# Access granted

Sent every time a delivery is added to a student by hand, from the dashboard or the API. A delivery granted by a sale fires only `delivery.add`. The event is `user.access.created` (`usuario.acesso.adicionado` in [payload version 1](https://cademi.dev/webhooks/v1/reference/usuario-acesso-adicionado.md)).

## Example body

```json
{
  "version": "2",
  "event": "user.access.created",
  "event_id": "01K5QW7M2Z3Y4X5W6V7U8T9S0R",
  "payload": {
    "delivery": {
      "id": 88,
      "type": "single",
      "config_url": "https://example.com",
      "external_ids": [
        "string"
      ],
      "name": "string"
    },
    "user": {
      "id": 1042,
      "access": {
        "first_at": {
          "iso": "2025-09-23T12:00:00-03:00",
          "unix": "1758639600"
        },
        "last_at": {
          "iso": "2025-09-23T12:00:00-03:00",
          "unix": "1758639600"
        }
      },
      "created": {
        "at": {
          "iso": "2025-09-23T12:00:00-03:00",
          "unix": "1758639600"
        },
        "by": 0,
        "by_key": 0,
        "method": "string",
        "on": "string"
      },
      "document": "string",
      "email": "maria@exemplo.com",
      "magic_login_url": "https://example.com",
      "name": "Maria Souza",
      "phone": "string"
    }
  }
}
```

## Fields

| Field | Type | Required | Description |
|---|---|---|---|
| `version` | string | yes | Always `2`. |
| `event` | string | yes | Always `user.access.created`. |
| `event_id` | string | yes | Unique id of the delivery (ULID). Retries of the same delivery keep it, so use it to ignore duplicates. |
| `payload` | object | yes |  |
| `payload.delivery` | object | yes | The delivery that granted the access: what a sale gives, per gateway product. |
| `payload.delivery.id` | integer | yes |  |
| `payload.delivery.type` | string | yes | `single` for a one-time sale, `recurrence` for a subscription. One of `single`, `recurrence`. |
| `payload.delivery.config_url` | string | yes | The delivery settings page in the dashboard. |
| `payload.delivery.external_ids` | array of string \| null | yes | The gateway product codes linked to the delivery. |
| `payload.delivery.name` | string | yes |  |
| `payload.user` | object | yes | The student the event is about. |
| `payload.user.id` | integer | yes |  |
| `payload.user.access` | object | yes |  |
| `payload.user.access.first_at` | object \| null | yes | First access; null before it happens. |
| `payload.user.access.first_at.iso` | string \| null | yes |  |
| `payload.user.access.first_at.unix` | string \| null | yes |  |
| `payload.user.access.last_at` | object \| null | yes | Last access; null before the first one. |
| `payload.user.access.last_at.iso` | string \| null | yes |  |
| `payload.user.access.last_at.unix` | string \| null | yes |  |
| `payload.user.created` | object | yes | How the student was created. `on` is the origin (`manual`, `transaction`, `import`, `free`, `redirect`, `google`, `api`); the other keys depend on it and may be absent. |
| `payload.user.created.at` | object \| null | yes | A point in time, as Unix seconds (a string) and ISO 8601 with the offset. Both are null when there is no date. |
| `payload.user.created.at.iso` | string \| null | yes |  |
| `payload.user.created.at.unix` | string \| null | yes |  |
| `payload.user.created.by` | integer | no | The administrator who created the student. |
| `payload.user.created.by_key` | integer | no | The API key that created the student. |
| `payload.user.created.method` | string | no |  |
| `payload.user.created.on` | string | no |  |
| `payload.user.document` | string \| null | yes | Document (CPF). |
| `payload.user.email` | string \| null | yes |  |
| `payload.user.magic_login_url` | string | yes | Link that signs the student in when opened. Treat it as a password. |
| `payload.user.name` | string \| null | yes |  |
| `payload.user.phone` | string \| null | yes | Mobile phone. |

Your endpoint answers with any `2xx` status to confirm the delivery. See [Deliveries and retries](https://cademi.dev/webhooks/deliveries.md).
