# Coorpacademy > Coorpacademy (marketed since 2022 as "Coorpacademy by Go1") is a Swiss-French B2B corporate > digital-learning platform — a learning experience platform built on inverted pedagogy and gamified > micro-learning, serving brand-scoped learning portals, a course and certification catalogue, skills > taxonomies, learner progression, adaptive review and HR analytics to large European enterprises. GENERATED BY API EVANGELIST. Coorpacademy publishes no llms.txt of its own (https://www.coorpacademy.com/llms.txt returns HTTP 500; https://api.coorpacademy.com/llms.txt returns 404, probed 2026-08-17). This file is assembled from Coorpacademy's own public specifications and pages and is not a provider-authored document. ## What Coorpacademy actually exposes Coorpacademy does not run a developer portal, and there is no signup, no pricing and no key-issuance page. What it does publish is a **public Swagger UI at https://api.coorpacademy.com/** which indexes **fourteen REST services — 96 paths and 155 operations in total**. Those specifications are the entire machine-readable public surface, and they are real: harvested verbatim 2026-08-17 into `openapi/`. Eight of the fourteen documents are OpenAPI 3.0.0; six are still Swagger 2.0, including the two most operationally important services (platform and progression). None is OpenAPI 3.1. ## The fourteen services - [Content API](https://api.coorpacademy.com/?urls.primaryName=api-content): base `https://content.coorpacademy.com/api/v2` — external courses and contents, skills, custom skills, certifications, custom playlists, bulk external-content ingest, video scripts, notifications, and consumption counters. 39 paths / 53 operations / 63 schemas. Spec also served at `https://content.coorpacademy.com/api-docs`. Auth: `authorization` header. - [Platform API](https://api.coorpacademy.com/?urls.primaryName=api-platform): base `https://platform.coorpacademy.com/api/v1` — brand (tenant) CRUD, brand migration, and per-brand SSO configuration including SAML metadata.xml extraction. 6 paths / 9 operations. Auth: `authentication` header. - [Progression API](https://api.coorpacademy.com/?urls.primaryName=api-progression): base `https://progression.coorpacademy.com/api` — the learner progression engine (moves, answers, clues, resource views, extra lives) plus a v2 analytics read surface. 21 paths / 26 operations. Auth: `authentication` header. - [Progression Aggregations API](https://api.coorpacademy.com/?urls.primaryName=api-progression-aggregations): base `https://aggregation-progression.coorpacademy.com/api` — DynamoDB-backed analytics aggregates. 3 paths / 5 operations. - [SCIM API](https://api.coorpacademy.com/?urls.primaryName=scim): base `https://api.coorpacademy.com/scim` — SCIM 2.0 user provisioning per brand (LIST, CREATE, FIND, PUT, PATCH on `/{brand}/Users`). Returns genuine RFC 7644 error envelopes. Auth: `token` header. - [SCORM Content API](https://api.coorpacademy.com/?urls.primaryName=api-content-scorm): base `https://api.coorpacademy.com/content-scorm` — the SCORM player runtime (slides, chapters, levels, exit nodes, answers, clues, extra lives, LMS API shim, launch URL) and Go1 enrolment-to-progression lookup. 16 paths / 16 operations. Auth: `Authorization` header. - [SCORM API](https://api.coorpacademy.com/?urls.primaryName=api-scorm): base `https://api.coorpacademy.com/scorm` — presigned S3 upload for single and bulk SCORM packages, plus package file serving. 4 operations. - [Email API](https://api.coorpacademy.com/?urls.primaryName=api-mail): base `https://api.coorpacademy.com/mail` — 27 Mandrill-backed transactional email sends, one per template. Auth: `Authorization` header. - [Mobile API](https://api.coorpacademy.com/?urls.primaryName=api-mobile): base `https://api.coorpacademy.com/mobile` — minimum installable app version per key. Auth: `Api-Secret` header. - [Review API](https://api.coorpacademy.com/?urls.primaryName=api-review): base `https://api.coorpacademy.com/review` — adaptive review mode: skills available to review and the next review slide. Auth: `authorization` header. - [H5P API](https://api.coorpacademy.com/?urls.primaryName=api-h5p): base `https://api.coorpacademy.com/h5p` — serves files from unpacked H5P packages. Auth: `token` header. - [External Resources API](https://api.coorpacademy.com/?urls.primaryName=api-external): base `https://api.coorpacademy.com/external` — presigned S3 upload for external content. - [Media API](https://api.coorpacademy.com/?urls.primaryName=api-media): base `https://api.coorpacademy.com/api-service` — media upload and image resize. - [PDF API](https://api.coorpacademy.com/?urls.primaryName=api-pdf): base `https://api.coorpacademy.com/pdf` — render a URL to PDF (certificates, reports). ## Things an agent must know before calling anything - **There is no single auth header.** Five different API-key header names are used across the estate: `authorization` (content, review), `Authorization` (content-scorm, mail, scorm), `token` (h5p, scim), `authentication` (platform, progression, progression-aggregations), `Api-Secret` (mobile). Two of those differ only by letter case. Three services (external, media, pdf) declare no security scheme at all even though the edge rejects unauthenticated calls. Read the per-service spec. - **No OAuth, no OIDC, no bearer tokens.** No `/.well-known/` document is served on any host (every path 404s; the www and api hosts 301 into an empty S3 bucket). - **No idempotency.** Zero matches for "idempoten" across all 155 operations. The 27 email-send operations, SCIM user creation and every presigned-URL mint have no replay-safe primitive. Do not blind-retry a POST. - **No rate limits and no rate-limit headers.** Zero 429s declared, no `RateLimit-*`, `X-RateLimit-*` or `Retry-After` observed live. Self-throttle. - **Three different error envelopes.** An Express `{id, code, status, success, message, errors[]}` shape (content, platform, progression), a bare `{message}` shape (content, mail, and the AWS API Gateway edge), and a genuinely conformant SCIM 2.0 error envelope (scim only). No `application/problem+json` anywhere. `code` was the string `"server_error"` on every live body observed, including a 401. - **Everything is tenant-scoped.** "Brand" (platform, SCIM) and "repository" (content) are the tenant boundary. You must know which brand you are acting for before any call. - **Content is addressed by (repository, ref, version)** — no object ids, no URNs, no UUIDs. A 409 on write means that triple already exists. - **Authoring is split edition / snapshot / consommation.** Certifications, custom skills and custom playlists exist as an editable EDITION, a published SNAPSHOT and a learner-facing CONSOMMATION, with a `PUT .../{ref}/undo` to revert. **Writing to the edition does not change what learners see.** This is the single most common way to get this API wrong. - **No events, no webhooks, no xAPI.** There is no AsyncAPI document, no callbacks block, no subscription endpoint and no LRS. Change detection means polling. - **No SDKs.** Coorpacademy publishes 73 first-party npm packages and not one of them is an API client. You write your own HTTP client. ## Getting access There is no self-serve path. No signup page, no pricing page (`/pricing` returns HTTP 500), no documented key-issuance flow. API access is negotiated inside a platform contract. Commercial contact now routes to Go1: https://www.go1.com/fr/speak-with-an-expert-old ## Corporate context Coorpacademy was founded in 2013 (co-founded by ex-Google France country manager Jean-Marc Tassetto, with instructional design backed by EPFL innovation labs) and was acquired by Australian edtech Go1 in April 2022. The English-language front door has since been handed to Go1: https://www.coorpacademy.com/en/ and /en/blog/ both 302 to https://www.go1.com/?source=coorp, and the APIs themselves carry Go1 integration points (`POST /content-scorm/getProgressionFromEnrolment` maps a Go1 `enrolment_id` to a Coorpacademy progression; `POST /mail/api/v1/go1Subscription` sends a Go1 subscription request). Anyone integrating should ask Go1 how long api.coorpacademy.com will be served — no deprecation policy is published. ## Human pages - Website: https://www.coorpacademy.com/ - API reference (Swagger UI): https://api.coorpacademy.com/ - Support / FAQ: https://support.coorpacademy.com/ - Blog: https://www.coorpacademy.com/blog - Status page: https://coorpacademy.status.io/ (machine-readable: https://api.status.io/1.0/status/59c0fe78af68b1046e096a85) - Legal notices and terms: https://www.coorpacademy.com/mentions-legales/ - Privacy policy (RGPD, last updated 2020-04-14): https://www.coorpacademy.com/privacy-policy/ - Accessibility: https://www.coorpacademy.com/accessibilite/ - GitHub organisation: https://github.com/CoorpAcademy ## Optional - Certification: Qualiopi "actions de formation" mark displayed in the site footer. No ISO 27001, no SOC 2, no trust centre, no security.txt, no vulnerability-disclosure policy. - Open source: 73 npm packages under `@coorpacademy` — a React design system (`@coorpacademy/components`, 2,444 releases), the slide player, the review app, and the `serverless-plugins` family (SQS/SNS/Kinesis/S3/DynamoDB-Streams/EventBridge emulators, 230 GitHub stars, last released 2026-07-07). Also the `baucis` forks that generate these very specifications. ## API Evangelist profile - Profile: https://apis.io/provider/coorpacademy/ - Machine-readable index: https://raw.githubusercontent.com/api-evangelist/coorpacademy/refs/heads/main/apis.yml - Harvested specifications, derived conventions, error catalogue, data model, conformance assessment and agent skills: https://github.com/api-evangelist/coorpacademy