API 문서
Smrt English Client API
학생과 클래스 기록을 기관의 시스템으로 제공하는 읽기 전용 API입니다. 각 API 키(API key)는 해당 기관의 데이터에만 접근할 수 있습니다.
작동 방식
요청 처리 방식
기관의 시스템이 자체 API 키로 학생이나 클래스 정보를 요청하면, API가 해당 기록을 읽기 전용으로 반환합니다.
dns기관 시스템기관의 학생 정보 시스템이나 리포트 도구입니다.
arrow_forwardkey기관의 API 키모든 요청과 함께 전송되며, 해당 학교에 연결되어 있습니다.
arrow_forwardapiSmrt English API학생과 클래스 정보를 위한 읽기 전용 엔드포인트입니다.
arrow_forwardtable_view기관의 기록성적, 출결, 클래스 명단을 JSON으로 제공합니다.
Smrt English API
Security & Permissions
Institutional Data Isolation
The API enforces strict institutional-level security:
- Single Institution Access: Your API key only accesses data for students enrolled at your institution
- Automatic Filtering: All database queries automatically filter by institution
- Cross-Institution Protection: Attempts to access other institutions' data return 404 (Not Found)
- Privacy Guarantee: Complete data separation between institutions
Data Access Rules
- Student Lookup: Only students enrolled at your institution can be retrieved
- Class Lookup: Only classes from your institution can be retrieved
- Email Matching: Email lookups are restricted to your institution's students and teachers
- Course Data: Only shows courses/classes where your students are enrolled
- Assignment Data: Only completed assignments are included in responses
- Assessment Data: Only assessments the student has taken are returned
Best Security Practices
1. Protect Your API Key
- Never commit API keys to version control or share in public forums
- Don't expose keys in client-side JavaScript or mobile apps
- Use environment variables or secure configuration management
- Store keys securely with appropriate access controls
- If you believe your key has been compromised, contact Smrt English immediately
2. Use HTTPS
- Always use HTTPS in production environments
- Never send API keys over unencrypted connections
- Verify SSL certificates to prevent man-in-the-middle attacks
3. Rate Limiting
- Be respectful of API resources
- Implement caching on your side when appropriate
- Avoid unnecessary repeated requests for the same data
- Contact Smrt English if you need high-volume access
4. Error Handling
- Don't expose API keys in error messages or logs
- Log errors securely on your server
- Handle authentication failures gracefully
- Implement appropriate retry logic with exponential backoff
5. Access Control Within Your Institution
- Limit which systems and personnel can use the API key
- Monitor API usage for suspicious activity
- Implement appropriate logging and auditing on your side
- Report any security concerns to Smrt English immediately