# Drillster > Drillster is a Utrecht-based adaptive learning platform for corporate and vocational > training. Its REST API (version 2.1.1, JSON over HTTPS, OAuth 2.0) provisions user > accounts, manages groups and group membership, publishes drills, courses and tests, and > retrieves proficiency, objective and test results. An outbound event notification service > pushes seven event types to subscriber webhooks, and an embeddable widget family puts the > Drillster player, tiles, repertoire and identity surfaces inside a customer's own site. Generated by API Evangelist on 2026-09-06 from the provider's own public documentation. Drillster does not publish an llms.txt of its own: https://www.drillster.com/llms.txt and https://drillster.com/llms.txt both returned HTTP 404 on 2026-09-06. ## API - [Drillster REST API 2.1.1 reference](https://www.drillster.com/info/developers/api/2.1.1/): the full contract โ€” overview, status codes, error responses, date and request formats, versioning policy - [Endpoint index](https://www.drillster.com/info/developers/api/2.1.1/endpoints/): roughly 180 documented endpoints across users, groups, drills, tests, catalogs, objectives, organizations and repertoire - [Object index](https://www.drillster.com/info/developers/api/2.1.1/objects/): roughly 200 documented response objects - Base URL: https://www.drillster.com/api/2.1.1 - Version endpoint (unauthenticated): https://www.drillster.com/api/2.1.1/version ## Authentication - [OAuth 2.0 overview](https://www.drillster.com/info/developers/rest-apis/oauth/): bearer tokens in the Authorization header, HTTPS only - [JWT authorization grant](https://www.drillster.com/info/developers/rest-apis/oauth/jwt-authorization-grant/): the server-to-server path, RFC 7523 ยง2.1, grant_type urn:ietf:params:oauth:grant-type:jwt-bearer - [Authorization code grant](https://www.drillster.com/info/developers/rest-apis/oauth/authorization-code-grant/): the end-user path, with refresh tokens - [Service accounts](https://www.drillster.com/info/developers/rest-apis/service-accounts/): non-human accounts with an RSA key pair for API integrations - [Registering your application](https://www.drillster.com/info/developers/rest-apis/registering-your-application/): client ID and client secrets; confidential clients only - [Authorization server metadata](https://www.drillster.com/.well-known/oauth-authorization-server): RFC 8414 discovery document ## Events and webhooks - [Event notification service](https://www.drillster.com/info/developers/api/push/): seven event types, HTTPS POST/PUT delivery, optional basic auth - [Event catalogue](https://www.drillster.com/info/developers/api/push/events/): ACCOUNT_CREATED, GROUP_MEMBER_ADDED, GROUP_MEMBER_REMOVED, OBJECTIVE_BECAME_OK, OBJECTIVE_BECAME_NOK, QUESTION_ANSWERED, TEST_COMPLETED - [Webhook setup](https://www.drillster.com/info/developers/api/push/webhooks/): created and connected in the console, scoped to the organization or to groups - [Retry mechanism](https://www.drillster.com/info/developers/api/push/retry/): at-least-once, in-order per queue, 30-second acknowledgement window, 7 days of retries ## Widgets - [Widget overview](https://www.drillster.com/info/developers/widgets/): iframe components plus a 4KB loader at https://www.drillster.com/widgets/loader.js - [Player](https://www.drillster.com/info/developers/widgets/player/), [Tile](https://www.drillster.com/info/developers/widgets/tile/), [Repertoire](https://www.drillster.com/info/developers/widgets/repertoire/), [Identity](https://www.drillster.com/info/developers/widgets/identity/), [Subscription](https://www.drillster.com/info/developers/widgets/subscription/), [Access code](https://www.drillster.com/info/developers/widgets/access-code/) ## LMS integration - [Typical LMS integration](https://www.drillster.com/info/developers/typical-lms-integration/) - [LTI](https://www.drillster.com/info/developers/integration-types/lti/): LTI 1.0 and LTI 1.3, with just-in-time account provisioning and SSO - [SCORM](https://www.drillster.com/info/developers/integration-types/scorm/): SCORM 1.2 only; SCORM 2004 is not supported - [OpenID Connect SSO](https://www.drillster.com/info/developers/integration-types/open-id-connect/): Drillster acts as the relying party against the customer's identity server - [Microsoft Entra ID](https://www.drillster.com/info/developers/integration-types/open-id-connect/ms-entra-id/) ## Company - [Developer documentation](https://www.drillster.com/info/developers/) - [Pricing](https://drillster.com/en/pricing): one annual per-user enterprise plan, projects starting at EUR 5,000 per year - [Integrations](https://drillster.com/en/integrations) - [Support](https://support.drillster.com/hc/en-us) and support@drillster.com - [Blog](https://drillster.com/en/blog) - [Terms](https://drillster.com/en/terms) and [Privacy](https://drillster.com/en/privacy) - [Responsible disclosure](https://www.drillster.com/info/reporting-security-breach/) and [security.txt](https://www.drillster.com/.well-known/security.txt) - [Console](https://www.drillster.com/console) and [developer applications](https://www.drillster.com/developer/applications) - [GitHub](https://github.com/drillster) ## Notes for agents - Write bodies are `application/x-www-form-urlencoded` form posts, not JSON. Responses are JSON. - Errors are a proprietary two-field object โ€” `{"id": "...", "description": "..."}` โ€” not RFC 9457. Branch on `id`. - Pagination is cursor-style: `resultFrom` (id of the last item on the previous page) plus `resultSize`; the `pagination` object returns `total`, `lastOnPage` and `moreAvailable`. - There is NO idempotency key and no documented replay protection on writes. - There is NO documented undo, restore or retention window on any DELETE. Treat deletes as final. - No rate limits, quotas or rate-limit headers are published; Drillster reserves the right to throttle. - There is no sandbox or test mode, no OpenAPI, no MCP server, no A2A agent card and no client SDK.