> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textsetu.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Import source/translation files (write)

> Additive import of parsed files. With `?branch=`, values are staged on the branch (no approval workflow) and plural forms are flattened to their `other` form (branch values are single-string).

The request body is capped at 10 MB (`bodyLimit`); a larger payload is rejected with 413. Split the files across several calls.



## OpenAPI

````yaml /openapi/textsetu.json post /projects/{projectId}/sources
openapi: 3.1.0
info:
  title: TextSetu API
  version: 1.2.0
  description: >-
    Public REST API for TextSetu. Authenticate with a Personal Access Token
    (tsu_pat_…) or a project token (tsu_proj_…) via the `Authorization: Bearer
    <token>` header.


    **Authorization is permission-based.** Every token carries an explicit
    allow-list of RBAC permission keys (e.g. `translation_read`), and each
    endpoint declares the permission it requires (`x-permission`). A token's
    effective access is its underlying authority ∩ its allow-list — a PAT is
    further bounded by its owner's role-based permissions, so it can only
    narrow, never exceed, what the owner already has. A project token is bound
    to a single project. There are no coarse read/write/manage scopes.


    **Response envelope.** Every endpoint returns `{ "success": true, "data": …
    }` on success and `{ "success": false, "error": { "code", "message" } }` on
    failure.


    **Rate limit.** 600 requests/minute, keyed by token (or by IP when
    unauthenticated). Exceeding it returns 429 with the standard error envelope.
servers:
  - url: https://api.textsetu.com/api/v1
    description: Production
  - url: /api/v1
    description: This server (self-hosted / same-origin)
security:
  - bearerAuth: []
tags:
  - name: Projects
    description: >-
      Read project metadata — settings, key separator, and the
      approval/branching flags that shape how the other endpoints behave.
  - name: Languages
    description: >-
      List and manage a project's target languages. Each language is referenced
      by its BCP-47 code; the source language is flagged separately.
  - name: Translations
    description: >-
      Manage a project's translations: create, read, update, and delete
      translation keys — the identifiers your app looks up, carrying metadata
      (description, tags, screenshot) — and set the translated value for a key
      in a given language. Value writes honor the project's approval workflow —
      non-approver writes land as `pending_review`.
  - name: Stats
    description: >-
      Per-language completeness and approval progress for a project — the
      numbers behind the dashboard.
  - name: Import/Export
    description: >-
      Bulk-load source files into a project or export the current translations.
      Supports the same file formats as the web app.
  - name: Branches
    description: >-
      Work on translations in isolation and merge them back. Branch reads/writes
      mirror the main endpoints but stage changes as a diff until merge. See the
      [branching guide](/docs/guides/branches).
  - name: Glossary
    description: >-
      Manage term bases — approved terminology and its translations — and check
      a string against them. See the [glossary guide](/docs/guides/glossary).
  - name: Translation Memory
    description: >-
      Reusable translation stores. Fuzzy-match and concordance-search prior
      translations to reuse them. See the [translation memory
      guide](/docs/guides/translation-memory).
  - name: AI
    description: >-
      Machine-translate a project with the org's configured AI engine (brand
      voice, glossary/TM grounding, and an optional review pass). Runs
      asynchronously — start a run and poll the returned `jobId`.
  - name: Webhooks
    description: >-
      Get notified when a project's translations change, instead of polling.
      Register an HTTPS endpoint, subscribe it to the events you care about, and
      TextSetu POSTs a signed payload whenever one occurs. Payloads follow the
      [Standard Webhooks](https://www.standardwebhooks.com) spec — verify the
      `webhook-signature` header with any compatible library. Delivery is
      at-least-once and unordered, so treat `webhook-id` as an idempotency key.
      Failed deliveries are retried five times over roughly seven hours, and
      every attempt is inspectable and replayable via the delivery log.
  - name: Meta
    description: Service-level and cross-cutting endpoints.
paths:
  /projects/{projectId}/sources:
    post:
      tags:
        - Import/Export
      summary: Import source/translation files (write)
      description: >-
        Additive import of parsed files. With `?branch=`, values are staged on
        the branch (no approval workflow) and plural forms are flattened to
        their `other` form (branch values are single-string).


        The request body is capped at 10 MB (`bodyLimit`); a larger payload is
        rejected with 413. Split the files across several calls.
      parameters:
        - name: projectId
          in: path
          required: true
          schema:
            type: string
          description: Project id (UUID) or id-embedded path slug.
        - name: branch
          in: query
          schema:
            type: string
          description: >-
            Target an open translation branch instead of main. Required when the
            project's main branch is protected.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                format:
                  type: string
                  minLength: 1
                files:
                  minItems: 1
                  type: array
                  items:
                    type: object
                    properties:
                      path:
                        type: string
                        minLength: 1
                      languageCode:
                        type: string
                        minLength: 1
                      contentBase64:
                        type: string
                    required:
                      - path
                      - languageCode
                      - contentBase64
              required:
                - format
                - files
      responses:
        '200':
          description: Counts of what the import added, updated, and skipped.
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                  - data
                properties:
                  success:
                    type: boolean
                    const: true
                  data:
                    type: object
                    properties:
                      keysAdded:
                        type: integer
                        description: New keys created by this import.
                        examples:
                          - 12
                      valuesAdded:
                        type: integer
                        description: New translation values written.
                        examples:
                          - 40
                      valuesUpdated:
                        type: integer
                        description: Existing values overwritten with a new string.
                        examples:
                          - 8
                      valuesSkipped:
                        type: integer
                        description: >-
                          Values left unchanged (identical to what was already
                          stored).
                        examples:
                          - 3
                      valuesFailed:
                        description: >-
                          Values that could not be written (e.g. an unresolvable
                          language). 0 on the branch path.
                        examples:
                          - 0
                        type: integer
                      keysDeleted:
                        description: >-
                          Keys removed because they were absent from the import
                          (main imports only).
                        examples:
                          - 0
                        type: integer
                      valuesReverted:
                        description: >-
                          Branch overrides dropped because they converged back
                          onto main (branch imports only).
                        examples:
                          - 1
                        type: integer
                      branchId:
                        description: >-
                          The branch the import targeted, echoed back (present
                          only for branch imports).
                        examples:
                          - br_5c1a9e2f
                        type: string
                      pluralFormsFlattened:
                        description: >-
                          Plural maps collapsed to their `other` form because
                          branch values are single-string (branch imports only).
                        examples:
                          - 2
                        type: integer
                    required:
                      - keysAdded
                      - valuesAdded
                      - valuesUpdated
                      - valuesSkipped
                    additionalProperties: false
        '400':
          description: Invalid format / file / base64
        '403':
          description: Forbidden / main branch protected
        '404':
          description: Not found
        '413':
          description: Request body exceeds the 10 MB limit
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        API token: tsu_pat_… (PAT) or tsu_proj_… (project token). The token's
        granted RBAC permissions determine access; see each operation's
        `x-permission`.

````