Dashboard
curva serve has a built-in web dashboard at /dashboard. It is one small page (HTML, CSS and
plain JavaScript, no external requests) that reads the same JSON API your code uses.
curva serveopen http://localhost:7777/dashboardIf the server has API keys, paste one into the API key field. Leave it blank on a keyless
local server. Pick a project (default default) and press Load.
What it shows
Section titled “What it shows”| View | Source | Shows |
|---|---|---|
| Overview | GET /metrics |
Requests by HTTP status, decisions, cache hit rate, abstain rate, p50 and p95 decide latency (estimated from the histogram buckets), and the daily quota left when CURVA_DAILY_LIMIT is set. Counters are since the server started |
| Decisions | GET /v1/audit |
The project’s decisions, newest first, 25 per page: id, time, model, mode, config, cached, latency, cost, and every answer (choice and confidence, score, P(yes), selected options, or skipped, with abstain and calibrated tags) |
| Calibration | GET /v1/calibration |
For one question: labels collected against the 30 needed, the fitted calibrator, accuracy, ECE, Brier and automation before and after calibration, and a reliability diagram (predicted confidence against observed accuracy, with the diagonal a calibrated model follows) |
| Drift | GET /v1/drift |
For one question: the weekly answer mix as stacked bars, average confidence per week, a table of the same numbers, and a warning when the latest week is flagged as drift |
The question pickers suggest the keys found in the project’s latest decisions. See Calibrate with feedback and Drift for what the numbers mean.
Security
Section titled “Security”- The page is public; the data is not.
GET /dashboardis served without a key because the page contains no data. Every request it makes for data goes to the API and needs a key like any other client. - The key stays in the browser tab. It is kept in
sessionStorage(gone when the tab closes) and sent only to this server, in theAuthorizationheader. The page’s Content-Security-Policy blocks requests to any other origin. - Use TLS. Anyone who can watch the traffic can read the key. On anything but localhost, put Curva behind a reverse proxy that terminates TLS (Caddy, nginx or a cloud load balancer), as in Self-hosting.
- Give the dashboard its own key (
curva keys create --name dashboard) so you can revoke it without touching production clients.

