Examplary
  • Start for free
    Developer docs

    Developer changelog

    Changes to the API, SDKs, embeds, and question type platform, in chronological order.

    1. The API is stricter about CORS

      The API used to reflect any origin back in its CORS headers. It now only does that for first-party Examplary origins and an organization's own active custom domain.

      If you were calling the API straight from browser JavaScript on your own domain, those requests will start failing. Server-to-server calls aren't affected — CORS is a browser-only restriction, so anything running on your backend carries on as before. If you need something in the browser, Embed Sessions are built for exactly that.

      LTI, OAuth and the public endpoints stay open, since they're meant to be called from places we don't control.

    2. Rate limits are now written down

      Most API endpoints are rate limited, per user or per IP address depending on the endpoint. That's been true for a while — you just had to find out by running into one.

      Every endpoint reference page now has a Rate limit section with its own limit, and there's a summary on the REST API overview. Go over it and you'll get a 429 with a Retry-After header telling you how long to wait.

      We also tightened the limits on the AI and email endpoints, and loosened them on the student-facing ones — a whole class taking a test from one school building shares a single IP address, and that shouldn't look like abuse.

    3. Release grades and assign sessions over the API

    4. Scanning endpoints for paper answers

    5. One endpoint for tests and practice spaces

      Listing everything in a workspace used to mean calling /exams and /practice-spaces and merging the two yourself.

      GET /items returns both in a single collection, so building a "recent activity" list or a picker takes one request. It needs the items:read scope.

    6. Manage integrations over the API

      Workspace integrations — the third-party services an organization connects to Examplary — now have their own endpoints. List them, read one, connect or update one with a POST, and disconnect with a DELETE.

      Handy if you're provisioning workspaces programmatically and want the integrations set up as part of that, rather than by hand afterwards.

    7. POST /exams/{id} and POST /folders/{id} are going away

      Updating a test or a folder with a POST is deprecated. Both routes still work today, but they'll be removed, so it's worth switching while there's no rush.

      Use PATCH instead: PATCH /exams/{id} and PATCH /folders/{id}. The request body and the response are unchanged, so for most integrations it's a one-word fix.

    8. See a workspace's limits

      GET /org/limits tells you what a workspace is allowed to do on its current plan, and how much of it has been used.

      Worth calling before you kick off a big batch of work, so you can tell your users they're about to run out rather than letting a request fail halfway through.

    9. Audit logs over the API

      Organizations on Examplary get a full audit trail of significant actions — sign-ins, grading decisions, permission changes, API key rotations. You can now read it programmatically and feed it into your own SIEM or compliance tooling.

      GET /audit-logs pages through the entries, and GET /audit-logs/export gives you the lot in one go. Both need the audit-logs:read scope.

    10. Reusable prompts over the API

      The prompt templates teachers pick from when writing AI instructions are now managed over the API: list, create, update and delete them under /prompts.

      If your product has its own house style for how questions or feedback should be written, you can push those in as templates and have them show up in the editor.