Skip to main content
ExodeAPI is a typed HTTP client covering the /saas/v2/* endpoints. It is intended for the server (Node.js ≥ 18, uses the built-in fetch) and handles authentication, serialization of query parameters and the request body, unwrapping the response (payload) and error handling.
The full REST specification (request/response, error codes) is in the Exode API section. The SDK is a typed wrapper over the same contract; its types are inferred from the same server-side zod schemas.

Initialization

To connect, you need three values: an API token, sellerId and schoolId. All three are issued in the school account on the API keys page; the step-by-step process is described in Working with the API. The token’s permissions are configured there as well: each method requires its own permission (listed on the method’s page in the Exode API section).

Configuration parameters

number
required
Seller ID. Sent in the Seller-Id header.
number
required
School ID. Sent in the School-Id header.
string
required
API token of the service user. Sent in Authorization: Bearer <token>.
string
Base API URL. Defaults to https://api.exode.biz/saas/v2.
number
Request timeout in milliseconds. Defaults to 30000. When exceeded, an ExodeAPIError with cause: "Timeout" (code 408) is thrown.
Keep the token in environment variables. Never commit tokens or pass them to the client side: ExodeAPI works on the server only.

Available resources

The client exposes a school namespace with nine resources:

school.user

User CRUD, search, state, deletion, auth tokens.

school.staff

Org structure (HR): departments, positions, employments, managers, absences.

school.group

Lists of groups and members, bulk adding/removing members.

school.course

List of courses and members’ course progress.

school.certificate

List of issued certificates.

school.productAccess

List of product accesses.

school.invoice

List of invoices.

school.form

Form layouts and custom field values.

school.queryExport

Generating exports and polling their results.

Users (school.user)

For more on auto-login via ___uat, see Telegram Mini App integration.
In TypeScript, pass enum parameters (UserStatus, ProfileRole, CourseType, etc.) using the exported enums: they are string enums, and a string literal such as 'Active' will not pass type checking. In JavaScript you can pass strings directly: the values match the names (UserStatus.Active === 'Active').

Staff (school.staff)

The org structure for HR integrations (1C, HRM): departments, positions, employments, department managers and absences. Most methods have ...ByExtId variants for syncing by your external identifier. The methods are available only to schools in the corporate segment (Corporate).
The full list of methods and fields is in the Staff section of the Exode API.

Groups (school.group)

Courses (school.course)

Certificates (school.certificate)

Product accesses (school.productAccess)

Invoices (school.invoice)

Forms (school.form)

Exports (school.queryExport)

Exports run asynchronously: generation starts a workflow, and you poll for the result by UUID.

Execution statuses

generate is limited to 100 requests per hour. Report types and variables are described in Reports and exports.

Response typing

The types of all responses are inferred from the same server-side zod schemas (via z.infer) and can be imported (User, Profile, Session, Group, GroupMember, CourseProgress, FormLayout, FormFieldValue, as well as the *Output types). There is no runtime validation on the client side: contracts are already checked on the backend (@ZodResponse), so zod does not end up in the runtime bundle; the response is returned as is, strictly typed.

Error handling

All errors are wrapped in ExodeAPIError:
The full list of domain cause codes is in Working with the API.

Updated: 2026-09-25 14:33 UTC