In this article, you’ll learn how to use incoming webhooks in Thrive Apprentice to let your checkout, CRM, or payment tool grant or revoke course access automatically, without writing any code.
What Incoming Webhooks Do
Each incoming webhook connects one external tool to one Thrive Apprentice product. The webhook gives you a unique URL. You paste that URL into your tool’s webhook settings, and whenever the tool sends a request to it, Thrive Apprentice runs the action you chose – for example, creating the student’s account and granting access to a course.
Common uses include:
- New course purchase – create the student account and enroll the buyer in the right course.
- Active subscription – keep access live for as long as the recurring payment goes through.
- Cancellation or refund – remove access on a refund or cancellation. The account and the student’s progress stay intact.
- New CRM contact – create the user and unlock the course you choose.
Creating an Incoming Webhook
- In your WordPress admin, go to Thrive Dashboard › Thrive Apprentice.
- Click Settings in the left sidebar, then select Incoming Webhooks.
- Click Add your first webhook (or Add another webhook if you already have one).
- Enter a Webhook name that describes the connection, for example “Stripe → Photography Masterclass.”

Each webhook is set up across four tabs: Setup, Field mapping, Security, and Logs.
Step 1: Choose the Action and Product (Setup Tab)
Under Action, choose what should happen when a request arrives:
- Find or create user, then grant access – Thrive Apprentice looks for a user with the email address in the request. If no account exists, it creates one and grants access. Email matching ignores capitalization and extra spaces.
- Grant access (existing users only) – access is granted only to users who already have an account. Requests for unknown email addresses are rejected and shown in the logs.
- Revoke access – removes the user’s access to the product. Their account and progress data are kept.
Then choose the Product the action applies to.

Step 2: Paste the Webhook URL Into Your Tool
Under Paste this URL into your tool, click Copy URL. In your tool’s webhook settings, paste it as the endpoint URL.

Step 3: Send a Test Request
Thrive Apprentice needs a sample of what your tool sends so it can match the fields. You have three options:
- Send a test request – click Start Listening, then trigger a test webhook from your tool within 60 seconds. Thrive Apprentice captures the request and auto-matches the fields. Nothing is created or granted during a test.
- Paste a sample payload – copy a sample event from your tool’s documentation or event viewer and paste the JSON, then click Use this payload. In Stripe, for example, go to Developers → Events, click an event, and copy its JSON.
- Skip for now – save the webhook and map the fields later. Incoming requests are logged, but no action runs until the email field is mapped, and the webhook shows a Mapping pending badge. When a real request arrives, open it in the Logs tab and click Use to map fields.

Step 4: Map the Fields (Field Mapping Tab)
Thrive Apprentice auto-matches the common fields from your test request. Review them and adjust anything that looks off:
- Email is required – it’s how Thrive Apprentice identifies the user. First name and Last name are optional.
- If your tool sends the buyer’s full name as a single field (for example, “Jenny Rosen”), turn on Split a single name field into first and last name.
- To connect fields yourself, click Switch to advanced mapping, pick a field from your payload on the left, then pick the Thrive Apprentice field on the right.
- Click Map more fields to add a Product override. This grants the product whose ID is in the request, instead of the product picked in Setup.

Only act on matching requests: if your tool sends several event types (purchases, refunds, cancellations) to the same URL, click Add a condition so the webhook only acts on the right one. Each webhook can have one condition. Enter the field path (use dots for nesting, for example data.object.status), choose equals, does not equal, or contains, and enter the value. If you pasted a sample payload or sent a test request, you can click a field from the sample to fill in both the field and the value. Requests that don’t match are acknowledged, so your tool doesn’t retry them, and logged as Skipped – didn’t match condition.

Step 5: Choose How Requests Are Verified (Security Tab)
Every new webhook starts with Shared secret selected and a secret already generated, ready to copy. Pick how Thrive Apprentice should confirm that a request really came from your tool:
- Shared secret (recommended) – your tool sends a secret value with every request, and Thrive Apprentice rejects anything that doesn’t match. Choose whether your tool sends it In a request header (most tools) or In a field inside the request body, then copy the secret into your tool. Treat it like a password.
- HMAC-SHA256 (advanced) – your tool signs each request with a signing secret, and Thrive Apprentice checks the signature. This works with tools such as WooCommerce, Lemon Squeezy, Memberful, MailerLite, and Typeform. Enter the Signature header, the Signature encoding (Hex or Base64), how the header is built (the signature on its own, a fixed prefix then the signature, or a timestamp and the signature together), and your tool’s signing secret. Check your tool’s webhook documentation for these values.
- None – anyone with the URL can trigger the webhook. This isn’t recommended; only use it for internal tools or low-risk actions.

You can also set a Rate limit (60, 120, or 300 requests per minute, or Unlimited). The default is 60 requests per minute. Requests above the limit get a 429 response and are logged.
Step 6: Save and Activate
Leave Activate on save on to have the URL start accepting requests as soon as you save, then click Save & activate. Turn it off to save the webhook as a draft instead.

Welcome Emails for New Students
When Find or create user, then grant access creates a new account, the student gets your New Account Created email from Settings › Email Templates, as long as its Incoming webhook trigger is ticked.

Checking Webhook Activity (Logs Tab)
The Logs tab lists recent requests, kept for 30 days. You can filter them by status (Successful, Failed, Skipped, or Mapping pending) and by time range. Click any row to see the full request, the response, and the result. From a logged request, you can re-run it through the webhook’s current settings or use it to map fields. Secrets are partly hidden in the logs.

If your tool sends the same sale twice, nothing breaks: the student keeps one account and one set of access, and the log shows User already had access. For every result and what to do about it, see How to Read Incoming Webhook Logs in Thrive Apprentice.
Managing Your Webhooks
All your webhooks are listed on the Incoming webhooks screen, where you can search them by name, filter by status, and sort them. Each webhook’s actions menu lets you:
- Edit the webhook.
- Pause it. A paused webhook stops accepting requests until you resume it.
- Duplicate it. The copy keeps the same setup, including its field mapping, condition, and security secret, but gets a new URL, and starts paused so you can review it first.
- Delete it. Tools that keep sending to its URL will get an error.

Troubleshooting Failed Requests
If a request fails, open it in the Logs tab to see why. Common causes are:
- The shared secret or signature doesn’t match – check that your tool uses the current secret and, for HMAC, the right header, encoding, and format.
- The request has no email address, or the email isn’t valid – check the email field mapping.
- The action is Grant access (existing users only) and no account exists for that email.
- The selected product has been deleted.
- The webhook is paused, or the rate limit was reached.
Connecting Specific Tools
Incoming webhooks work with any tool that can send a webhook. These guides walk through common ones:
Moving from a Thrive Automator recipe? See How to Move a Thrive Automator Course-Access Recipe to Incoming Webhooks.
Frequently Asked Questions
Do I need Thrive Automator or Zapier?
No. Incoming webhooks are part of Thrive Apprentice. If your tool can send webhooks itself, point it straight at the webhook URL. You only need Zapier or Make for tools that can’t.
How can I see which webhook gave a student access?
In Thrive Apprentice’s Members section, open the student and click Edit access rights. The Source column shows the webhook that granted access, for example “Incoming webhook: Stripe → Photography Masterclass.”

Does a test request create users or grant access?
No. Test requests captured with Start Listening are only used to match fields. Nothing is created or granted.
Does revoking access delete the student’s account?
No. Revoke access only removes access to the product. The student’s account and progress are kept.
Can one webhook handle purchases and refunds?
Each webhook runs one action. Create one webhook to grant access and another to revoke it, and add a condition to each so it only acts on the matching event type.
That’s it! You’ve learned how to connect an external tool to Thrive Apprentice with an incoming webhook, map its fields, secure it, and check its activity in the logs.