Skip to main content

Request headers

string
required
The service user’s API token in the Bearer YOUR_TOKEN format. The school owner issues the token in the admin panel: Manage → School → For developers → API keys — see the “Authentication” section for details.
integer
required
The numeric ID of the seller — the account the school belongs to. Copy it on the API keys page, in the Integration data → Identifiers card. The token’s permissions are checked against this ID.
integer
required
The numeric ID of the school, found in the same place as Seller-Id. The value must match the seller’s school — otherwise a 400 error with cause: "ForbiddenSchoolMismatch" is returned.
User states are key-value records in the database linked to a specific user. Reading and writing are available only for a limited list of keys (whitelist). Some keys are masked on read.The endpoints below work in the school context and require the school user management permission.Setting a value via PUT fully replaces the key’s previous value. There are no partial updates (merge).

Supported keys

  • Type: object.
  • GET/SET: yes/yes.
  • Masking: no.
  • Purpose: UTM/referral parameters of the first visit/sign-up.
  • UtmSignupParams is stored as an object of arbitrary string key-value pairs (for example, utm_source, utm_medium, fbclid).
Success (GET UtmSignupParams)
Body (SET UtmSignupParams)
  • Type: boolean.
  • GET/SET: yes/yes.
  • Masking: no.
  • Purpose: flag indicating that personal information has been filled in.
  • PersonalInfoFilled is a boolean true / false value indicating whether personal information has been filled in.
Success (GET PersonalInfoFilled)
Body (SET PersonalInfoFilled)
  • Type: object.
  • GET/SET: yes/yes.
  • Masking: no.
  • Purpose: the user’s onboarding progress.
Body (SET OnBoardingProgress)
  • Type: array.
  • GET/SET: yes/yes.
  • Masking: no.
  • Purpose: content categories selected by the user (an array of IDs).
Body (SET ContentCategoryIds)
Writing (SET) is allowed only for the keys UtmSignupParams, PersonalInfoFilled, OnBoardingProgress, ContentCategoryIds. Reading (GET) is additionally available for VkToken (returned masked). A request for a key outside this list returns a 400 error with cause: "Unauthorized" and the message Not allowed key <key> — this is a key restriction, not a token problem. A non-existent key name is rejected by validation (400).

Get a state by key

GET /saas/v2/user/:userId/state/get?key=PersonalInfoFilled

Parameters

integer
required
The user’s numeric ID in Exode (the id field from user/find or user/list). The user must belong to the school from the School-Id header.
string
required
State key — one of the values from the list above, case-sensitive.

Response

any
required
The state value. If no value has been written for the key yet, null.

Set a state by key

PUT /saas/v2/user/:userId/state/set?key=PersonalInfoFilled

Parameters

integer
required
The user’s numeric ID in Exode (the id field from user/find or user/list). The user must belong to the school from the School-Id header.
string
required
State key — one of the values from the list above, case-sensitive.
any
required
The value to write to the state. Its type depends on the key.

Response

boolean
required
Flag indicating that the state was written successfully.

Permission requirements

Requires token authentication and the “School User Management” permission (SchoolManageUsers).

Updated: 2026-09-25 14:33 UTC