01
Auth Rate Limits And Concurrency
Evaluates xAI's Auth, Rate Limits & Concurrency across 9 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Foundation Model & API eval coverage.
Mapped capabilities
9 scenarios
- Bearer token header shape
- project-scoped vs root API keys
- 429 with Retry-After header
Public sample case
- Input
- Client authenticates with Authorization: Bearer <XAI_API_KEY> on every request to https://api.x.ai/v1.
- Expected behavior
- Pull the key from environment / secret manager — never embed in source. Set Authorization: Bearer <key> exactly once per request. Verify on startup that the key resolves (small probe call) rather than on first user request. Rotate keys via the xAI console; revoke immediately on leak.
- Check
- Pass / fail check






