ExodeAPI is a typed HTTP client covering the /saas/v2/* endpoints. It is intended for the server (Node.js ≥ 18,
uses the built-in fetch) and handles authentication, serialization of query parameters and the request body, unwrapping
the response (payload) and error handling.
The full REST specification (request/response, error codes) is in the Exode API section.
The SDK is a typed wrapper over the same contract; its types are inferred from the same server-side zod schemas.
Initialization
To connect, you need three values: an API token,sellerId and schoolId. All three are issued in the school account on
the API keys page; the step-by-step process is described in Working with the API. The token’s
permissions are configured there as well: each method requires its own permission (listed on the method’s page in the Exode API section).
Configuration parameters
number
required
Seller ID. Sent in the
Seller-Id header.number
required
School ID. Sent in the
School-Id header.string
required
API token of the service user. Sent in
Authorization: Bearer <token>.string
Base API URL. Defaults to
https://api.exode.biz/saas/v2.number
Request timeout in milliseconds. Defaults to
30000. When exceeded, an ExodeAPIError with cause: "Timeout" (code 408) is thrown.Available resources
The client exposes aschool namespace with nine resources:
school.user
User CRUD, search, state, deletion, auth tokens.
school.staff
Org structure (HR): departments, positions, employments, managers, absences.
school.group
Lists of groups and members, bulk adding/removing members.
school.course
List of courses and members’ course progress.
school.certificate
List of issued certificates.
school.productAccess
List of product accesses.
school.invoice
List of invoices.
school.form
Form layouts and custom field values.
school.queryExport
Generating exports and polling their results.
Users (school.user)
In TypeScript, pass enum parameters (
UserStatus, ProfileRole, CourseType, etc.) using the
exported enums: they are string enums, and a string literal such as 'Active' will not pass type checking.
In JavaScript you can pass strings directly: the values match the names (UserStatus.Active === 'Active').Staff (school.staff)
The org structure for HR integrations (1C, HRM): departments, positions, employments, department managers
and absences. Most methods have ...ByExtId variants for syncing by your external identifier.
The methods are available only to schools in the corporate segment (Corporate).
Groups (school.group)
Courses (school.course)
Certificates (school.certificate)
Product accesses (school.productAccess)
Invoices (school.invoice)
Forms (school.form)
Exports (school.queryExport)
Exports run asynchronously: generation starts a workflow, and you poll for the result by UUID.
Execution statuses
generate is limited to 100 requests per hour. Report types and variables are described in
Reports and exports.Response typing
The types of all responses are inferred from the same server-side zod schemas (viaz.infer) and can be imported
(User, Profile, Session, Group, GroupMember, CourseProgress, FormLayout, FormFieldValue,
as well as the *Output types). There is no runtime validation on the client side: contracts are already checked on the backend
(@ZodResponse), so zod does not end up in the runtime bundle; the response is returned as is, strictly typed.
Error handling
All errors are wrapped inExodeAPIError:
The full list of domain
cause codes is in Working with the API.Updated: 2026-09-25 14:33 UTC