Webhooks overview
How to receive real-time events from iwoca, and the endpoints that manage them
Webhooks let iwoca notify your system the moment something happens — an application is offered or declined, or a customer is funded. You never have to poll. There are two sides to webhooks in this API:
- Endpoints you call to configure your webhook URL and manage which events you receive.
- Events iwoca sends to your endpoint as
POSTrequests when something happens.
Concepts, base URL and end-to-end setup
Verify the X-IW-Signature header and handle retries
Setting up
- 1Configure your webhook URL and token
Set the endpoint iwoca should call using
PUT /webhooks/configuration/. Read the current config withGET /webhooks/configuration/. - 2Subscribe to the events you want
Choose which events to receive with
POST /webhooks/subscriptions/. Review your subscriptions withGET /webhooks/subscriptions/, and remove them withDELETE /webhooks/subscriptions/. - 3Check available event types
See every event you can subscribe to with
GET /webhooks/event_types/. - 4Verify signatures
Confirm each incoming webhook is from iwoca by checking the
X-IW-Signatureheader — see Security.
Your webhook endpoint should respond with a 2xx status code to confirm receipt.
Failed deliveries are retried up to 10 times over roughly 16 hours – see retry behaviour. Your subscription stays active either way; it is never disabled automatically.
Events iwoca sends
Each event below is delivered as a POST to your configured URL. Follow the link for the exact payload schema.
| Event | When it fires |
|---|---|
application_attributed | An application is created for a customer and attributed to you. |
application_offered | The customer receives a confirmed offer. |
application_declined | A customer's application is declined. |
application_deferred | An application is deferred (closed without an approve/decline decision). |
application_status_changed | The status of an application changes. |
indicative_offer_created | An indicative offer is created. |
customer_funded | A customer draws down funds from an offer originating from your application. |
funding_created_202607 | Funds are sent to a customer. |
prequalification_202505 | Sent when a prequalification data file has been processed. Contains a prequalification quote for each unique external_customer_id in the uploaded file. |
prequalification_data_file_processed_202510 | Lighter version of prequalification_202505. Sent when a data file has been processed, but contains only the prequalification_data_id — pass it to GET /prequalification_data to retrieve the quotes. |