SKAVIO / JOURNAL

SKAVIO JOURNAL · DEVELOPER HOW-TO

OWASP REST Security Cheat Sheet

Skavio Processing API gives backend teams one integration surface for OCR, PDF tools, image and media processing, Flow extraction, Transcribe and Meeting reports. The useful common ground is the job lifecycle: upload sources, estimate credits, submit, monitor and download. Reuse that orchestration while keeping each operation’s inputs, settings and outputs explicit.

OWASP REST Security Cheat Sheet

Choose the output before choosing the operation

Start with what your application needs to receive—not just the source file’s extension. A scanned invoice might require readable text, an editable document or structured fields for a downstream business process. Those are different jobs, even when they begin with the same PDF. OCR produces text or document output. Skavio Flow extracts custom fields and line items into XLSX, CSV or JSON, with source evidence and review warnings. Skavio Transcribe produces a transcript, while Skavio Meeting adds speaker-aware reporting, including summaries, decisions, action items and open questions. For file transformations, documented selectors include pdf-merge, image-edit, audio-trim and video-resize; transcribe and meeting select the corresponding recording workflows. Settings belong in options, but accepted sources and source counts differ by operation. One API does not mean one interchangeable payload—or automatic chaining of several operations into a single job.

Build one upload-to-download lifecycle

Keep authentication and processing requests in your backend. Skavio supports scoped API keys and company-isolated jobs. Use HTTPS and keep credentials out of URLs, where logs may capture them. Inspect the developer documentation at https://www.skavio.eu/api/docs/ and the published OpenAPI contract at https://www.skavio.eu/api/openapi.json before implementing request bodies. Use those references for exact upload fields, operation options and result references rather than guessing a payload. OpenAPI provides a language-independent API description that can support client generation and testing.

Budget by operation, not by job count

The API and Skavio’s web processing tools draw from one company Pricing V2 wallet. That gives the integration a shared balance, not a flat price for every job. Page count, source size, duration and the selected operation determine the quote. Submission reserves the measured quote; success charges once, and permanent failure releases the reservation. Prepaid credits do not expire, and monthly credits roll over. Use the server quote for the actual submission and GET /v1/pricing for the published pricing schedule. As an illustrative calculation, a 12-page, 8 MB PDF processed under the file-work rate uses the larger of one started 25 MB unit and two started 10-page units: 4 credits. OCR TXT for 12 pages is 36 credits; Flow extraction is 300 credits. These are different outputs, not interchangeable prices for the same work. Confirm the selected job’s server quote rather than treating this illustration as a completed API test.

Make retries safe—and completion verifiable

A submission timeout creates uncertainty: your application may not know whether the server accepted the job. Persist the Idempotency-Key before submitting so an identical retry reuses the job instead of creating another submission. Changed parameters with the same key return 409. An intentional retry after terminal failure requires a new key. Treat completion webhooks as notifications that must be verified. Delivery is at least once, so duplicate events are possible. Verify the signature against the raw request body, perform the documented timestamp checks and deduplicate events before triggering downstream actions. Keep your own submission record with the operation, options, quote and resulting job identifier. That gives the application a clear basis for status checks and output handling when a network request is interrupted.

Finish with output validation, not just a successful status

Check limits before uploading: the total upload limit is 500 MB, PDFs are limited to 100 pages, and Transcribe or Meeting recordings to 10 hours. File Toolbox media has a separate two-hour maximum. Do not assume that every operation accepts the same source types or settings. After success, download outputs before the applicable retention period expires and store them according to your own retention requirements. Validate the result your downstream process actually needs. A successful job is not the same as an approved invoice record or a checked meeting decision. For Flow, review dates, totals and line items using the available evidence and warnings before export or downstream use. For Meeting, check decisions, action items and follow-up drafts before sharing them. The integration can reuse one lifecycle while preserving these task-specific review steps. For a first implementation, test one supported source end to end: obtain the quote, submit with idempotency, observe completion and download an authenticated result. Expand to additional operations only after checking their inputs and outputs against the contract. Start at https://www.skavio.eu/api/ to create a company API key and choose your first supported file.

Reuse the job lifecycle—not the assumption that every operation accepts the same input.

Sources

Open Skavio Processing API, create a company API key and test one supported file