Tài liệu API
Smrt English Client API
API chỉ đọc, trả dữ liệu học viên và lớp học về hệ thống của đơn vị. Mỗi khóa API (API key) chỉ truy cập được dữ liệu của chính đơn vị sở hữu khóa đó.
Cách thức hoạt động
Cách một yêu cầu được xử lý.
Hệ thống của đơn vị gửi yêu cầu lấy dữ liệu một học viên hoặc một lớp kèm khóa API riêng, và API trả về dữ liệu ở chế độ chỉ đọc.
dnsHệ thống của đơn vịPhần mềm quản lý học viên hoặc công cụ báo cáo của đơn vị.
arrow_forwardkeyKhóa API của đơn vịĐược gửi kèm mọi yêu cầu và gắn với đơn vị.
arrow_forwardapiSmrt English APICác endpoint chỉ đọc cho học viên và lớp học.
arrow_forwardtable_viewDữ liệu của đơn vịĐiểm, điểm danh và danh sách lớp ở định dạng JSON.
Smrt English API
Security & Permissions
Institutional Data Isolation
The API enforces strict institutional-level security:
- Single Institution Access: Your API key only accesses data for students enrolled at your institution
- Automatic Filtering: All database queries automatically filter by institution
- Cross-Institution Protection: Attempts to access other institutions' data return 404 (Not Found)
- Privacy Guarantee: Complete data separation between institutions
Data Access Rules
- Student Lookup: Only students enrolled at your institution can be retrieved
- Class Lookup: Only classes from your institution can be retrieved
- Email Matching: Email lookups are restricted to your institution's students and teachers
- Course Data: Only shows courses/classes where your students are enrolled
- Assignment Data: Only completed assignments are included in responses
- Assessment Data: Only assessments the student has taken are returned
Best Security Practices
1. Protect Your API Key
- Never commit API keys to version control or share in public forums
- Don't expose keys in client-side JavaScript or mobile apps
- Use environment variables or secure configuration management
- Store keys securely with appropriate access controls
- If you believe your key has been compromised, contact Smrt English immediately
2. Use HTTPS
- Always use HTTPS in production environments
- Never send API keys over unencrypted connections
- Verify SSL certificates to prevent man-in-the-middle attacks
3. Rate Limiting
- Be respectful of API resources
- Implement caching on your side when appropriate
- Avoid unnecessary repeated requests for the same data
- Contact Smrt English if you need high-volume access
4. Error Handling
- Don't expose API keys in error messages or logs
- Log errors securely on your server
- Handle authentication failures gracefully
- Implement appropriate retry logic with exponential backoff
5. Access Control Within Your Institution
- Limit which systems and personnel can use the API key
- Monitor API usage for suspicious activity
- Implement appropriate logging and auditing on your side
- Report any security concerns to Smrt English immediately