> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zivio.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Score a proposal against the project's quality criteria (create or update an evaluation)

> Records reviewer scores out of 10, each with justification notes, against the project's evaluation criteria — mirroring the web UI's evaluation form. Send several criteria in one call via `scores`, or a single criterion at the top level. Re-scoring a criterion overwrites the previous score and notes, so the same call creates or updates an evaluation. Identify each criterion by `criterion_id` (from GET /projects/{id}/evaluations) or by its exact `criterion` name. Notes are required. The whole batch is applied together, and the project's proposal scores are recalculated afterwards, exactly as the UI does.



## OpenAPI

````yaml /api-reference/v4/openapi.json post /bids/{id}/scores
openapi: 3.1.0
info:
  title: API V4
  version: '4'
  description: >-
    OAuth 2.0 secured API. Obtain an access token using client credentials to
    access protected endpoints. The regional endpoints listed below serve every
    Zivio organisation, so each request — including the token request — must
    carry a `zivio-tenant-id` header identifying yours. Requests without it are
    rejected with a 404 before any token is checked.
  contact:
    name: API Support
    email: support@zivio.com
servers:
  - url: https://api.zivio.net/api/v4
    description: Global API Router
  - url: https://api.eu.zivio.net/api/v4
    description: EU Data Region
  - url: https://api.uk.zivio.net/api/v4
    description: UK Data Region
  - url: https://api.us.zivio.net/api/v4
    description: US Data Region
security:
  - oauth2: []
    tenantId: []
paths:
  /bids/{id}/scores:
    post:
      tags:
        - Bids
      summary: >-
        Score a proposal against the project's quality criteria (create or
        update an evaluation)
      description: >-
        Records reviewer scores out of 10, each with justification notes,
        against the project's evaluation criteria — mirroring the web UI's
        evaluation form. Send several criteria in one call via `scores`, or a
        single criterion at the top level. Re-scoring a criterion overwrites the
        previous score and notes, so the same call creates or updates an
        evaluation. Identify each criterion by `criterion_id` (from GET
        /projects/{id}/evaluations) or by its exact `criterion` name. Notes are
        required. The whole batch is applied together, and the project's
        proposal scores are recalculated afterwards, exactly as the UI does.
      operationId: postBidsByIdScores
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: integer
          description: Bid ID
          example: 123
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                scores:
                  type: array
                  description: >-
                    One entry per criterion: { criterion_id or criterion, score
                    (0-10), notes }.
                  items:
                    type: object
                    properties:
                      criterion_id:
                        type: integer
                        description: Quality criterion id.
                        example: 11
                      criterion:
                        type: string
                        description: Criterion name, as an alternative to criterion_id.
                        example: Technical Approach
                      score:
                        type: integer
                        description: Whole number from 0 to 10.
                        example: 8
                      notes:
                        type: string
                        description: Justification for the score (required).
                        example: Strong discovery phase and a credible test strategy.
                criterion_id:
                  type: integer
                  description: 'Single-score form: the criterion id.'
                criterion:
                  type: string
                  description: 'Single-score form: the criterion name.'
                score:
                  type: integer
                  description: 'Single-score form: whole number from 0 to 10.'
                notes:
                  type: string
                  description: 'Single-score form: justification (required).'
      responses:
        '200':
          description: Scores recorded; the proposal's recalculated scorecard is returned
          content:
            application/json:
              schema:
                type: object
              example:
                message: Recorded 2 scores for proposal 9
                project_id: 123
                proposal:
                  bid_id: 9
                  total_score_percentage: 84
                  scores:
                    - criterion_id: 11
                      criterion: Technical Approach
                      score: 8
                      notes: Strong discovery phase.
                      weighted_score: 80
                  unscored_criteria: []
        '401':
          description: >-
            Unauthorized - the access token is missing, expired, revoked or
            malformed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: invalid_token
                error_description: >-
                  The access token provided is expired, revoked, malformed, or
                  invalid for other reasons
        '403':
          description: Forbidden - insufficient scope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: insufficient_scope
                error_description: >-
                  The request requires higher privileges than provided by the
                  access token
                required_scope: bid_evaluations:write
                provided_scopes:
                  - welcome:read
        '422':
          description: >-
            Unknown criterion, score out of range, missing notes, or quality
            scoring disabled for the project. A validation failure lists the
            project's available criteria so the call can be corrected
          content:
            application/json:
              schema:
                type: object
              example:
                error: validation_failed
                errors:
                  - score must be a whole number between 0 and 10 (got "eight")
                available_criteria:
                  - id: 11
                    description: Technical Approach
      security:
        - oauth2:
            - bid_evaluations:write
          tenantId: []
components:
  schemas:
    Error:
      type: object
      description: Error envelope returned by every non-2xx V4 response
      properties:
        error:
          type: string
          example: insufficient_scope
        error_description:
          type: string
        message:
          type: string
        details:
          type: object
          additionalProperties: true
        required_scope:
          type: string
          example: projects:read
        provided_scopes:
          type: array
          items:
            type: string
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        OAuth 2.0 client credentials. The access token from POST /oauth/token is
        sent as a bearer token. Request only the scopes you need.
      flows:
        clientCredentials:
          tokenUrl: https://api.zivio.net/api/v4/oauth/token
          scopes:
            bank_accounts:read: Read bank account details on suppliers and the org.
            catalogs:read: Read catalog items.
            cost_centers:read: Read cost center records.
            eoi_responses:read: Read responses to expressions of interest.
            eois:read: Read expressions of interest.
            offers:read: Read offers for projects.
            org_units:read: Read your organization unit hierarchy.
            org_users:read: Read members of your organization.
            resources:read: Read resource (worker) records.
            sales_invoices:read: Read invoices issued to clients.
            sales_milestones:read: Read milestones on sales engagements.
            skill_categories:read: Read the skill category taxonomy.
            skill_taxonomies:read: Read skill taxonomy structure.
            skills:read: Read individual skills.
            supplier_documents:read: Read documents uploaded by suppliers.
            supplier_lists:read: Read curated lists of suppliers.
            supplier_users:read: Read users belonging to supplier organizations.
            tax_types:read: Read configured tax types.
            users:read: Read user profiles.
            variation_orders:read: Read variation orders on projects.
            welcome:read: 'Required: confirms your identity to the application.'
            bid_evaluations:read: >-
              Read evaluation scorecards for bids, including criterion scores
              and quality, cost and total scores.
            bid_evaluations:write: >-
              Score bids against a project's quality criteria and override
              calculated cost scores.
            bids:read: Read bids submitted on projects.
            bids:write: >-
              Shortlist, select, eliminate and reinstate bids submitted on
              projects.
            invoices:read: Read invoices on projects.
            invoices:write: Create and update invoices.
            notes:read: Read notes on projects and EOIs.
            notes:write: Create and update notes on projects and EOIs.
            project_approvals:read: Read project approval workflows.
            project_approvals:write: Create and update project approval workflows.
            project_conversations:read: Read messages exchanged with suppliers on a project.
            project_conversations:write: Send messages to suppliers on a project.
            project_invitations:read: Read supplier invitations on projects.
            project_invitations:write: Invite suppliers to bid on projects.
            project_questions:read: Read supplier clarification questions on projects.
            project_questions:write: Answer and approve supplier clarification questions.
            projects:read: Read projects.
            projects:write: Create and update projects.
            milestones:read: Read milestones on projects.
            milestones:write: Create and update milestones.
            orgs:read: Read organization records.
            orgs:write: Create and update organization records.
            purchase_orders:read: Read purchase orders.
            purchase_orders:write: Create and update purchase orders.
            reviews:read: Read reviews left on suppliers.
            reviews:write: Create and update reviews.
            suppliers:read: Read supplier profiles.
            suppliers:write: Create and update supplier profiles.
            raw_scorecard_entries:write: Create and update raw scorecard entries.
            raw_scorecard_entries:read: Read raw scorecard entries.
            tasks:read: >-
              Read the acting user's task queue, including outstanding approvals
              and items to review.
            tasks:write: Complete and dismiss tasks in the acting user's task queue.
            act_as_user: >-
              Make requests as another user within the token holder's delegation
              boundary.
    tenantId:
      type: apiKey
      name: zivio-tenant-id
      in: header
      description: >-
        Your Zivio organisation identifier. The regional API endpoints serve
        every Zivio organisation, so each request must identify yours.

````