ScholarScan Manual

Configure external sources and scholarly APIs

This guide explains the External sources and APIs panel in ScholarScan tenant settings, including where credentials come from and which services do not require a key.

Open the settings: Sign in to ScholarScan → Tenant settings → select your institution → expand External sources and APIs.

Open tenant settings

Before you begin

You need an approved ScholarScan institution-administrator or super-administrator account. Credentials are encrypted at rest and are not displayed again after saving. Leaving a secret field blank preserves its saved value; select Remove saved key only when you intend to revoke it from ScholarScan.

Assignment-level Online sources must also be enabled in Moodle before ScholarScan uses these external services. Saving a tenant provider does not send existing submissions automatically; request a recheck when you need a previous submission scanned with the new coverage.

Provider summary

Provider Coverage in ScholarScan Credential required?
CORE Open-access research metadata and available full text Yes: CORE API key
Europe PMC Open-access life-sciences articles and XML full text No
PubMed Central PMC Open Access search and article text No; enter an institutional NCBI contact email
Common Crawl Historical captures of candidate web URLs No
Wayback Machine Historical captures of candidate web URLs No
SearXNG Live-web discovery that supplies candidate URLs No key in ScholarScan; super administrator manages the endpoint
Brave Search Live-web discovery Yes: Brave Search API key
Google Custom Search Live-web discovery for eligible existing customers Yes: Google API key and Search Engine ID

CORE: generate and save the API key

CORE is the only scholarly collection in the current ScholarScan integration that requires a key.

  1. Open the official CORE API registration page.
  2. In Register for an API key, enter an institutional email address. CORE recommends an institutional address when registering for institutional use.
  3. Select Register now.
  4. Check that mailbox for the key and instructions from CORE. Review the linked terms and quota before enabling production use.
  5. Return to ScholarScan’s External sources and APIs panel.
  6. Paste the value into CORE API key and select Enable CORE.
  7. Select Save external source settings.

The saved value is encrypted and the form subsequently shows only Saved — leave blank to keep. Official references: CORE API overview and registration, CORE API documentation, and CORE FAQ.

Warning

Do not copy the key into a Moodle assignment, browser address bar, email message, or screenshot. If it is exposed, use CORE’s registration form to restore or replace access and update ScholarScan.

Europe PMC: enable without a key

Europe PMC’s public REST service does not require an API key for this integration.

  1. Select Enable Europe PMC.
  2. Save the tenant settings.

ScholarScan searches open-access records and retrieves available full-text XML. Read the Europe PMC REST API documentation and Europe PMC privacy information before institutional use.

PubMed Central: enter the contact email

ScholarScan uses NCBI E-utilities and the PMC Open Access service without an API key at its bounded request rate.

  1. Select Enable PubMed Central.
  2. Enter a monitored institutional address in NCBI contact email. This identifies the organisation responsible for the requests.
  3. Save the tenant settings.

Official references: NCBI developer APIs, E-utilities guidance, and PMC Open Access information.

Common Crawl and Wayback Machine

Neither archive requires a key in ScholarScan.

  1. Enable Common Crawl, Wayback Machine, or both.
  2. Ensure a live-web search provider is enabled, because the archives need candidate URLs.
  3. Save the settings.

These services check historical captures only for URLs found by live-web search. They do not perform a global phrase search over all archived internet content. See Common Crawl Get Started, Common Crawl URL Index, and Wayback Machine information.

Live-web provider keys

Live-web search is separate from the scholarly collections but supplies public pages and candidate URLs for archive checking.

SearXNG

Choose SearXNG when the institution uses the ScholarScan-managed search endpoint. It does not require a tenant API key. Only a ScholarScan super administrator can change the endpoint for network-safety reasons.

Brave Search

  1. Open the official Brave Search API page and select Get started.
  2. Create or sign in to the provider account, choose an appropriate plan, and create an API key in its dashboard.
  3. In ScholarScan, choose Brave Search API, paste the key, enable live-web search, and save.

Check current pricing and quotas before enabling it. Provider terms can change independently of ScholarScan.

Google Custom Search

Google requires both an API key and a Programmable Search Engine ID (cx). Follow Google’s Custom Search JSON API introduction, create the search engine, obtain the key, then paste both values into ScholarScan. Availability is subject to Google’s current customer and product rules.

Verify the configuration

  1. Use a test assignment with Online sources enabled.
  2. Submit or recheck a suitable test document containing at least several complete sentences.
  3. Open the lecturer’s detailed report.
  4. Review Online source check, Open scholarly collections, and Historical web archives.
  5. Confirm each provider shows Completed, No matches, or an expected disabled state.

No matches means the provider was reached but did not return an exact matching passage. Failed or Not configured indicates a key, endpoint, quota, network, or provider-availability problem.

Privacy and safe operation

Troubleshooting

Symptom What to check
CORE says Not configured Confirm the tenant has a saved CORE key and Enable CORE is selected.
Saving says a key is required Paste a new key, or disable that provider before saving.
A saved key should be replaced Paste the replacement and save; the new value overwrites the old encrypted value.
A key must be removed Select Remove saved key, disable the provider if required, and save.
Europe PMC or PMC fails Check outbound HTTPS, provider availability, and the NCBI contact email.
Archives fetch no snapshots Confirm live web search returned candidate URLs; the URL may also be absent from that archive.
Provider reaches a quota Review the provider dashboard or terms, wait for quota renewal, or disable the provider temporarily.