---
title: "Overview"
icon: "file-lines"
description: "Authentication, base URLs, and endpoint flows by integration type"
---

> For the complete documentation index, see [llms.txt](/llms.txt).

The iwoca Lending API lets you refer customers for business finance, track their application, and surface offers.
The endpoints you call depend on your integration type.

<CardGroup cols={3}>
  <Card title="Customers" icon="user" href="/api-reference/customer/overview">
    Create and manage customers
  </Card>
  <Card title="Applications" icon="rectangle-list" href="/api-reference/application/overview">
    Submit loan applications
  </Card>
  <Card title="Offers" icon="hand-holding-dollar" href="/api-reference/offers/overview">
    Retrieve and select offers
  </Card>
  <Card title="Documents" icon="folder-open" href="/api-reference/documents/overview">
    Upload supporting documents
  </Card>
  <Card title="Prequalification" icon="filter" href="/api-reference/prequalification/overview">
    Check eligibility before applying
  </Card>
  <Card title="Webhooks" icon="bell" href="/api-reference/webhooks/overview">
    Real-time status notifications
  </Card>
</CardGroup>

## Endpoint flow by integration type

<Tabs>
  <Tab title="API Lite">
    Create a customer and hand off to iwoca.

    <Steps>
      <Step title="POST /customers/">
        Create the customer with company and director details.
      </Step>
      <Step title="POST /customers/{customer_id}/applications/">
        Submit a loan application with the requested amount.
      </Step>
      <Step title="GET /customers/{customer_id}/login_link/">
        Redirect the customer to iwoca to complete the process.
      </Step>
    </Steps>
  </Tab>
  <Tab title="API Plus">
    Surface offers and handle selection in your UI before handing off.

    <Steps>
      <Step title="POST /customers/">
        Create the customer with full details for automated decisions.
      </Step>
      <Step title="POST /customers/{customer_id}/applications/">
        Submit a loan application with the requested amount.
      </Step>
      <Step title="GET /applications/{application_id}/offers/">
        Retrieve offers (may take up to 30s on first call).
      </Step>
      <Step title="GET /customers/{customer_id}/login_link/">
        Customer selects an offer – get a login link, passing their chosen offer as `offer_id`, and redirect them to iwoca.
      </Step>
    </Steps>
  </Tab>
</Tabs>

## Additional endpoints

Beyond the core flow, you can use additional endpoints for document uploads, repayment schedules, funding account details, prequalification, and more.
Browse the sidebar to explore all endpoints.

---

## Authentication

<CardGroup cols={1}>
  <Card title="Check authentication" icon="code" href="/api-reference/authentication-check/get-authentication-check">
    `GET` /authentication_check/
  </Card>
</CardGroup>

```bash
curl -X GET https://stage.iwoca-dev.co.uk/api/lending/v2.2/authentication_check/ \
  -H "Authorization: Bearer {your_api_token}" \
  -H "Accept: application/json"
```

```json Response
{
  "data": {
    "api_version": "2.2.0"
  }
}
```

<Steps>
  <Step title="Get your API token">
    Retrieve your token from the [Partner Developer Portal](https://stage.iwoca-dev.co.uk/login/).
    You'll have separate tokens for sandbox and production.
  </Step>
  <Step title="Set required headers">
    Every request needs `Authorization` and `Accept`.
    POST/PATCH requests also need `Content-Type`.
  </Step>
  <Step title="Verify your connection">
    Call `GET /authentication_check/` to confirm everything is working before building your integration.
  </Step>
</Steps>

## Reference

<AccordionGroup>
  <Accordion title="Base URLs">
    | Environment | URL |
    |---|---|
    | Sandbox | `https://stage.iwoca-dev.co.uk/api/lending/v2.2` |
    | Production | `https://www.iwoca.co.uk/api/lending/v2.2` |
  </Accordion>
  <Accordion title="Required headers">
    | Header | Value | When |
    |---|---|---|
    | `Authorization` | `Bearer {token}` | Every request |
    | `Accept` | `application/json` | Every request |
    | `Content-Type` | `application/json` | POST/PATCH requests |
  </Accordion>
</AccordionGroup>
