01
Auth Cloud And Governance
Evaluates Qdrant's Auth, Cloud & Governance across 10 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Vector Database eval coverage.
Mapped capabilities
10 scenarios
- api-key required (no default auth)
- read-only api key for query path
- JWT RBAC scoped tokens
Public sample case
- Input
- Agent exposes a self-hosted Qdrant on a public port without setting service.api_key, assuming it is private.
- Expected behavior
- A bare Qdrant instance has no authentication by default — anyone who can reach the port has full read/write. Always set service.api_key (and TLS) before exposing it, and pass the key via the api-key header. Never rely on network obscurity alone.
- Check
- Pass / fail check






