---
title: "Webhooks overview"
icon: "bell"
description: "How to receive real-time events from iwoca, and the endpoints that manage them"
---

> For the complete documentation index, see [llms.txt](/llms.txt).

Webhooks let iwoca notify your system the moment something happens — an application is offered or declined, or a customer is funded.
You never have to poll.
There are two sides to webhooks in this API:

- **Endpoints you call** to configure your webhook URL and manage which events you receive.
- **Events iwoca sends** to your endpoint as `POST` requests when something happens.

<CardGroup cols={2}>
  <Card title="How webhooks work (guide)" icon="book" href="/guides/webhooks/overview">
    Concepts, base URL and end-to-end setup
  </Card>
  <Card title="Security" icon="shield" href="/guides/webhooks/security">
    Verify the `X-IW-Signature` header and handle retries
  </Card>
</CardGroup>

## Setting up

<Steps>
  <Step title="Configure your webhook URL and token">
    Set the endpoint iwoca should call using [`PUT /webhooks/configuration/`](/api-reference/webhook-management/put-webhooks-configuration). Read the current config with [`GET /webhooks/configuration/`](/api-reference/webhook-management/get-webhooks-configuration).
  </Step>
  <Step title="Subscribe to the events you want">
    Choose which events to receive with [`POST /webhooks/subscriptions/`](/api-reference/webhook-management/post-webhooks-subscriptions). Review your subscriptions with [`GET /webhooks/subscriptions/`](/api-reference/webhook-management/get-webhooks-subscriptions), and remove them with [`DELETE /webhooks/subscriptions/`](/api-reference/webhook-management/delete-webhooks-subscriptions).
  </Step>
  <Step title="Check available event types">
    See every event you can subscribe to with [`GET /webhooks/event_types/`](/api-reference/webhook-management/get-webhooks-event-types).
  </Step>
  <Step title="Verify signatures">
    Confirm each incoming webhook is from iwoca by checking the `X-IW-Signature` header — see [Security](/guides/webhooks/security).
  </Step>
</Steps>

<Warning>
Your webhook endpoint should respond with a `2xx` status code to confirm receipt.
Failed deliveries are retried up to 10 times over roughly 16 hours – see [retry behaviour](/guides/webhooks/security#retry-behaviour). Your subscription stays active either way; it is never disabled automatically.
</Warning>

## Events iwoca sends

Each event below is delivered as a `POST` to your configured URL. Follow the link for the exact payload schema.

| Event | When it fires |
| --- | --- |
| [`application_attributed`](/api-reference/webhooks/post-application-attributed) | An application is created for a customer and attributed to you. |
| [`application_offered`](/api-reference/webhooks/post-application-offered) | The customer receives a confirmed offer. |
| [`application_declined`](/api-reference/webhooks/post-application-declined) | A customer's application is declined. |
| [`application_deferred`](/api-reference/webhooks/post-application-deferred) | An application is deferred (closed without an approve/decline decision). |
| [`application_status_changed`](/api-reference/webhooks/post-application-status-changed) | The status of an application changes. |
| [`indicative_offer_created`](/api-reference/webhooks/post-indicative-offer-created) | An indicative offer is created. |
| [`customer_funded`](/api-reference/webhooks/post-customer-funded) | A customer draws down funds from an offer originating from your application. |
| [`funding_created_202607`](/api-reference/webhooks/post-funding-created-202607) | Funds are sent to a customer. |
| [`prequalification_202505`](/api-reference/webhooks/post-prequalification-202505) | Sent when a prequalification data file has been processed. Contains a prequalification quote for each unique `external_customer_id` in the uploaded file. |
| [`prequalification_data_file_processed_202510`](/api-reference/webhooks/post-prequalification-data-file-processed-202510) | Lighter version of `prequalification_202505`. Sent when a data file has been processed, but contains only the `prequalification_data_id` — pass it to `GET /prequalification_data` to retrieve the quotes. |
