1. Home
  2. Knowledge Base
  3. Thrive Apprentice
  4. Thrive Apprentice Settings
  5. How to Use Incoming Webhooks in Thrive Apprentice

How to Use Incoming Webhooks in Thrive Apprentice

In this article, you’ll learn how to use incoming webhooks in Thrive Apprentice to let your checkout, CRM, or payment tool grant or revoke course access automatically, without writing any code.

Note: Incoming webhooks are available in Thrive Apprentice 11.1 and later.

What Incoming Webhooks Do

Each incoming webhook connects one external tool to one Thrive Apprentice product. The webhook gives you a unique URL. You paste that URL into your tool’s webhook settings, and whenever the tool sends a request to it, Thrive Apprentice runs the action you chose – for example, creating the student’s account and granting access to a course.

Common uses include:

  • New course purchase – create the student account and enroll the buyer in the right course.
  • Active subscription – keep access live for as long as the recurring payment goes through.
  • Cancellation or refund – remove access on a refund or cancellation. The account and the student’s progress stay intact.
  • New CRM contact – create the user and unlock the course you choose.

Creating an Incoming Webhook

  1. In your WordPress admin, go to Thrive Dashboard › Thrive Apprentice.
  2. Click Settings in the left sidebar, then select Incoming Webhooks.
  3. Click Add your first webhook (or Add another webhook if you already have one).
  4. Enter a Webhook name that describes the connection, for example “Stripe → Photography Masterclass.”
Incoming Webhooks in Thrive Apprentice settings with the Add another webhook button

Each webhook is set up across four tabs: Setup, Field mapping, Security, and Logs.

Step 1: Choose the Action and Product (Setup Tab)

Under Action, choose what should happen when a request arrives:

  • Find or create user, then grant access – Thrive Apprentice looks for a user with the email address in the request. If no account exists, it creates one and grants access. Email matching ignores capitalization and extra spaces.
  • Grant access (existing users only) – access is granted only to users who already have an account. Requests for unknown email addresses are rejected and shown in the logs.
  • Revoke access – removes the user’s access to the product. Their account and progress data are kept.

Then choose the Product the action applies to.

Setup tab with the action and product selected

Tip: Welcome emails for accounts created by a webhook are managed under Email Templates in Thrive Apprentice’s settings.

Step 2: Paste the Webhook URL Into Your Tool

Under Paste this URL into your tool, click Copy URL. In your tool’s webhook settings, paste it as the endpoint URL.

Copy URL button next to the webhook URL

Step 3: Send a Test Request

Thrive Apprentice needs a sample of what your tool sends so it can match the fields. You have three options:

  • Send a test request – click Start Listening, then trigger a test webhook from your tool within 60 seconds. Thrive Apprentice captures the request and auto-matches the fields. Nothing is created or granted during a test.
  • Paste a sample payload – copy a sample event from your tool’s documentation or event viewer and paste the JSON, then click Use this payload. In Stripe, for example, go to Developers → Events, click an event, and copy its JSON.
  • Skip for now – save the webhook and map the fields later. Incoming requests are logged, but no action runs until the email field is mapped, and the webhook shows a Mapping pending badge. When a real request arrives, open it in the Logs tab and click Use to map fields.
Sample payload pasted with the Use this payload button

Step 4: Map the Fields (Field Mapping Tab)

Thrive Apprentice auto-matches the common fields from your test request. Review them and adjust anything that looks off:

  • Email is required – it’s how Thrive Apprentice identifies the user. First name and Last name are optional.
  • If your tool sends the buyer’s full name as a single field (for example, “Jenny Rosen”), turn on Split a single name field into first and last name.
  • To connect fields yourself, click Switch to advanced mapping, pick a field from your payload on the left, then pick the Thrive Apprentice field on the right.
  • Click Map more fields to add a Product override. This grants the product whose ID is in the request, instead of the product picked in Setup.
Field mapping tab with email and name auto-matched

Only act on matching requests: if your tool sends several event types (purchases, refunds, cancellations) to the same URL, click Add a condition so the webhook only acts on the right one. Each webhook can have one condition. Enter the field path (use dots for nesting, for example data.object.status), choose equals, does not equal, or contains, and enter the value. If you pasted a sample payload or sent a test request, you can click a field from the sample to fill in both the field and the value. Requests that don’t match are acknowledged, so your tool doesn’t retry them, and logged as Skipped – didn’t match condition.

Condition set to only act when type equals checkout.session.completed

Step 5: Choose How Requests Are Verified (Security Tab)

Every new webhook starts with Shared secret selected and a secret already generated, ready to copy. Pick how Thrive Apprentice should confirm that a request really came from your tool:

  • Shared secret (recommended) – your tool sends a secret value with every request, and Thrive Apprentice rejects anything that doesn’t match. Choose whether your tool sends it In a request header (most tools) or In a field inside the request body, then copy the secret into your tool. Treat it like a password.
  • HMAC-SHA256 (advanced) – your tool signs each request with a signing secret, and Thrive Apprentice checks the signature. This works with tools such as WooCommerce, Lemon Squeezy, Memberful, MailerLite, and Typeform. Enter the Signature header, the Signature encoding (Hex or Base64), how the header is built (the signature on its own, a fixed prefix then the signature, or a timestamp and the signature together), and your tool’s signing secret. Check your tool’s webhook documentation for these values.
  • None – anyone with the URL can trigger the webhook. This isn’t recommended; only use it for internal tools or low-risk actions.
Security tab with Shared secret selected and the X-Webhook-Secret header

You can also set a Rate limit (60, 120, or 300 requests per minute, or Unlimited). The default is 60 requests per minute. Requests above the limit get a 429 response and are logged.

Note: If you click the regenerate icon next to the secret value, the old secret stops working as soon as you save. Update the secret in your tool right away, or its requests will be rejected.

Step 6: Save and Activate

Leave Activate on save on to have the URL start accepting requests as soon as you save, then click Save & activate. Turn it off to save the webhook as a draft instead.

Rate limit and Activate on save settings with the Save and activate button

Welcome Emails for New Students

When Find or create user, then grant access creates a new account, the student gets your New Account Created email from Settings › Email Templates, as long as its Incoming webhook trigger is ticked.

Incoming webhook trigger enabled on the New Account Created email template

Note: The Incoming webhook trigger is on by default for new sites. If you’d already customized the New Account Created email before updating, the trigger starts off so existing students don’t get unexpected emails – tick it yourself to send welcome emails to webhook-created students.

Checking Webhook Activity (Logs Tab)

The Logs tab lists recent requests, kept for 30 days. You can filter them by status (Successful, Failed, Skipped, or Mapping pending) and by time range. Click any row to see the full request, the response, and the result. From a logged request, you can re-run it through the webhook’s current settings or use it to map fields. Secrets are partly hidden in the logs.

Logs tab showing successful, failed, and skipped requests

If your tool sends the same sale twice, nothing breaks: the student keeps one account and one set of access, and the log shows User already had access. For every result and what to do about it, see How to Read Incoming Webhook Logs in Thrive Apprentice.

Managing Your Webhooks

All your webhooks are listed on the Incoming webhooks screen, where you can search them by name, filter by status, and sort them. Each webhook’s actions menu lets you:

  • Edit the webhook.
  • Pause it. A paused webhook stops accepting requests until you resume it.
  • Duplicate it. The copy keeps the same setup, including its field mapping, condition, and security secret, but gets a new URL, and starts paused so you can review it first.
  • Delete it. Tools that keep sending to its URL will get an error.
Webhook actions menu with Edit, Pause, Copy URL, Duplicate, and Delete

Troubleshooting Failed Requests

If a request fails, open it in the Logs tab to see why. Common causes are:

  • The shared secret or signature doesn’t match – check that your tool uses the current secret and, for HMAC, the right header, encoding, and format.
  • The request has no email address, or the email isn’t valid – check the email field mapping.
  • The action is Grant access (existing users only) and no account exists for that email.
  • The selected product has been deleted.
  • The webhook is paused, or the rate limit was reached.

Connecting Specific Tools

Incoming webhooks work with any tool that can send a webhook. These guides walk through common ones:

Moving from a Thrive Automator recipe? See How to Move a Thrive Automator Course-Access Recipe to Incoming Webhooks.

Frequently Asked Questions

Do I need Thrive Automator or Zapier?

No. Incoming webhooks are part of Thrive Apprentice. If your tool can send webhooks itself, point it straight at the webhook URL. You only need Zapier or Make for tools that can’t.

How can I see which webhook gave a student access?

In Thrive Apprentice’s Members section, open the student and click Edit access rights. The Source column shows the webhook that granted access, for example “Incoming webhook: Stripe → Photography Masterclass.”

Member access source showing the incoming webhook that granted access

Does a test request create users or grant access?

No. Test requests captured with Start Listening are only used to match fields. Nothing is created or granted.

Does revoking access delete the student’s account?

No. Revoke access only removes access to the product. The student’s account and progress are kept.

Can one webhook handle purchases and refunds?

Each webhook runs one action. Create one webhook to grant access and another to revoke it, and add a condition to each so it only acts on the matching event type.

That’s it! You’ve learned how to connect an external tool to Thrive Apprentice with an incoming webhook, map its fields, secure it, and check its activity in the logs.

Was this article helpful?

Related Articles

>