본문 바로가기

API 문서

Smrt English Client API

학생과 클래스 기록을 기관의 시스템으로 제공하는 읽기 전용 API입니다. 각 API 키(API key)는 해당 기관의 데이터에만 접근할 수 있습니다.

테스트 허브 열기

작동 방식

요청 처리 방식

기관의 시스템이 자체 API 키로 학생이나 클래스 정보를 요청하면, API가 해당 기록을 읽기 전용으로 반환합니다.

기관 시스템기관의 학생 정보 시스템이나 리포트 도구입니다.
기관의 API 키모든 요청과 함께 전송되며, 해당 학교에 연결되어 있습니다.
Smrt English API학생과 클래스 정보를 위한 읽기 전용 엔드포인트입니다.
기관의 기록성적, 출결, 클래스 명단을 JSON으로 제공합니다.
keyboard_arrow_up

Smrt English API

security Security & Permissions

Institutional Data Isolation

The API enforces strict institutional-level security:

  • Single Institution Access: Your API key only accesses data for students enrolled at your institution
  • Automatic Filtering: All database queries automatically filter by institution
  • Cross-Institution Protection: Attempts to access other institutions' data return 404 (Not Found)
  • Privacy Guarantee: Complete data separation between institutions

Data Access Rules

  1. Student Lookup: Only students enrolled at your institution can be retrieved
  2. Class Lookup: Only classes from your institution can be retrieved
  3. Email Matching: Email lookups are restricted to your institution's students and teachers
  4. Course Data: Only shows courses/classes where your students are enrolled
  5. Assignment Data: Only completed assignments are included in responses
  6. Assessment Data: Only assessments the student has taken are returned

Best Security Practices

1. Protect Your API Key

  • Never commit API keys to version control or share in public forums
  • Don't expose keys in client-side JavaScript or mobile apps
  • Use environment variables or secure configuration management
  • Store keys securely with appropriate access controls
  • If you believe your key has been compromised, contact Smrt English immediately

2. Use HTTPS

  • Always use HTTPS in production environments
  • Never send API keys over unencrypted connections
  • Verify SSL certificates to prevent man-in-the-middle attacks

3. Rate Limiting

  • Be respectful of API resources
  • Implement caching on your side when appropriate
  • Avoid unnecessary repeated requests for the same data
  • Contact Smrt English if you need high-volume access

4. Error Handling

  • Don't expose API keys in error messages or logs
  • Log errors securely on your server
  • Handle authentication failures gracefully
  • Implement appropriate retry logic with exponential backoff

5. Access Control Within Your Institution

  • Limit which systems and personnel can use the API key
  • Monitor API usage for suspicious activity
  • Implement appropriate logging and auditing on your side
  • Report any security concerns to Smrt English immediately