Libris Translate 0.28.0 · User guide

Category: Automate

API tokens and permissions

Give a script or an assistant exactly the operations it needs, and nothing more.

Steps

  1. Open My account › API tokens and click “Create a token”. Give it a name, tick its “Permissions” and choose an “Expiration”, or none.
  2. Tick only what the client needs among the nine permissions: Read series, Send content, Start the pipeline, Follow jobs, Control jobs (pause, resume, cancel), Read results, and for MCP, Read the library, Change the library and Delete from the library.
  3. If needed, limit the token: its highest priority, simultaneous jobs and waiting requests, and a budget per month or over its life. Tick “Sign webhooks with a secret of this token” if its requests will name a callback_url.
  4. Copy the secret when it appears, since it is never shown again, and keep it in your client’s secret manager. Clients send it as a Bearer token to the automation API (/api/v1) and to the MCP server (/mcp).
  5. When the task is over, click “Revoke”: clients using the token then get a 401 error. A revoked token can then be deleted from the list, while what it did stays in the log.

What to know

A token acts on behalf of the account that created it, within that account’s own rights, and it cannot sign in to the interface; the web session, in turn, does not open the automation API. Each token is limited to 120 requests a minute by default, and an account can hold at most 50 tokens that are not revoked. Beyond its waiting-requests limit, a request is refused with HTTP 429; beyond its budget, a request that would start work gets HTTP 402. A book is counted when it is added: one that does not fit in what is left of the licence’s quota plus the margin is refused whole with HTTP 402 (licence_quota_insufficient, or allowance_insufficient for the account’s own quota), and nothing is imported. The automation API and the MCP server come with the Studio and Pro plans: with a Trial or Personal licence, no token can be created and a valid token gets HTTP 402 (automation_not_licensed); existing tokens are kept and work again once the licence includes the API. Start the pipeline is the permission that spends: leave it out of any token that should only read.

Fictional example

Give a fictional reporting assistant a token with Read series, Follow jobs and Read results only, expiring in 30 days, and keep Start the pipeline for the script that submits books.

Continue