Libris Translate 0.28.0 · User guide

Category: Automate

Completion webhooks

Have Libris Translate call your server when an automation request ends.

Steps

  1. An administrator opens Settings › Automation API and, in the “Webhooks of API requests” card, lists the “Allowed hosts” (one per line, *.example.org for subdomains) and any “Allowed private networks”, then sets a “Global signing secret” of at least 32 characters, or leaves each token to sign with its own.
  2. When submitting work through the API, name a callback_url on one of the allowed hosts.
  3. When the request ends, Libris Translate sends one signed POST. Check the X-Libris-Signature header, an HMAC-SHA256 of the X-Libris-Timestamp value and the body, before trusting it.
  4. Then fetch the request’s status and result through the API. Accept the same notification twice without harm, and keep polling as a fallback.

What to know

A failed call is retried with a growing delay, up to 6 attempts in all and with a 10-second timeout by default. Private and loopback addresses are refused unless they lie in an allowed network, the address checked is the one called, and redirects are not followed. With no allowed host, webhooks are refused. The token’s own secret, when it has one, always signs its requests. A notification says the request ended; read its report for any passage left untranslated before you publish the result. The API reference gives the exact field names.

Fictional example

A fictional receiver checks the signature, records the request identifier, then downloads the translated EPUB only if the final status says the result is ready.

Continue