Developers
HTTP API
Main routes, origin checks and download contracts.
The API is prefixed by /api, except for health.
Health
| Method | Route | Purpose |
|---|---|---|
GET | /health | Service status and non-sensitive information. |
Providers
| Method | Route | Purpose |
|---|---|---|
GET | /api/settings/credentials | Masked credential metadata. |
POST | /api/settings/credentials | Save key and endpoint by provider. |
POST | /api/settings/test-connection | Test the connection. |
POST | /api/settings/models | Retrieve available models. |
POST | /api/settings/test-translation | Translate an excerpt. |
POST | /api/settings/sandbox-extract | Extract a passage from a temporary document. |
Projects
| Method | Route | Purpose |
|---|---|---|
POST | /api/jobs/upload | Import and prepare a project. |
GET | /api/jobs | List projects. |
GET | /api/jobs/{id} | Read a project. |
GET | /api/jobs/{id}/segments | Read its segments. |
POST | /api/jobs/{id}/start | Start or resume. |
POST | /api/jobs/{id}/pause | Pause. |
POST | /api/jobs/{id}/retry | Reset failures. |
POST | /api/jobs/{id}/update-config | Modify an allowed configuration. |
GET | /api/jobs/{id}/download | Reconstruct and download. |
DELETE | /api/jobs/{id} | Delete the project and dedicated files. |
Glossaries and events
GET, POST and DELETE under /api/glossaries, plus GET /api/events for the SSE stream.
Origins
There is no application token. Browser write requests must come from the served app or an explicit ALLOWED_ORIGINS value.
Download
The response carries Cache-Control: no-store, X-Content-Type-Options: nosniff and X-TraDoc-Export: partial|final. The MIME type follows the reconstructed extension.