Annotation Result Callback
Update:
Receive annotation changes from the console.
POSTcallbackUrl
Configure the receiving URL in Console → Service Configuration → Manual Annotation → Callback URL.
Request Parameters
Request Headers
All headers below are required.
Header
Value
Description
Content-Type
application/json; charset=UTF-8
Request body format
Accept
application/json; charset=UTF-8
Response format
X-AppId
—
Project ID from Console → Service Configuration
X-TimeStamp
—
UTC time when the callback is sent, in W3C format.
Format example: 2026-09-30T02:30:00Z. This example illustrates the format only.
Authorization
—
See Callback Signature below
Request Body
Parameter
Type
Required
Description
appId
String
Required
Project Number
textData
Array
Required
Original Data
markData
Object
Required
Modify Data
markTag is deprecated. Use markTags for the latest category list; markResult is the latest moderation result.
Request Example
{
"appId": "",
"textData": [
{
"taskId": "",
"strategyId": "",
"language": "",
"stext": "",
"word": "",
"userId": "",
"result": "",
"tag": "",
"subTag": ""
}
],
"markData": {
"markResult": "",
"markTag": "",
"markTags": ""
}
}
Callback Signature
Verify the Authorization header with the callback signature below. It signs the full CallbackUrl, rather than separate host and path values.
Signing Parameter
Value
HTTPMethod
POST
CallbackUrl
Configured callback URL
- Hash the UTF-8 request body with SHA256 and convert the digest to hexadecimal.
- Build
StringToSign as shown below.
- Compute HMAC-SHA256 using
secretKey, encode the result with Base64, and compare it with Authorization.
CanonicalizedQueryString = hex(sha256(jsonBody))
StringToSign = HTTPMethod + "\n" +
CallbackUrl + "\n" +
CanonicalizedQueryString + "\n" +
"X-AppId:" + SAME_APPID_IN_HEADER + "\n" +
"X-TimeStamp:" + SAME_TIMESTAMP_IN_HEADER
Receive annotation changes from the console.
POST
callbackUrlConfigure the receiving URL in Console → Service Configuration → Manual Annotation → Callback URL.
Request Parameters
Request Headers
All headers below are required.
| Header | Value | Description |
|---|---|---|
Content-Type |
application/json; charset=UTF-8 |
Request body format |
Accept |
application/json; charset=UTF-8 |
Response format |
X-AppId |
— | Project ID from Console → Service Configuration |
X-TimeStamp |
— | UTC time when the callback is sent, in W3C format. Format example: 2026-09-30T02:30:00Z. This example illustrates the format only. |
Authorization |
— | See Callback Signature below |
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
appId |
String |
Required | Project Number |
textData |
Array |
Required | Original Data |
markData |
Object |
Required | Modify Data |
markTag is deprecated. Use markTags for the latest category list; markResult is the latest moderation result.
Request Example
{
"appId": "",
"textData": [
{
"taskId": "",
"strategyId": "",
"language": "",
"stext": "",
"word": "",
"userId": "",
"result": "",
"tag": "",
"subTag": ""
}
],
"markData": {
"markResult": "",
"markTag": "",
"markTags": ""
}
}
Callback Signature
Verify the Authorization header with the callback signature below. It signs the full CallbackUrl, rather than separate host and path values.
| Signing Parameter | Value |
|---|---|
HTTPMethod |
POST |
CallbackUrl |
Configured callback URL |
- Hash the UTF-8 request body with SHA256 and convert the digest to hexadecimal.
- Build
StringToSignas shown below. - Compute HMAC-SHA256 using
secretKey, encode the result with Base64, and compare it withAuthorization.
CanonicalizedQueryString = hex(sha256(jsonBody))
StringToSign = HTTPMethod + "\n" +
CallbackUrl + "\n" +
CanonicalizedQueryString + "\n" +
"X-AppId:" + SAME_APPID_IN_HEADER + "\n" +
"X-TimeStamp:" + SAME_TIMESTAMP_IN_HEADER