Add quiz

Creates a new quiz in the current member's quizzes folder, proxying to Plone's content-creation REST API after sanitizing the submitted rich content.

POST /++addQuiz

Quiz Management

Authentication

Requires an authenticated (logged-in) account. Also requires a registered Integrator subscription.

This endpoint requires the calling application to be registered as an Integrator. Every call must identify the registration via a registration_id parameter (or an X-Client-Id header), and authenticate using one of the following methods, selected with the subscription_method parameter:

  • referer — The request's HTTP Referer header must match one of the domains authorized for this Integrator registration.
  • ip — The request's source IP address must match one of the IP addresses authorized for this Integrator registration.
  • client_token — A client token issued at registration time is supplied with the request.

Register as an Integrator and configure authorized domains, IP addresses, or a client token.

Request

Content type: application/json

NameInTypeRequiredDescription
REQUEST_METHODbodystringNo—
quiz_idbodystringNo—
BODYbodystringNo—
rich_detailsbodystringNo—
timebodystringNo—
QUERY_STRINGbodystringNo—
questionsbodystringNo—
review_statebodystringNo—
additional_toolsbodystringNoSent by the web client (found via frontend call-site tracing).
enabled_toolsbodybooleanNoSent by the web client (found via frontend call-site tracing).
gamifiedbodybooleanNoSent by the web client (found via frontend call-site tracing).
imagebodystringNoSent by the web client (found via frontend call-site tracing).
quiz_modebodystringNoSent by the web client (found via frontend call-site tracing).
quiz_stylebodystringNoSent by the web client (found via frontend call-site tracing).
randomize_questionsbodybooleanNoSent by the web client (found via frontend call-site tracing).
subjectsbodystringNoSent by the web client (found via frontend call-site tracing).
themebodystringNoSent by the web client (found via frontend call-site tracing).
quiz_linkquerystringNoSent by the web client (found via frontend call-site tracing).
quiz_uidquerystringNoSent by the web client (found via frontend call-site tracing).

Example request body

{
  "REQUEST_METHOD": "referer",
  "quiz_id": "12345",
  "BODY": "example_value",
  "rich_details": "A brief description goes here.",
  "time": "2026-01-15T10:30:00Z",
  "QUERY_STRING": "example_value",
  "questions": "example_value",
  "review_state": "published"
}

Responses

StatusMeaning
200Successful response.
400Missing quiz id
403Forbidden - the current user or Integrator registration does not have sufficient permissions.
404Administration folder not found
409Conflict - the request could not be completed due to a conflict with existing data.
500Unexpected error: ...
401Unauthorized - missing or invalid Integrator authentication (registration_id/X-Client-Id, plus referer/IP/client_token).

Example response (illustrative - field names only, values are placeholders)

{
  "status_code": "published",
  "message": "example_value",
  "@id": "https://example.com/rest-api/sample-object",
  "UID": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4"
}