Skip to main content

Request headers

string
required
The service user’s API token in the Bearer YOUR_TOKEN format. The school owner issues the token in the admin panel: Manage → School → For developers → API keys — see the “Authentication” section for details.
integer
required
The numeric ID of the seller — the account the school belongs to. Copy it on the API keys page, in the Integration data → Identifiers card. The token’s permissions are checked against this ID.
integer
required
The numeric ID of the school, found in the same place as Seller-Id. The value must match the seller’s school — otherwise a 400 error with cause: "ForbiddenSchoolMismatch" is returned.
Requires authentication and the “School User Management” permission (SchoolManageUsers).

Request parameters

integer
required
The user’s numeric ID in Exode (the id field from user/find, user/create or user/upsert). The user must belong to the school from the School-Id header; otherwise you get 401 with cause: "Forbidden" and the message seller not entity owner.
boolean
default:"false"
Force creation of a new session. If true, a new session is always created, even if the user already has an active one. If false or omitted, the existing active session is returned (or a new one is created if none exists).
The method creates a new session for the user or returns the existing active session. The session token is used to authenticate the user in the system. The isCreated flag in the response indicates whether a new session was created or an existing one was returned.
For users who have at least one permission in the admin panel (administrators, managers, employees with management access), this method does not issue a token: it returns a Forbidden error with the message User is school admin or manager. The method is intended for students.
The token grants full sign-in to the user’s account and is valid for a long time (see expireAt). Do not store it in logs, transmit it only over HTTPS, and do not publish links containing it. forceCreate: true creates a new session on every call without ending the previous ones, so do not use it on every sign-in unless necessary.

Response parameters

object
required
The user session object; the full structure is described in the session reference.
boolean
required
Indicates whether a new session was created. true: a session was created; false: the existing active session was returned.

Permission requirements

Creating a user session token requires the “School User Management” permission (SchoolManageUsers).
The service user must be authenticated with a token and have the appropriate access permissions for the specified school.

Using the token

The session token has a limited validity period (usually 2 years). After it expires, you need to create a new session for the user.
Automatic user sign-in:To sign the user in to the app automatically, use the ___uat GET parameter in the URL:
Where TOKEN_FROM_SESSION is the value of the token field from this API method’s response.
The user will be signed in automatically when following such a link.

Updated: 2026-09-25 14:33 UTC