IDEMPOTENT, and already_revoked is a SUCCESS: it reports the ORIGINAL revocation rather than restamping it, so a retry cannot overwrite the record of who actually ended the waiver. An already-expired waiver may still be revoked — the audit trail distinguishes "this was wrong" from "this ran out".

delete/projects/{projectId}/eval-runs/{runId}/gate-waivers/{waiverId}

Path parameters

projectIdstring required

ID of the hosted project that contains the server.

runIdstring required

Eval run ID, as returned by POST /eval-runs.

waiverIdstring required

Gate waiver ID, as returned when the waiver was granted or read.

Headers

x-mcpjam-eval-vocabulary'1' | '2'

Which vocabulary this request and its response speak. Absent means 1, which is byte-for-byte today's contract: the same request fields, the same refusals, the same response projection. 2 is the canonical vocabulary. Any other value is a 400 with code: "VALIDATION_ERROR".

Today it decides one thing: the spelling of an evaluator's policy role. Vocabulary 1 accepts and returns gating; vocabulary 2 accepts both spellings and returns the canonical required. Sending required without the header is a 400, deliberately — vocabulary 1 is not widened to meet vocabulary 2 half way, because a boundary that accepts a spelling it does not announce is one two implementations can disagree about.

A response that varies by vocabulary sends Vary: x-mcpjam-eval-vocabulary.

Response

The revoked waiver.

status'created' | 'conflict' | 'revoked' | 'already_revoked' required

conflict — a waiver was already in force, and waiver is that EXISTING one rather than a second row. already_revoked — this waiver had already been revoked, and waiver reports the original revocation rather than restamping it, so the record of who actually ended it survives a second call.

republishedChecksinteger required

GitHub Check Runs brought back in line by this write. A published check is a persisted verdict, not a live read, so 0 on a repository with checks connected means the status that gates the merge did not move.

Changes

Changed in 3 of the 122 revisions of this API.3