Перейти до вмісту

Документація API

Клієнтський API Smrt English

API лише для читання, який передає дані учнів і груп у системи вашого закладу. Кожен API-ключ (API key) дає доступ лише до даних свого закладу.

Відкрити центр тестування

Як це працює

Як виконується запит

Ваша система запитує дані учня або групи за власним API-ключем, а API повертає записи лише для читання.

Ваша системаВаша система обліку учнів або інструмент звітності.
Ваш API-ключНадсилається з кожним запитом і прив’язаний до вашого закладу.
API Smrt EnglishЕндпоінти (кінцеві точки) для учнів і груп, лише для читання.
Ваші даніОцінки, відвідуваність і списки груп у форматі JSON.
keyboard_arrow_up

Smrt English API

security Security & Permissions

Institutional Data Isolation

The API enforces strict institutional-level security:

  • Single Institution Access: Your API key only accesses data for students enrolled at your institution
  • Automatic Filtering: All database queries automatically filter by institution
  • Cross-Institution Protection: Attempts to access other institutions' data return 404 (Not Found)
  • Privacy Guarantee: Complete data separation between institutions

Data Access Rules

  1. Student Lookup: Only students enrolled at your institution can be retrieved
  2. Class Lookup: Only classes from your institution can be retrieved
  3. Email Matching: Email lookups are restricted to your institution's students and teachers
  4. Course Data: Only shows courses/classes where your students are enrolled
  5. Assignment Data: Only completed assignments are included in responses
  6. Assessment Data: Only assessments the student has taken are returned

Best Security Practices

1. Protect Your API Key

  • Never commit API keys to version control or share in public forums
  • Don't expose keys in client-side JavaScript or mobile apps
  • Use environment variables or secure configuration management
  • Store keys securely with appropriate access controls
  • If you believe your key has been compromised, contact Smrt English immediately

2. Use HTTPS

  • Always use HTTPS in production environments
  • Never send API keys over unencrypted connections
  • Verify SSL certificates to prevent man-in-the-middle attacks

3. Rate Limiting

  • Be respectful of API resources
  • Implement caching on your side when appropriate
  • Avoid unnecessary repeated requests for the same data
  • Contact Smrt English if you need high-volume access

4. Error Handling

  • Don't expose API keys in error messages or logs
  • Log errors securely on your server
  • Handle authentication failures gracefully
  • Implement appropriate retry logic with exponential backoff

5. Access Control Within Your Institution

  • Limit which systems and personnel can use the API key
  • Monitor API usage for suspicious activity
  • Implement appropriate logging and auditing on your side
  • Report any security concerns to Smrt English immediately