Naalya Developers

Overview

Base URL, keys, limits and errors.

Base URL

https://staging.api.naalyaschools.ac.ug for this environment. Set it once as NAALYA_API; every path below is relative to it.

Keys

Header: X-API-Key. Created under Development > API Keys; shown once.

SecretPublishable
Lives inYour serverThe visitor's browser
Origin checkNoneOrigin must match an allowed origin on the key
Use forA backend calling the APIA widget or form calling the API from the page

An origin is scheme + host + port, exact and lowercase: https://www.school.ac.ug and https://school.ac.ug are two entries.

Never ship a secret key in a page

Revoke it in the Hub if it leaks; revoking is immediate.

Clients

  • Widget: one script tag, no code.
  • @naalya/chat on npm: createNaalyaChat for any framework, useNaalyaChat for React, mountNaalyaChat to place the widget from code.
  • Plain HTTP, as documented on the Chat and Enquiries pages.

Limits

  • 60 requests a minute per key.
  • 10 requests a minute per visitor IP on publishable keys.

Over the limit: 429, resets within a minute.

Errors

{
  "statusCode": 403,
  "error": "Forbidden",
  "message": "Origin not allowed for this key",
  "path": "/api/v1/public-ai/chat",
  "timestamp": "2026-10-03T08:15:00.000Z",
  "requestId": "a1b2c3d4-1234-4321-9876-abcdefabcdef"
}

400 adds details, one line per field.

StatusWhyFix
400Body failed validationRead details
401No key, revoked or unknownCheck the header and the key
403Wrong key kind, or origin not allowedUse the right kind or add the origin
413Body over 1 MB (chat) or 100 KB (enquiries)Shorten the messages
429Rate limitBack off for a minute

On this page