Integrations for your app backend
Any backend that speaks HTTPS can connect to Limenia. For common platforms there are connectors that enforce bans directly, and runnable examples.
Six events, signed with HMAC-SHA256
Limenia sends every event via POST to your backend, signed and with retries over about 20 hours. Every attempt is in the delivery log.
- decision.created: a decision with its statement of reasons
- subject.status_changed: a temporary suspension has ended
- reports.resolved: the outcome for the reporters
- appeal.resolved: an appeal has been decided
- review.decided: a review has been decided
- test.ping: the test from the dashboard
Runnable examples for your backend
Each example shows the same paths: send a report, query a status, check a device and receive webhooks with signature verification.
- Node.js (Express)
- Python (FastAPI)
- Go
- PHP (Laravel)
- AWS Lambda
- Supabase Edge Functions
- Firebase Cloud Functions
Frequently asked questions
Your question is not here? Write to us, a person will answer.
[email protected]Do I need a connector?
No. The signed webhook covers every decision. A connector is worth it if bans should take effect directly in Firebase Authentication, Supabase Auth or RevenueCat, even while your webhook receiver is down.
Can I use Limenia without a backend of my own?
No. The API key belongs in a backend, never in a mobile or web app. A Cloud Function or an Edge Function is enough.
How do I verify a webhook signature?
Compute HMAC-SHA256 with your webhook secret over the timestamp and the raw body and compare in constant time. Reject the request if the timestamp is more than 300 seconds off. The examples on GitHub show this for every backend.
Ready for your notice and action process?
We show you Limenia with an example and work out what your app needs for the DSA and the app stores.
Or email us directly: [email protected]