Server-to-server API guide.

JATS Verify API v1

From payment to your first request.

Every paid option includes a server-to-server API key and the package credits purchased. Credits remain valid for 12 months. This guide covers the complete path, including key recovery and usage checks.

Generate a client or inspect the request schema with the OpenAPI 3.1 document.

01 / GET A KEY

How API access is issued.

  1. Choose your package credits.Buy one complete check for $12.99, 100 team credits for $149, or 1,000 API credits for $499.
  2. Open the automatic JATS Verify email.It contains a secure Access Center link and your jv_live_… API key.
  3. Recover it whenever needed.Use the Access Center with the same checkout email. No password is required.

Access is automatic. There is no application, approval step, or separate developer account.

02 / GITHUB ACTION

Add the release gate without installing an engine.

The public JATS Verify API Action sends the selected package directly from a GitHub runner to the private API and writes the returned JSON evidence into the workflow workspace.

- uses: james-hr/jats-verify@v1
  with:
    api-key: ${{ secrets.JATS_VERIFY_API_KEY }}
    xml: production/article.xml
    assets-zip: production/assets.zip
    report: jats-verify-report.json

Store the key as a GitHub Actions secret. The action fails the job when the configured release gate fails.

03 / AUTHENTICATE

Send the key in a request header.

Use either X-API-Key or a Bearer token. Do not put the key in a URL, browser storage, repository, log, or client-side application.

Base URL: https://jatsverify.com/api/v1

X-API-Key: jv_live_your_key_here

This API is intended for your server, CI job, or private command line. Cross-origin browser access is not enabled.

04 / CHECK USAGE

Confirm the key before uploading.

curl --fail-with-body \
  https://jatsverify.com/api/v1/access/me \
  -H "X-API-Key: $JATS_VERIFY_API_KEY"

The JSON response includes expires_at, seconds_remaining, package_limit, packages_used, and packages_remaining. Times are Unix seconds in UTC.

{
  "status": "active",
  "expires_at": 1788048000,
  "seconds_remaining": 863400,
  "package_limit": 100,
  "packages_used": 2,
  "packages_remaining": 98
}

05 / INSPECT XML

Return a JSON evidence report.

curl --fail-with-body \
  https://jatsverify.com/api/v1/inspect \
  -H "X-API-Key: $JATS_VERIFY_API_KEY" \
  -H "Accept: application/json" \
  -F "[email protected];type=application/xml" \
  -F "[email protected];type=application/zip" \
  -F "fail_on=error" \
  -o evidence.json

Only xml is required. The response contains the pass or fail decision, finding counts, ordered findings, article summary, asset evidence, canonical SHA-256, and registry-check status.

06 / BUILD BUNDLE

Return a reproducible release ZIP.

curl --fail-with-body \
  https://jatsverify.com/api/v1/bundle \
  -H "X-API-Key: $JATS_VERIFY_API_KEY" \
  -H "Accept: application/zip" \
  -F "[email protected];type=application/xml" \
  -F "[email protected];type=application/xml" \
  -F "[email protected];type=application/json" \
  -o jats-release.zip

The ZIP contains the submitted XML, included assets, evidence.json, and manifest-sha256.txt. Download results in the same request because JATS Verify does not keep customer package copies for later retrieval.

REQUEST FIELDS

Multipart form fields.

FieldRequiredLimitPurpose
xmlYes10 MiBCurrent JATS XML document.
assets_zipNo25 MiB compressedFigures and other locally referenced files.
baselineNo10 MiBPrevious XML version for semantic comparison. Paid only.
profileNo256 KiBJournal-specific JSON rules. Paid only. Download a sample.
fail_onNoOne valueerror, warning, or info. Default: error.

07 / LIMITS

Bounded, predictable processing.

  • Paid access accepts the purchased number of unique canonical packages during its 12-month validity, from 1 to 1,000.
  • Rechecking the same canonical XML does not use another package slot.
  • An assets ZIP may contain up to 100 files and 100 MiB uncompressed. Unsafe paths, links, encrypted entries, duplicates, and extreme compression ratios are rejected.
  • Requests are synchronous. Keep the connection open until the report or ZIP is returned.
  • The service makes no external DOI, PMID, ORCID, or other registry calls.

08 / ERRORS

Actionable HTTP responses.

StatusMeaningNext action
400Malformed XML, ZIP, profile, or request.Read the JSON detail and correct the input.
401API key is missing, invalid, or expired.Recover the current key in the Access Center.
413A request or file exceeds a documented limit.Reduce or split the package.
422A form value is invalid.Check field names and fail_on.
429The purchased unique-package allowance is used.Purchase another credit pack or contact JATS Verify for custom volume.
503Access fulfillment or email is temporarily unavailable.Retry later or email support.

Every response includes an X-Request-ID. Include that value when contacting [email protected].