Signed event destinations, deliveries and test calls.
List webhooks
GET/webhooks
The org's outgoing webhook endpoints. Signing secrets are never included — the whsec_ secret is returned exactly once, by the create call.
Responses
200List webhooks.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks \
--header 'Authorization: Bearer cr_live_…'
{
"data": [
{
"active": true,
"createdAt": "2026-01-31T12:00:00.000Z",
"events": [
"enrollment.created"
],
"id": "string",
"teamId": "string",
"url": "string"
}
]
}
Create a webhook
POST/webhooks
Registers an endpoint for signed event deliveries. The URL must be a public https host — localhost, private, and internal addresses are rejected. The response includes the whsec_ signing secret ONCE; store it now, it is never shown again.
Request body
eventsenum[]required
enrollment.createdenrollment.requestedenrollment.approvedenrollment.rejectedenrollment.expiredlearner.unenrolledcontent.completedcontent.createdcontent.updatedcontent.publishedcontent.deletedoffer.createdoffer.updatedoffer.primary_changedoffer.archivedreview.createdreview.updatedcohort.createdcohort.updatedcohort.deletedcohort.joinedcohort.member.movedcohort.member.removeddiscussion.post.createddiscussion.post.deleteddiscussion.post.resolveddiscussion.post.reopenedpurchase.createdpurchase.installment.paidpurchase.installment.failedpurchase.installment.recoveredpurchase.installment.canceledcampaign.redeemedpurchase.refunded
Responses
201Create a webhook.
400Validation failed or the request body is malformed.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks \
--request POST \
--header 'Authorization: Bearer cr_live_…' \
--header 'Content-Type: application/json' \
--data '{
"events": [
"enrollment.created"
],
"url": "https://example.com",
"teamId": "string"
}'
{
"data": {
"active": true,
"createdAt": "2026-01-31T12:00:00.000Z",
"events": [
"enrollment.created"
],
"id": "string",
"secret": "string",
"teamId": "string",
"url": "string"
}
}
Enable or disable a webhook
PATCH/webhooks/{id}
Only active can change — an inactive endpoint keeps its configuration and delivery history but receives nothing. To change the URL or events, delete the webhook and create a new one.
Responses
200Enable or disable a webhook.
400Validation failed or the request body is malformed.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
404The resource does not exist (or belongs to another org).
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks/{id} \
--request PATCH \
--header 'Authorization: Bearer cr_live_…' \
--header 'Content-Type: application/json' \
--data '{
"active": true
}'
{
"data": {
"active": true,
"createdAt": "2026-01-31T12:00:00.000Z",
"events": [
"enrollment.created"
],
"id": "string",
"teamId": "string",
"url": "string"
}
}
Delete a webhook
DELETE/webhooks/{id}
Removes the endpoint and its delivery history.
Responses
200Delete a webhook.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
404The resource does not exist (or belongs to another org).
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks/{id} \
--request DELETE \
--header 'Authorization: Bearer cr_live_…'
{
"data": {
"deleted": true,
"id": "string"
}
}
List recent deliveries
GET/webhooks/{id}/deliveries
The endpoint's most recent delivery attempts, newest first.
Responses
200List recent deliveries.
400Validation failed or the request body is malformed.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
404The resource does not exist (or belongs to another org).
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks/{id}/deliveries \
--header 'Authorization: Bearer cr_live_…'
{
"data": [
{
"attempt": 0,
"createdAt": "2026-01-31T12:00:00.000Z",
"durationMs": 0,
"error": "string",
"event": "string",
"eventId": "string",
"eventVersion": 0,
"id": "string",
"requestBody": "string",
"responseBody": "string",
"responseStatus": 0,
"success": true
}
]
}
Send a test ping
POST/webhooks/{id}/test
POSTs a signed webhook.test event to the endpoint and records the attempt. Returns 200 even if the endpoint fails — check the delivery log for the result.
Responses
200Send a test ping.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
404The resource does not exist (or belongs to another org).
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks/{id}/test \
--request POST \
--header 'Authorization: Bearer cr_live_…'
{
"data": {
"id": "string",
"sent": true
}
}