Scoped authentication
API tokens are hashed at rest, displayed once, limited by scopes, expire after ninety days, and can be revoked.
Developer portal
Efibb exposes selected mobile configuration, catalog, authenticated sync, adaptive learning, credentials, and study-abroad state through /api/v2. Internal administration, infrastructure, private tenant, and operational-security routes are excluded from this public specification.
API tokens are hashed at rest, displayed once, limited by scopes, expire after ninety days, and can be revoked.
Cursor-based synchronization supports bounded updates for learning, projects, notifications, and orders.
Public catalog endpoints expose approved learning and opportunity content—not internal administration schemas or secrets.
Authenticated registration creates a controlled foundation for future iOS, Android, and web-push delivery.