# score.created

Sent to the webhook endpoints subscribed to `score.created` in `event_types`. The resource type of this event, used as the key of `resource_filters`, is `score`.

## Example body

```json
{
  "id": "evt_01J8Z3TESTE",
  "type": "score.created",
  "version": 1,
  "occurred_at": "2026-09-29T12:00:00Z",
  "data": {
    "id": "sco_42",
    "origin": "lesson_completed",
    "points": 10,
    "product_id": "prd_42",
    "user_id": "usr_42"
  },
  "delivery_id": "whd_01J8Z3TESTE",
  "attempt": 1
}
```

With `payload_detail` set to `masked` or `full`, the body also carries `expanded` with `product`, `user`, each in the same format as the API returns it. See [API webhooks](https://cademi.dev/api/webhooks.md).

## Fields

| Field | Type | Required | Description |
|---|---|---|---|
| `id` | string | yes | ID of the event, prefixed with `evt_`, as in `GET /events/{event_id}`. Every delivery and retry of the same event has the same ID. |
| `type` | string | yes | Always `score.created`. |
| `version` | integer | yes | Always `1`. Version of the format of `data` for this event type. |
| `occurred_at` | string | yes | When the event occurred, in UTC. |
| `data` | object | yes | Data of the event, in the format of its `version`. People are identified only by ID. The only free text is the note written by whoever operates the account (`reason` in `certificate.revoked` and `diamond_membership.stage_changed`), sent as written. |
| `data.id` | string | yes | Public ID of the score, prefixed with `sco_`. |
| `data.origin` | string | yes | What earned the points, as in `origin` of the score in the API. One of `lesson_completed`, `course_started`, `course_progress_50`, `course_progress_75`, `course_progress_90`, `course_completed`, `certificate_issued`, `question`, `comment`, `exam_passed`, `manual`. |
| `data.points` | integer | yes | Number of points of the entry. |
| `data.product_id` | string \| null | yes | Public ID of the product where the points were earned, prefixed with `prd_`. `null` when the points are not tied to a product. |
| `data.user_id` | string | yes | Public ID of the user, prefixed with `usr_`. |
| `expanded` | object | no | Present only when the `payload_detail` of the endpoint is `masked` or `full`. Contains the resources the event refers to, in the same format as the API returns them, as they were when the delivery was created: a retry sends the same objects. A key is `null` when the resource no longer exists. In `masked`, personal data is masked by the rules described in `payload_detail` of `POST /webhooks` (`re**@g**.com`, `Renan C** P**`), and free text written by users is replaced with `[redacted]`; a masked value keeps the type of the field, but may not match its `format` (a masked email is not a valid address). Masked personal data is still personal data. In `full`, values are sent as stored. Products, lessons and exams have the format returned by the listing operations: for a product, `display` and `definitions` are empty objects and `offer` is not included. |
| `delivery_id` | string | yes | ID of this delivery, prefixed with `whd_`, as in `GET /webhooks/{webhook_id}/deliveries/{webhook_delivery_id}`. Every retry of the delivery has the same ID. |
| `attempt` | integer | yes | Number of this attempt of the delivery, starting at 1. |

Your endpoint answers with any `2xx` status to confirm the delivery. See [Deliveries and retries](https://cademi.dev/webhooks/deliveries.md).
