In this article, you’ll learn how to use an incoming webhook to give buyers access to a Thrive Apprentice course when they purchase through ThriveCart, and how to remove access again on a refund.
Step 1: Create the Webhook in Thrive Apprentice
- Go to Thrive Dashboard › Thrive Apprentice › Settings › Incoming Webhooks.
- Click Add your first webhook (or Add another webhook).
- Name the webhook, for example “ThriveCart → Photography Masterclass.”
- Under Action, keep Find or create user, then grant access.
- Under Product, choose the Thrive Apprentice product the buyer should get.
- Under Paste this URL into your tool, click Copy URL.
Step 2: Add the Webhook in ThriveCart
- In ThriveCart, click your profile icon and go to Settings › API & Webhooks.
- Next to Webhooks & notifications, click View settings, then click Add another webhook.
- Enter a name, paste the Thrive Apprentice URL into the Webhook URL field, and tick the option to receive the results as JSON.
- Save the webhook.
Step 3: Send a Test
Back in Thrive Apprentice, click Start Listening, then send a test from ThriveCart within 60 seconds (or make a test purchase). Thrive Apprentice captures the request and matches the fields. Nothing is created or granted during the test.
Map the Fields
On the Field mapping tab, check that Thrive Apprentice picked the buyer’s email address for the Email field, and their first and last name if your test included them. The previews show the real values from your test, so you can confirm at a glance. Adjust anything that looks off.
Step 4: Only Act on Purchases
ThriveCart sends every event – purchases, refunds, subscription payments, and cancellations – to the same URL. On the Field mapping tab, click Add a condition and click the event field in your test request to fill it in. Set it to equals order.success so this webhook only grants access for purchases.
Step 5: Protect the Webhook
ThriveCart includes your account’s secret word in every webhook request, in a field called thrivecart_secret. To use it:
- In ThriveCart, go to Settings › API & Webhooks and copy the secret word from ThriveCart order validation.
- In Thrive Apprentice, open the Security tab and keep Shared secret selected.
- Under Where does your tool send the secret?, choose In a field inside the request body.
- Enter
thrivecart_secretas the field, and paste ThriveCart’s secret word as the secret value.
Save, Test, and Check the Log
- Leave Activate on save on and click Save & activate.
- Make a test purchase in ThriveCart.
- Open the webhook’s Logs tab. You should see Granted access to followed by the product and the buyer’s email.
If the result is different, see How to Read Incoming Webhook Logs in Thrive Apprentice for what each result means.
Removing Access on a Refund
Each webhook does one job, so refunds need a second webhook:
- Open the webhook’s actions menu and click Duplicate. The copy has a new URL and starts paused.
- Edit the copy, rename it (for example, add “Refund”), and change the Action to Revoke access.
- On the Field mapping tab, change the condition value to
order.refund. Then open the copy’s Security tab and check that it still uses thethrivecart_secretfield and ThriveCart’s secret word. In ThriveCart, nothing changes – add the copy’s URL as another webhook, the same way as Step 2. - Save and activate the copy.
Revoking access keeps the student’s account and course progress, so they can pick up where they left off if they buy again.
That’s it! ThriveCart purchases now give buyers their Thrive Apprentice course automatically, and refunds take access away.