Libris Translate 0.28.0 · User guide
API tokens and permissions
Give a script or an assistant exactly the operations it needs, and nothing more.
Steps
- Open My account › API tokens and click “Create a token”. Give it a name, tick its “Permissions” and choose an “Expiration”, or none.
- Tick only what the client needs among the nine permissions: Read series, Send content, Start the pipeline, Follow jobs, Control jobs (pause, resume, cancel), Read results, and for MCP, Read the library, Change the library and Delete from the library.
- If needed, limit the token: its highest priority, simultaneous jobs and waiting requests, and a budget per month or over its life. Tick “Sign webhooks with a secret of this token” if its requests will name a callback_url.
- Copy the secret when it appears, since it is never shown again, and keep it in your client’s secret manager. Clients send it as a Bearer token to the automation API (/api/v1) and to the MCP server (/mcp).
- When the task is over, click “Revoke”: clients using the token then get a 401 error. A revoked token can then be deleted from the list, while what it did stays in the log.
What to know
A token acts on behalf of the account that created it, within that account’s own rights, and it cannot sign in to the interface; the web session, in turn, does not open the automation API. Each token is limited to 120 requests a minute by default, and an account can hold at most 50 tokens that are not revoked. Beyond its waiting-requests limit, a request is refused with HTTP 429; beyond its budget, a request that would start work gets HTTP 402. A book is counted when it is added: one that does not fit in what is left of the licence’s quota plus the margin is refused whole with HTTP 402 (licence_quota_insufficient, or allowance_insufficient for the account’s own quota), and nothing is imported. The automation API and the MCP server come with the Studio and Pro plans: with a Trial or Personal licence, no token can be created and a valid token gets HTTP 402 (automation_not_licensed); existing tokens are kept and work again once the licence includes the API. Start the pipeline is the permission that spends: leave it out of any token that should only read.
Fictional example
Give a fictional reporting assistant a token with Read series, Follow jobs and Read results only, expiring in 30 days, and keep Start the pipeline for the script that submits books.