# 1. API Access & Keys

User Type: **Training Institute**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 1. API Access & Keys

### 1.1 API Key Management
**What it does:** Lets the Training Institute manage its API keys: the Institute creates a key with a name and scope, views the active keys, and revokes a key. The key is shown only once at creation. This lets the Institute's systems connect to the platform programmatically.

**Sub-features:**
- API key management
- Create a key with a name and scope
- Active keys list
- Revoke a key
- Key shown only once at creation
- Key scope limits access
- Management available on web and mobile
- Management event logging (created, revoked)
- Audit logging of the API key management

**Training Institute User Journey:**
1. Training Institute opens the API key management.
2. Training Institute creates a key with a name and scope.
3. The active keys list is shown.
4. Training Institute revokes a key.
5. The key is shown only once at creation.
6. The key scope limits access.
7. Training Institute opens Profile → "Activity" and confirms the management events are recorded.

**Rules & Edge Cases:**
- The key is shown only once at creation.
- A revoked key stops working immediately.
- Management events (created, revoked) are logged with the account and the timestamp.
- The API key management is audit-logged with the account and the timestamp.

### 1.2 API Usage Monitoring
**What it does:** Shows the Training Institute its API usage: the calls per day, the usage by endpoint category, the rate limit headroom, and the recent errors. The Institute sees the usage and can set a usage alert threshold. This helps the Institute monitor its integrations.

**Sub-features:**
- API usage view
- Calls per day shown
- Usage by endpoint category
- Rate limit headroom shown
- Recent errors shown
- Set a usage alert threshold
- Usage available on web and mobile
- Usage event logging (viewed)
- Audit logging of the API usage monitoring

**Training Institute User Journey:**
1. Training Institute opens the API usage monitoring.
2. The API usage view is shown.
3. The calls per day are shown.
4. The usage by endpoint category is shown.
5. The rate limit headroom is shown.
6. Training Institute sets a usage alert threshold.
7. Training Institute opens Profile → "Activity" and confirms the usage events are recorded.

**Rules & Edge Cases:**
- The rate limit headroom is shown against the plan limit.
- A usage alert is sent at the threshold.
- Usage events (viewed) are logged with the account and the timestamp.
- The API usage monitoring is audit-logged with the account and the timestamp.

### 1.3 API Documentation & Sandbox
**What it does:** Provides the Training Institute with API documentation and a sandbox: the Institute browses the endpoint reference, the authentication guide, and a sandbox environment to test integrations without affecting live data. The Institute can copy example requests. This helps the Institute build integrations correctly.

**Sub-features:**
- API documentation
- Endpoint reference
- Authentication guide
- Sandbox environment
- Test without affecting live data
- Copy example requests
- Documentation available on web and mobile
- Documentation event logging (viewed)
- Audit logging of the API documentation and sandbox

**Training Institute User Journey:**
1. Training Institute opens the API documentation.
2. The endpoint reference is shown.
3. The authentication guide is shown.
4. Training Institute uses the sandbox environment.
5. The test does not affect live data.
6. Training Institute copies example requests.
7. Training Institute opens Profile → "Activity" and confirms the documentation events are recorded.

**Rules & Edge Cases:**
- The sandbox does not affect live data.
- The documentation is versioned with the API.
- Documentation events (viewed) are logged with the account and the timestamp.
- The API documentation and sandbox is audit-logged with the account and the timestamp.
