Webhooks automatically send information from Cademy to another system when selected events happen. For example, Cademy can notify your CRM when a registration is created or notify your reporting system when an order is updated.
Webhooks are useful for custom integrations because the other system does not need to keep checking Cademy for changes.
Important: A webhook is a developer tool. If you do not already have an endpoint URL, ask your developer or integration provider to create one. Your normal website address is usually not a webhook endpoint.
Before You Start
You need:
A Teams or Custom plan.
System Admin access. Only System Admins can open and manage Settings > Webhooks.
A public HTTPS endpoint that can accept JSON
POSTrequests.Access to the system receiving the requests so you can store the secret and verify each request.
What Should I Enter in Endpoint URL?
Endpoint URL is the web address where Cademy will send webhook messages. It is mandatory and cannot be left blank.
Your developer or integration provider should give you this address. For example:
https://example.com/webhooks/cademy
Do not enter your normal website homepage unless it has been specifically built to receive Cademy webhook requests.
The URL must:
Start with
https://.Be available publicly on the internet.
Not use localhost, a
.localaddress, or a private or reserved IP address.Return a successful
2xxresponse within 10 seconds.
Create a Webhook
From the admin dashboard, go to Settings > Webhooks.
Click Add Webhook.
Enter the address provided by your developer or integration provider in Endpoint URL.
Use Description (optional) to explain what the webhook connects to. You can leave this blank.
Under Events, select every event you want Cademy to send.
Click Create.
Copy the Webhook Secret
After you click Create, Webhook Secret opens.
Click Copy secret to clipboard.
Store the secret securely in the system that receives the webhook.
Click Done.
The receiving system uses this secret to confirm that requests came from Cademy. Do not publish or share it. You can open the webhook menu and use Reveal Secret… if you need to copy it again later.
Choose Which Events to Send
You can select one event, several events, or every event. You can change the selection later with Edit….
Group | Event shown in Cademy | Event code sent |
Courses | Course created |
|
Courses | Course updated |
|
Courses | Course deleted |
|
Course Dates | Course date created |
|
Course Dates | Course date updated |
|
Course Dates | Course date deleted |
|
Contacts | Contact created |
|
Contacts | Contact updated |
|
Contacts | Contact deleted |
|
Registrations | Registration created |
|
Registrations | Registration cancelled |
|
Orders | Order created |
|
Orders | Order updated |
|
Course updated can be sent for published, private, and draft courses, including when a course's visibility changes.
What Cademy Sends
Cademy sends a signed HTTPS POST request shortly after a selected event happens.
JSON Body
Every request uses the same top-level structure:
{
"id": "evt_1234567890abcdef",
"type": "registration.created",
"created": "2026-07-17T10:00:00.000Z",
"data": {
"id": "registration-id"
}
}
Field | Meaning |
| The event ID. Use this to identify and ignore duplicate events. |
| The event code, such as |
| The date and time the event happened, in ISO 8601 format. |
| Information about the course, course date, contact, registration, or order. |
Deletion events contain identifiers instead of the full deleted record. course.deleted and contact.deleted contain the record ID. course_date.deleted contains the course date ID and course ID.
Request Headers
Header | Meaning |
| The event code. |
| A unique ID for that delivery attempt. |
| The Unix timestamp used to sign the request. |
| The HMAC SHA-256 signature. |
Verify the Signature
Verify every request before using its data:
Read the raw request body exactly as Cademy sent it. Do this before parsing or reformatting the JSON.
Read
X-Cademy-Timestamp.Join the timestamp, a full stop, and the raw body:
{timestamp}.{rawBody}.Create an HMAC SHA-256 digest using the webhook secret.
Add the
sha256=prefix and compare the result withX-Cademy-Signatureusing a timing-safe comparison.
Node.js example:
import { createHmac, timingSafeEqual } from 'node:crypto';const expected = `sha256=${createHmac('sha256', secret)
.update(`${timestamp}.${rawBody}`)
.digest('hex')}`;const isValid =
signature.length === expected.length &&
timingSafeEqual(Buffer.from(signature), Buffer.from(expected));
Important: Webhooks use at-least-once delivery and events are not guaranteed to arrive in order. Your system must safely handle duplicates by storing the JSON body's id and ignoring any event ID it has already processed.
Check Deliveries and Retries
View Recent Deliveries
Go to Settings > Webhooks.
Open the menu beside the webhook.
Click View Deliveries….
Recent Deliveries shows the event, result, time, attempt number, response status, duration, and any error. Delivery records are kept for 30 days. The JSON payload is not stored in this delivery history.
What Happens When a Delivery Fails?
Any 2xx response counts as successful. A non-2xx response, network error, unsafe redirect, or request that takes longer than 10 seconds counts as failed.
Cademy makes up to 5 attempts over about 30 minutes. The first attempt happens immediately, followed by up to 4 retries.
Why Was My Webhook Auto-disabled?
If 10 consecutive events each use all 5 attempts without succeeding, Cademy changes the webhook's status to Auto-disabled. This prevents repeated requests to an endpoint that is not working.
Fix the endpoint, then go to Settings > Webhooks and click Re-enable. A successful delivery resets the consecutive failure count.
Manage a Webhook
Go to Settings > Webhooks and open the menu beside a webhook.
Option | What it does |
Edit… | Change the Endpoint URL, Description (optional), or Events. |
View Deliveries… | Open the delivery history from the last 30 days. |
Reveal Secret… | Show and copy the current webhook secret. |
Regenerate Secret… | Create a new secret. The current secret stops working immediately, so update your receiving system straight away. |
Disable | Stop new deliveries and queued retries immediately without deleting the webhook. |
Enable | Start sending selected events again. |
Delete… | Permanently remove the webhook and stop deliveries immediately. |
Troubleshooting
Cademy Will Not Accept the Endpoint URL
Check the message shown under Endpoint URL:
Endpoint URL must use HTTPS: Replace
http://with a workinghttps://endpoint.Endpoint URL cannot target localhost: Use a public endpoint instead of localhost or a
.localaddress.Endpoint URL cannot target a private or reserved address: Use a public internet address instead of a private or internal IP address.
The Webhook Is Enabled but Nothing Arrives
Open Edit… and confirm the correct event is selected.
Confirm the event happened after the webhook was enabled. Cademy does not send historical events.
Open View Deliveries… and look for the event.
Confirm the endpoint accepts HTTPS
POSTrequests and returns a2xxresponse within 10 seconds.Check that your endpoint is not redirecting requests to a different host.
The Signature Does Not Match
Use the raw request body before JSON parsing or reformatting.
Use the value from
X-Cademy-Timestampin the signed content.Confirm your receiving system uses the current secret. If you used Regenerate Secret…, the previous secret stopped working immediately.
Confirm the expected value includes the
sha256=prefix.
Frequently Asked Questions
Do I need a developer to use webhooks?
Usually, yes. You can create and manage the webhook in Cademy, but the receiving endpoint must be built or provided by a developer or integration service.
Can I leave Endpoint URL blank?
No. Cademy needs a public HTTPS endpoint before it can create the webhook.
Can I use my website homepage as Endpoint URL?
Usually not. Use it only if a developer has specifically configured that address to receive Cademy webhook POST requests.
Can I leave Description (optional) blank?
Yes. It is only a label to help System Admins understand what the webhook connects to.
Can I send a test webhook?
There is no separate test button. Create the webhook, then perform one of its selected events in Cademy and check View Deliveries….
Will Cademy send an event exactly once?
No. Cademy uses at-least-once delivery, so the same event can arrive more than once. Use the JSON body's id to ignore duplicates.
Will events arrive in the same order they happened?
Not always. Your receiving system should use the event's created value and must not rely on delivery order.
How many times will Cademy retry a failed delivery?
Cademy makes up to 5 attempts over about 30 minutes.
How long is delivery history kept?
Recent Deliveries keeps delivery records for 30 days. It does not store the JSON payload.
Can I see the secret again?
Yes. Open the webhook menu and click Reveal Secret….
What happens if I regenerate the secret?
The previous secret stops working immediately. Copy the new secret to your receiving system straight away.
Can I pause a webhook without deleting it?
Yes. Use Disable. This stops new deliveries and queued retries immediately. Use Enable when you are ready to start again.




