Skip to content
cursareDocs
Sign inGet started
Documentation
  • Overview
  • Index2
  • Organization17
  • Sales6
  • Insights8
  • Reports and safety7
  • Minor accounts8
  • Minor safety3
  • Offers11
  • Media1
  • Contents10
  • Learner delivery1
  • Learner runtime5
  • Learners12
  • Cohorts12
  • Intake forms5
  • Campaigns4
  • Teams8
  • Affiliates7
  • Links7
  • Reviews1
  • Integrations26
  • MCP2
  • Webhooks6

Webhooks

Signed event destinations, deliveries and test calls.

6 endpoints

List webhooks

GET/webhooks

The org's outgoing webhook endpoints. Signing secrets are never included — the whsec_ secret is returned exactly once, by the create call.

Responses

200List webhooks.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks \
  --header 'Authorization: Bearer cr_live_…'
{
  "data": [
    {
      "active": true,
      "createdAt": "2026-01-31T12:00:00.000Z",
      "events": [
        "enrollment.created"
      ],
      "id": "string",
      "teamId": "string",
      "url": "string"
    }
  ]
}

Create a webhook

POST/webhooks

Registers an endpoint for signed event deliveries. The URL must be a public https host — localhost, private, and internal addresses are rejected. The response includes the whsec_ signing secret ONCE; store it now, it is never shown again.

Request body

eventsenum[]required

enrollment.createdenrollment.requestedenrollment.approvedenrollment.rejectedenrollment.expiredlearner.unenrolledcontent.completedcontent.createdcontent.updatedcontent.publishedcontent.deletedoffer.createdoffer.updatedoffer.primary_changedoffer.archivedreview.createdreview.updatedcohort.createdcohort.updatedcohort.deletedcohort.joinedcohort.member.movedcohort.member.removeddiscussion.post.createddiscussion.post.deleteddiscussion.post.resolveddiscussion.post.reopenedpurchase.createdpurchase.installment.paidpurchase.installment.failedpurchase.installment.recoveredpurchase.installment.canceledcampaign.redeemedpurchase.refunded

urlurirequired
teamIdstring | null

Responses

201Create a webhook.
400Validation failed or the request body is malformed.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks \
  --request POST \
  --header 'Authorization: Bearer cr_live_…' \
  --header 'Content-Type: application/json' \
  --data '{
  "events": [
    "enrollment.created"
  ],
  "url": "https://example.com",
  "teamId": "string"
}'
{
  "data": {
    "active": true,
    "createdAt": "2026-01-31T12:00:00.000Z",
    "events": [
      "enrollment.created"
    ],
    "id": "string",
    "secret": "string",
    "teamId": "string",
    "url": "string"
  }
}

Enable or disable a webhook

PATCH/webhooks/{id}

Only active can change — an inactive endpoint keeps its configuration and delivery history but receives nothing. To change the URL or events, delete the webhook and create a new one.

Path parameters

idstring

The webhook id.

Request body

activeboolean

Responses

200Enable or disable a webhook.
400Validation failed or the request body is malformed.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
404The resource does not exist (or belongs to another org).
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks/{id} \
  --request PATCH \
  --header 'Authorization: Bearer cr_live_…' \
  --header 'Content-Type: application/json' \
  --data '{
  "active": true
}'
{
  "data": {
    "active": true,
    "createdAt": "2026-01-31T12:00:00.000Z",
    "events": [
      "enrollment.created"
    ],
    "id": "string",
    "teamId": "string",
    "url": "string"
  }
}

Delete a webhook

DELETE/webhooks/{id}

Removes the endpoint and its delivery history.

Path parameters

idstring

The webhook id.

Responses

200Delete a webhook.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
404The resource does not exist (or belongs to another org).
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks/{id} \
  --request DELETE \
  --header 'Authorization: Bearer cr_live_…'
{
  "data": {
    "deleted": true,
    "id": "string"
  }
}

List recent deliveries

GET/webhooks/{id}/deliveries

The endpoint's most recent delivery attempts, newest first.

Path parameters

idstring

The webhook id.

Query parameters

limitinteger

Responses

200List recent deliveries.
400Validation failed or the request body is malformed.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
404The resource does not exist (or belongs to another org).
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks/{id}/deliveries \
  --header 'Authorization: Bearer cr_live_…'
{
  "data": [
    {
      "attempt": 0,
      "createdAt": "2026-01-31T12:00:00.000Z",
      "durationMs": 0,
      "error": "string",
      "event": "string",
      "eventId": "string",
      "eventVersion": 0,
      "id": "string",
      "requestBody": "string",
      "responseBody": "string",
      "responseStatus": 0,
      "success": true
    }
  ]
}

Send a test ping

POST/webhooks/{id}/test

POSTs a signed webhook.test event to the endpoint and records the attempt. Returns 200 even if the endpoint fails — check the delivery log for the result.

Path parameters

idstring

The webhook id.

Responses

200Send a test ping.
401Missing, invalid or revoked API key.
403The key's organization does not own this resource.
404The resource does not exist (or belongs to another org).
429Rate limit exceeded (240 reads/min, 60 writes/min per key).
500Unexpected server error.
curl https://api.cursare.com/v1/webhooks/{id}/test \
  --request POST \
  --header 'Authorization: Bearer cr_live_…'
{
  "data": {
    "id": "string",
    "sent": true
  }
}

Your privacy choices

The technical Tag Manager container is required to apply your choices. Analytics and marketing cookies and storage remain optional and stay off until you authorize them. Privacy Policy.

Sign-in, security, core functions and consent enforcement.

Audience measurement such as Google Analytics.

Marketing storage, campaign attribution and optional tags.