> For the complete documentation index, see [llms.txt](/llms.txt).

# Configure webhook url and token

**PUT** `https://www.iwoca.co.uk/api/lending/v2.2/webhooks/configuration/`

## Body
```json
{
  "data": {
    "regenerate_webhook_secret_token": false,
    "webhook_url": "https://partner.example.com/iwoca-webhook/"
  }
}
```

### Body fields
- `data` (object, required)
- `data.regenerate_webhook_secret_token` (boolean) — When `true`, generates a new secret token (used to sign webhook payloads) and replaces the existing one. Existing webhook deliveries will be signed with the new token from this point forward. Defaults to `false`.
- `data.webhook_url` (string, required) — The base URL iwoca will POST to when sending webhooks. Must be HTTPS.

## Responses
### 202 — Webhook url and token successfully configured

### 400 — Bad Request
```json
{
  "errors": [
    {
      "code": "string",
      "detail": "string",
      "meta": {},
      "source": {
        "parameter": "string",
        "pointer": "string"
      }
    }
  ]
}
```

### 401 — Unauthorized
```json
{
  "errors": [
    {
      "code": "AuthenticationFailed",
      "detail": "string",
      "meta": {}
    }
  ]
}
```

### 403 — Permission Denied
```json
{
  "errors": [
    {
      "code": "PermissionDenied",
      "detail": "string",
      "meta": {}
    }
  ]
}
```

### 500 — Unexpected Error
```json
{
  "errors": [
    {
      "code": "string",
      "detail": "string",
      "meta": {}
    }
  ]
}
```

## Example (curl)
```bash
curl https://www.iwoca.co.uk/api/lending/v2.2/webhooks/configuration/ \
  --request PUT \
  --header 'Authorization: Bearer <api-key>' \
  --header 'Content-Type: application/json' \
  --data '{
  "data": {
    "regenerate_webhook_secret_token": false,
    "webhook_url": "https://partner.example.com/iwoca-webhook/"
  }
}'
```