> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trdrs.co/llms.txt
> Use this file to discover all available pages before exploring further.

# List enrollment events

> **Preview: outside the additive-only guarantee.** These shapes are the pre-contract v1 scaffold; the Phase-1 rebuild will change them. Read them, do not pin to them.

**Served only when the engine runs with `CHALLENGES_ENABLED`.** The route bundle is not merely disabled without it. It is never constructed, so every path here answers `404`.

Returns the status history for one of the caller’s enrollments. Every threshold crossing is its own row, so an outcome can be reconstructed exactly. An enrollment belonging to another user is reported as `404`, indistinguishable from one that does not exist; ownership failures never confirm that an id is real.



## OpenAPI

````yaml /partner-platform/openapi.json get /api/enrollments/events
openapi: 3.1.0
info:
  title: trdrs Engine API
  version: 1.1.0
  description: >-
    ## API Reference


    This is the served OpenAPI contract for the trdrs engine: market data,
    trading and account

    routes for your firm's traders, trdrs Connect account-registration handoff,
    and preview

    challenge routes.


    See Quick Start for the first integration path: key setup, market config,
    chart data, Connect

    account registrations, idempotency, stream reconnects, and conformance.


    See Overview and API Standards for the cross-cutting contract rules.
servers:
  - url: https://app.trdrs.co
    description: Production
  - url: /
    description: This engine
security: []
tags:
  - name: Market data
    description: >-
      Symbol search and resolution, OHLCV history, quote snapshots, the server
      clock, and the live bar stream. Crypto rides each venue’s public feed;
      futures stream from the caller’s own connected Rithmic account. With none
      connected, futures requests answer 503 `feed_requires_connection`.
  - name: News
    description: >-
      Aggregated market news and the economic calendar, from licensed/open
      sources, keyword-tagged with futures roots at ingest. Platform-wide
      content (nothing per-user), admitted exactly like Market data: a licensed
      origin, a session, or a firm API key. Headlines page by published time,
      scope by instrument root, and stream live over SSE; thumbnails serve
      through the image proxy.
  - name: Trading
    description: >-
      The money surface: entries, exits, replaces, cancels, and position/account
      flattening. Every order-placing call uses `clientOrderId` as its
      idempotency key.
  - name: Account
    description: >-
      Reading a connected account. You do not create trading accounts here: a
      trader connects their own broker account (or creates a free demo account)
      in the app, and firms create evaluation accounts through the Partner API
      (Firm accounts → Create evaluation accounts) or register venue accounts
      through Connect (Create an account registration). Account state and the
      durable ledgers: balances, positions, working orders, fills, P&L history,
      and the live account stream.
  - name: Connect
    description: >-
      trdrs Connect account registration, for partner firms. Register an account
      you issued on your own venue — a pending account registration — with the
      trader’s sign-in email, optionally the venue account id and the login name
      your venue issued. The trader finds it waiting in the connect flow the
      moment they sign in with that email: the connect step is pre-filled with
      everything except the credential, which the trader always enters
      themselves. A registration never transmits a password and never grants
      access to anything before the trader’s own login succeeds. These routes
      answer a partner-scoped key only; a firm API key or a user session gets
      401. Registrations expire after 30 days; re-registering the same email +
      account refreshes the expiry instead of duplicating. The end-to-end flow
      guide is **[Quick Start](/docs/guides/quick-start)**.
  - name: Firm accounts
    description: >-
      Evaluation accounts your firm issues on the trdrs venue, through your
      partner key — the other half of account setup. Connect registrations hand
      off accounts that exist on your venue; these routes create and manage
      accounts on ours: the trader trades them on trdrs, and your firm owns the
      lifecycle. Every route is scoped to accounts your firm created through
      this API — an account the same trader opened themselves is invisible and
      untouchable here, by construction. Creation is batched with per-item
      results, and every write carries your own `referenceId`, so a crashed
      pipeline retries safely. Served when the deployment runs the prop engine;
      without it, every route in this group answers `404`.
  - name: Webhooks
    description: >-
      The outbound event bus: register an https endpoint and the platform pushes
      events to it instead of your back office polling us. Every delivery is
      signed (`trdrs-signature: t=<unix>,v1=<hmac-sha256>` over
      `${t}.${rawBody}`) so you can prove it came from us and is fresh, and
      every delivery is durable — a failed attempt is retried with backoff for
      about nine hours and the whole log is readable, so an endpoint that was
      down is a delay rather than a lost event. Serves brokers and prop firms
      alike: the account-registration (`registration.*`) events fire wherever
      Connect does, and the account events fire where the prop engine runs.
  - name: Challenges
    description: >-
      The prop evaluation surface: challenge programs and a trader’s own
      enrollments. **Preview: the one group on this page outside the
      additive-only guarantee** (the pre-contract v1 scaffold; the Phase-1
      rebuild will change these shapes; see Stability). **Cookie-authenticated,
      not key-authenticated**, and served only when the engine runs with
      `CHALLENGES_ENABLED`; without that flag the bundle is absent and every
      route below returns `404`. The firm-console/admin half of this surface is
      deliberately not documented here. It is back office, not licensed surface.
paths:
  /api/enrollments/events:
    get:
      tags:
        - Challenges
      summary: List enrollment events
      description: >-
        **Preview: outside the additive-only guarantee.** These shapes are the
        pre-contract v1 scaffold; the Phase-1 rebuild will change them. Read
        them, do not pin to them.


        **Served only when the engine runs with `CHALLENGES_ENABLED`.** The
        route bundle is not merely disabled without it. It is never constructed,
        so every path here answers `404`.


        Returns the status history for one of the caller’s enrollments. Every
        threshold crossing is its own row, so an outcome can be reconstructed
        exactly. An enrollment belonging to another user is reported as `404`,
        indistinguishable from one that does not exist; ownership failures never
        confirm that an id is real.
      parameters:
        - name: id
          in: query
          required: true
          schema:
            type: string
            format: uuid
          description: The enrollment id.
      responses:
        '200':
          description: The status events
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EnrollmentEventsResponse'
        '400':
          description: '`id` required, or no trading profile'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Not authenticated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: >-
            No such enrollment, it belongs to another user, or
            `CHALLENGES_ENABLED` is off
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - sessionCookie: []
      x-codeSamples:
        - lang: javascript
          label: TypeScript
          source: >-
            // First-party cookie auth: this runs in a signed-in trdrs session,
            not under an API key.

            const res = await
            fetch('https://app.trdrs.co/api/enrollments/events?id=e5c90b1a-7d34-4f6b-8a2e-91c8f0d47a53',
            {
              credentials: 'include',
            })

            const data = await res.json()
        - lang: shell
          label: cURL
          source: >-
            curl
            'https://app.trdrs.co/api/enrollments/events?id=e5c90b1a-7d34-4f6b-8a2e-91c8f0d47a53'
            \
              -b "session=$TRDRS_SESSION"
components:
  schemas:
    EnrollmentEventsResponse:
      type: object
      properties:
        events:
          type: array
          items:
            $ref: '#/components/schemas/EnrollmentEvent'
      required:
        - events
      example:
        events:
          - status: registered
            actor: system
            reason: null
            at: 1787058000
          - status: in_progress
            actor: system
            reason: first fill
            at: 1787144400
    ErrorResponse:
      type: object
      properties:
        error:
          type: string
      required:
        - error
      example:
        error: invalid_instrument
    EnrollmentEvent:
      type: object
      properties:
        status:
          type: string
        actor:
          type: string
          description: An admin's identity, or `system` for monitor-driven transitions.
        reason:
          type:
            - string
            - 'null'
        at:
          type: number
          description: Epoch seconds
      required:
        - status
        - actor
        - reason
        - at
  securitySchemes:
    sessionCookie:
      type: apiKey
      in: cookie
      name: session
      description: >-
        The signed session cookie of a logged-in trdrs user. First-party/browser
        only; a firm API key cannot reach a route secured this way.

````