Version 1.0.1
The sandbox is live and the contract names it as a second server, and the panel now requires students to confirm their email address. No operation, field or error code changes.
Added
- The contract's server list names the sandbox,
https://apisnd.main-team.org, after production, markedx-environment: sandbox. Production stays the first entry, so a tool that takes the first server still calls production. No operation changes.
Changed
- The sandbox is live at
https://apisnd.main-team.org/v1. It runs the same release as production, with separate accounts issued by an operator, seeded reference data with production's organization ids, no emails and test-mode payments. Registration is open there, with the same permissions and rate limits as in production. The official client libraries accept only the production base URL, so call the sandbox over HTTPS directly. The "Try it" console on the reference pages works against the sandbox with a token you paste. Students pay in the sandbox's panels with Stripe's test cards, such as 4242 4242 4242 4242; the Environments page lists them. Test cards never work in production. createSigninLink: a student whose email address is not confirmed must now confirm it before they can use the panel, My Exams included, so they confirm before they can start an exam. The panel asks for a 6-digit code on every page until the address is confirmed, and the student can no longer put it off; signing out is the only way out. A student already inside an exam room is not interrupted. Only the confirmation on the student's core record counts. A code is valid for 15 minutes, and a new one can be requested after 60 seconds. The sandbox sends no emails, so its panels don't ask. Have your students confirm well before an exam day, for example right after their first sign-in. The request, its answers and the link are unchanged.- Documentation corrections: the pages that called the sandbox planned now describe it as it runs, and every page that called the panel's email confirmation prompt optional now describes it as required. The pages no longer write a current version number into their text: the API reference shows the version they describe, and the changelog lists every version.
Release notes
Version 1.0.1 changes no operation, request field, response field or error code, so code written against 1.0.0 keeps working without a change. It opens the sandbox, names the sandbox in the contract, and changes one thing your students see in the panel.
The sandbox is live
The sandbox runs at https://apisnd.main-team.org/v1, on the same release of the API as production. It has its own accounts, issued by an operator (ask at info@main-team.org), seeded reference data with production's organization ids, and no real students. Registration is open there, with the same permissions and rate limits as in production. See Environments.
- Sign-in links you mint there open on
authsnd.main-team.org, and your students land on the organization's sandbox panel, never on production's. A sandbox panel is atsnd.<brand>.orgwhere production's ismy.<brand>.org, for examplesnd.stemolympiad.org. - No email is ever sent, so the sandbox's panels don't ask students to confirm their address.
- The data may be reset, and we tell you in advance. The sandbox has no availability guarantee.
- The official client libraries accept only the production base URL, so call the sandbox over HTTPS directly.
The "Try it" console on the reference pages works against the sandbox. Sign a token with your sandbox apiKey and apiSecret on your own machine and paste the token. Never paste your apiSecret.
Test payments with Stripe's test cards
The API never charges anyone: students pay in the panel. The sandbox's panels take payments through Stripe in test mode, so no real money moves, and you pay with Stripe's test cards:
| Card number | Result |
|---|---|
4242 4242 4242 4242 | Succeeds without authentication |
4000 0025 0000 3155 | Asks for 3D Secure authentication |
4000 0000 0000 9995 | Declined for insufficient funds |
Use any future expiry date, any 3-digit CVC and any postal code. See Test payments. In production only real cards work: never use a test card there.
The sandbox in the contract
The contract now lists the sandbox as a second server, after production:
"servers": [
{ "url": "https://api.main-team.org", "x-environment": "production" },
{
"url": "https://apisnd.main-team.org",
"x-environment": "sandbox",
"description": "Sandbox: separate accounts and data; no e-mail; Stripe test mode"
}
]
Production stays the first entry, so a tool that takes the first server still calls production. To point a generated client at the sandbox, choose the server whose x-environment is sandbox, or set the base URL yourself. The paths carry /v1, so each server is a bare origin.
Students confirm their email address in the panel
A student whose email address isn't confirmed must now confirm it before they can use the panel. The panel asks for a 6-digit code on every page until the address is confirmed, and the student can no longer put it off. My Exams is covered too, so a student must confirm before they can start an exam. A student already inside an exam room is not interrupted. Signing out is the only way out of the prompt. Only the confirmation on the student's core record counts. A code is valid for 15 minutes, and a new one can be requested after 60 seconds. The sandbox sends no email, so its panels don't ask.
createSigninLink itself is unchanged: the request, its answers and the link are the same, and a student with an unconfirmed address still gets a link. Register an address the student reads, and tell your students before their first sign-in that they will need to reach their mailbox. Have them confirm well before an exam day, for example right after their first sign-in. See Email confirmation.
Documentation corrections
- Pages that called the sandbox planned now describe it as it runs.
- Pages that called the panel's email confirmation optional now describe it as required.
- The pages no longer write a current version number into their text. The API reference shows the version they describe, and the changelog lists every version.