https://your-school.exode.biz/your-slug) and embeds a mini app in an iframe: a website or
web application hosted anywhere (Vercel, your own server, etc.).
The mini app receives signed user data from the platform (Init Data),
can verify it on its backend and build any logic, from a landing page to a full-fledged
service with its own database.
Creating a page
- Open Control Panel → School → Customization → Apps & pages.
- Click Create app and fill in:
- Title: shown in the header and the menu (in the school’s languages);
- App address (slug): lowercase Latin letters, digits and hyphens, 2–64 characters.
The page opens at
/<slug>. The platform’s system addresses are reserved; - App URL (iframe): the https address of your mini app (it opens in an iframe);
- Window type: how the app is shown to the user (see below);
- Layout: only for the Page type: Full width or Island (a card with margins);
- Available without login: whether to show the page to unauthenticated visitors. Such a visitor also
receives signed Init Data, but without user data (
user=null).
- After creating the page, open the page menu ”⋯” → Show secret. Your server needs this secret to verify Init Data. Keep it on the server only. The same menu has Regenerate secret: the old secret stops working immediately.
Pages can be created and edited by a manager with the “Apps & Pages Management” permission (
SchoolManagePages).The mini app’s website must allow embedding in an iframe: do not send the
X-Frame-Options header, and if
you use Content-Security-Policy: frame-ancestors, include the school’s domain in it.Window type
At most one window can be expanded at a time: opening a second one minimizes the first.
Minimized windows collect in a tray and expand with a single click.
On a phone, every window type opens as a regular page.
Page parameters
The page address parameters are passed to the iframe as a query string: the link/<slug>?courseId=5 opens the
app at https://<your-app>/…?courseId=5#exodeInitData=…. If the app URL already has its own query, the parameters
are appended to it, and Init Data still arrives in the hash. The platform’s service parameters (modal, popup,
appId) are not passed to the iframe.
This works for every window type. If the app is already open and gets opened with different parameters (for
example, to continue working on another course), the iframe reloads with the new address; with the same
parameters the window just expands.
A window restored after the platform reloads opens without parameters.
School home page
In the page list, you can set a main page: the selected page (system or custom) opens at/. A custom page set as the main page cannot be deleted or
turned off; set another main page first.
iframe lifecycle
An open app page is not unloaded when navigating around the platform: the iframe loads once and stays in memory, so reopening it is instant. The same goes for a minimized window: minimizing does not reload the app, and its state is preserved. Two commands are available from the mini app itself (MiniApp SDK):app.ui.minimize(): minimize the window (does nothing for the Page type, since there is nothing to minimize);app.ui.close(): close the app and unload the iframe.
The platform keeps a limited number of apps in memory and unloads the oldest
inactive ones. Do not rely on state surviving a close; save important data
on your server.
What’s next
- Introduction to MiniApp SDK: the bridge, context, commands and events;
- Init Data: verifying signed data on your server.
Updated: 2026-09-28 05:04 UTC