School IT & Network Requirements
Product purpose
Number Ninjas is a K–12 educational mathematics platform for schools, teachers, and students. It supports arithmetic practice, classroom assignments, diagnostics, mastery tracking, and progress reporting. Game mechanics and character rewards support instruction; this is not a general-purpose gaming portal. Google Classroom integration supports authorized classroom workflows.
Required first-party network access
For the production service at numberninjas.app, normal student practice requires these two hostnames. Both use HTTPS over TCP port 443. No separate asset/CDN hostname or WebSocket connection is required by student practice. Fonts, images, audio, and learning assets are served from the application origin.
| Hostname | Purpose | Student requirement | Transport / WebSockets |
|---|---|---|---|
| numberninjas.app | Application, scripts, styles, fonts, images, audio, and practice assets | Required | HTTPS / TCP 443; no WebSockets |
| backend.numberninjas.app | API configuration, sessions, questions, answers, assignments, and progress | Required | HTTPS / TCP 443; no student WebSockets |
Copyable student allowlist
numberninjas.app
backend.numberninjas.appAllow both hosts, including application assets and API paths under /api/v1/. Permit session cookies and credentialed requests between these first-party hosts. Do not pin deployment IP addresses or broadly allow unrelated third-party domains. Hosting behind a CDN does not require students to visit the CDN vendor’s domain.
Conditional login and optional integrations
| Hostname / service | Purpose and student requirement | Transport / WebSockets |
|---|---|---|
| accounts.google.com | Required when students or teachers choose Google sign-in; not needed for guest sign-in. Google may also use its own login assets and a district identity provider; see the guidance below. | HTTPS / TCP 443; no Number Ninjas WebSocket requirement |
| classroom.google.com | Optional Google Classroom website, including opening published assignments or diagnostics. Not used by practice once Number Ninjas is open. | HTTPS / TCP 443; no Number Ninjas WebSocket requirement |
| backend.numberninjas.app | Teacher-only realtime dashboard updates at /api/v1/teacher/ws. Not required for student practice. | WSS / TCP 443; WebSocket upgrade required for live teacher updates |
| a.pigeonz.io | Optional Rybbit analytics configured for consenting teachers on the dashboard. Not required for students or guests, sign-in, or core teacher functions. | HTTPS / TCP 443; no WebSockets |
Google controls the additional hosts used on its sign-in pages. Follow the relevant parts of Google’s Workspace firewall guidance and your district’s identity-provider requirements; the two-domain student allowlist is not a complete Google Workspace allowlist. Google sign-in can also require district approval of the application, independently of network filtering.
Server-to-server Google connections use oauth2.googleapis.com (tokens and revocation), www.googleapis.com (signing keys), and classroom.googleapis.com (courses, rosters, and assignment publication), all over HTTPS / TCP 443 without WebSockets. These are backend egress requirements, not additional student-browser allowlist entries.
ClassLink support is pre-pilot and is not enabled in the verified production configuration. If offered by your deployment, request its approved district-specific sign-in hostnames from support before rollout. No generic ClassLink wildcard allowlist is required for the current service.
Filtering and deployment checks
Test on a student device with the district’s normal filter and TLS inspection enabled: open the application, sign in, complete practice, and check images, audio, and saved progress. Also test assignments and diagnostics for authorized classrooms. For teachers, test Classroom access and realtime dashboard updates. Inspect the browser console and network panel for blocked requests. Do not disable district security controls as a troubleshooting shortcut; contact support with the failing hostname.
Educational categorization does not guarantee access. District policies and local blocklists can still restrict the application. Ask your administrator to review the reported category and, where appropriate, allowlist the service or request a correction from the filtering vendor.
Security, privacy, and school agreements
Classroom authorization and access controls are enforced by the backend. Public information pages do not publish student or classroom records. No advertising or student behavioral analytics are needed for practice. The documents below explain data use, retention, deletion, security, school authorization, and the conditions relevant to COPPA and FERPA; this page does not claim a legal certification or replace your district’s review.
- Privacy Policy, including security practices and incident contact
- School Student Data Notice
- School Student Data Agreement (school agreement and data-processing terms)
- Terms of Service
- Google data controls and deletion
Contact support about any additional district DPA or agreement review.
School IT support
Email support@yinyang-interactive.com with the filtering vendor, reported category, blocked hostname, device/browser, time of failure, and whether student practice or teacher tools are affected. Do not send student names, credentials, session cookies, or unredacted network captures. Report security concerns to security@yinyang-interactive.com.
Network inventory last reviewed September 26, 2026.
