HEXLE API

Rest-API

1.18.0

Course Self-Service, Account Tiers, and Enhanced Security 10.07.2026

The account deletion confirmation link in the email now correctly points to an absolute URL.

The company overview now shows whether a deletion is scheduled and when it takes effect.

Audit logs and IP checks now correctly resolve the actual client IP even behind proxies.

Deactivated staff members no longer block email uniqueness, while reactivation still checks for duplicates.

System admins can now delete individual Git security reports or clear a repository's entire history at once.

Post-checkout feedback can now only be submitted once per session.

Users now receive a confirmation email whenever their password is changed, and a matching confirmation when their email address is updated.

The new "Basic" account tier without a company context adds a Business upgrade option and a purchase history overview to the dashboard.

Published guides can now be hidden from the public documentation index while remaining reachable via direct link.

A new public endpoint lists all published guides in the documentation.

Business users can now switch their session out of company context into a Basic mode without changing their account tier.

Even with a restricted Basic session, public pages such as maintenance status or release notes remain reachable.

From a restricted Basic session, users can now switch straight back into their company or employee context without logging in again.

When a user belongs to multiple companies or holds multiple employee roles, switching to a Business account now goes through the familiar login dialog, and after an account upgrade the return only leads to trusted destinations.

Feedback entries now record which page or link they were submitted from.

In the self-service area, course participants can now report absences, check their credit balance, and redeem it for another course's waiting list.

Trainers can now keep an attendance list per course session with freely definable columns.

After a course ends, participants automatically receive a certificate of participation as a PDF by email or for download.

Missed course sessions can now be made up in compatible replacement sessions, complete with an approval and confirmation workflow.

The new attendance, make-up session, and certificate features are now secured with dedicated, more precise permissions instead of coarse read/write access.

Test and demo environments can now generate realistic sample data at the push of a button.

Login integration and base configuration are now in place for the new HEXLE Education and HEXLE Office products.

Company owners can transfer ownership of a company to another person via email confirmation.

Based on their email domain, users will now be signed in automatically through an external identity provider that companies can configure themselves.

System admins can now manually unlock individual add-on modules for companies, the WebUntis integration was extended, and several errors reported by Sentry were fixed.

In the school module, students can now be created, edited, and assigned to classes directly.

Rebooking a registration into a fully booked course now returns a specific error code instead of a generic message.

School years can now be managed, and class memberships are automatically synced with WebUntis, including logging of the notifications sent.

Companies can now manage teams with members and sign in via a passwordless login link.

Timesheet sync reports are now visible and deletable on a per-team basis, with revised tracking intervals and a reworked notification template.

The public HTML homepage has been removed, while login and redirects remain reachable unchanged.

Logged-in customers can now view all their public course and appointment bookings together under "My Bookings".

When a spot opens up due to a cancellation, it's now automatically offered to the next person on the waiting list.

Existing booking records with invalid database values no longer cause crashes in the new waitlist feature.

Automatic username assignment is now backed by additional unit tests.

Companies within their deletion period now see a banner on the dashboard showing the time remaining until permanent deletion.

The ticket endpoints in the API documentation now come with clear, readable descriptions.

The scanner endpoint in the API documentation has been given a clear description.

The time tracking (LZE) endpoints are now clearly described in the API documentation as well.

The course date ID in enrollment responses is now covered by regression tests.

Cancellations of customer products now take effect only after a one-month notice period, as specified in the terms and conditions.

Addresses can now be created and edited without selecting an address type, without triggering an error.

Payment reminders are no longer sent for course enrollments that have no outstanding balance.

Further-reading links in system emails now point to the new Help Center instead of the old terms and conditions pages.

Checkout now automatically calculates the correct destination-country VAT for EU orders, including reverse charge for business customers, and this update also fixed bugs affecting team invitations and course credits.