> For the complete documentation index, see [llms.txt](/llms.txt).

# application_attributed

**Webhook event:** `application_attributed`

Sent when an application is created for a customer and attributed to you. This covers applications created:

1. By you, over the API.
2. By your team, via the iwoca Introducer Portal.
3. By iwoca staff, and attributed to you.
4. By the customer themselves — for example through your affiliate signup flow — and attributed to you.

### When an application is moved to another customer

If you submit an application for a customer who already exists in iwoca's system under a different `customer_id`, iwoca staff close your application and create a replacement on the existing customer. Your original application ends up with the status `deferred`.

You will receive this webhook with:

1. `previous_customer_id` and `previous_application_id` — the IDs you originally submitted.
2. `current_customer_id` — the customer the replacement application was created on.
3. `current_application_id` — the replacement application itself.

**Use `current_customer_id` and `current_application_id` from then on.** The previous pair no longer points at a live application.

## Header parameters
- `X-IW-Event-ID` (string, required) — UUID of the webhook event. Webhooks which do not deliver successfully are retried. This will be the same across retry attempts for the same webhook.
- `X-IW-Event-Type` (string, required) — The type of webhook being delivered — matches the `webhook_event_type` values from `GET /webhooks/event_types/`.
- `X-IW-Signature` (string, required) — HMAC-SHA256 signature of the request body, base64-encoded and prefixed with `sha256=`. The HMAC key is your webhook secret token (not your API token), which you can fetch from the iwoca Notifications API or the Developer Portal. Verify this header to confirm the webhook is genuinely from iwoca and to mitigate replay attacks (by also checking that `X-IW-Timestamp` is recent). Retried deliveries get a fresh timestamp and therefore a fresh signature.

```
message   = "{X-IW-Timestamp}.{raw_request_body}"
signature = "sha256=" + base64(hmac_sha256(secret, message))
```
- `X-IW-Timestamp` (string, required) — Unix timestamp (seconds) at which the delivery was initiated. If this delivery is a retry of an earlier failed delivery, the timestamp is of the current attempt, not the original delivery.

## Payload
```json
{
  "data": {
    "current_application_id": "a5c3f20f-0912-4b3b-a15a-3b711e9ced58",
    "current_customer_id": "a7fe5409-8ce8-4551-9c37-d8e52fccbd0a",
    "previous_application_id": "86665004-f599-4312-baf6-f11a4f4f7596",
    "previous_customer_id": "64c0d004-3526-43d4-a86b-0527fbd656e8"
  }
}
```

### Payload fields
- `data` (object, required)
- `data.current_application_id` (string, required) — application_id of the application which was just created or assigned to you
- `data.current_customer_id` (string, required) — customer_id on which the current_application_id exists
- `data.previous_application_id` (string) — application_id of the application this replaces, if any
- `data.previous_customer_id` (string) — customer_id on which previous_application_id existed

## Responses
### 201 — Return status code 200 or 201 to acknowledge receipt of the webhook. Any non-2XX response code will result in iwoca retrying the delivery.
