> For the complete documentation index, see [llms.txt](/llms.txt).

# application_offered

**Webhook event:** `application_offered`

Sent when the customer receives a confirmed offer

## Header parameters
- `X-IW-Event-ID` (string, required) — UUID of the webhook event. Webhooks which do not deliver successfully are retried. This will be the same across retry attempts for the same webhook.
- `X-IW-Event-Type` (string, required) — The type of webhook being delivered — matches the `webhook_event_type` values from `GET /webhooks/event_types/`.
- `X-IW-Signature` (string, required) — HMAC-SHA256 signature of the request body, base64-encoded and prefixed with `sha256=`. The HMAC key is your webhook secret token (not your API token), which you can fetch from the iwoca Notifications API or the Developer Portal. Verify this header to confirm the webhook is genuinely from iwoca and to mitigate replay attacks (by also checking that `X-IW-Timestamp` is recent). Retried deliveries get a fresh timestamp and therefore a fresh signature.

```
message   = "{X-IW-Timestamp}.{raw_request_body}"
signature = "sha256=" + base64(hmac_sha256(secret, message))
```
- `X-IW-Timestamp` (string, required) — Unix timestamp (seconds) at which the delivery was initiated. If this delivery is a retry of an earlier failed delivery, the timestamp is of the current attempt, not the original delivery.

## Payload
```json
{
  "data": {
    "application_id": "b71ffccf-cdf3-4218-9a4f-f0a7238f1769",
    "approximate_apr": 0.842513,
    "customer_id": "07cd75a9-95dc-4123-ade9-b09ad0165d39",
    "duration": {
      "amount": 730,
      "unit": "days"
    },
    "expiry_date": "2026-06-25",
    "external_customer_id": "12345",
    "fee_percentage": 5,
    "interest_only_repayments": 0,
    "interest_rates": [
      {
        "as_of": 0,
        "rate": 0.0515
      }
    ],
    "is_closed": true,
    "max_amount": 18000,
    "offer_id": "a8fa3eca-3e49-4e31-8ceb-0491e7096475",
    "payment_interval": "1m",
    "personal_guarantee_proportion": 100,
    "product_type": "flexi_loan",
    "promotions": [],
    "revoked_at": "2024-01-01T00:00:00Z"
  }
}
```

### Payload fields
- `data` (object, required)
- `data.application_id` (string, required)
- `data.approximate_apr` (number, required) — Approximate Annual Percentage Rate as a decimal. For example, 0.3995 means 39.95%. Note that this may differ to how this field is presented in the /offers endpoint, depending on which version you're using.
- `data.customer_id` (string, required)
- `data.duration` (object, required)
- `data.duration.amount` (number, required)
- `data.duration.unit` (string, required) — In practice, always days
- `data.expiry_date` (string, required) — The date on which the offer expires
- `data.external_customer_id` (string) — The optional external_customer_id you sent in the POST /customers request when creating the customer
- `data.fee_percentage` (number) — What percentage of the amount borrowed will be added to the loan as a fee when the customer takes the money
- `data.interest_only_repayments` (integer, required) — Some offers have an interest-only period. For example if the `payment_interval` is `1m` and `interest_only_repayments` is `3`, the first three months of the loan are interest-only which means the first three repayments due will be lower than the normal repayments
- `data.interest_rates` (array, required) — Interest rate of the offer. Returned as a list but in practice there will be one item.
- `data.interest_rates[].as_of` (integer, required) — Unused
- `data.interest_rates[].rate` (number, required) — Interest rate as a decimal. For example, 0.028 means the interest rate is 2.8%. Note that this may differ to how this field is presented in the /offers endpoint, depending on which version you're using.
- `data.is_closed` (boolean, required) — Whether the application is closed. Usually, receiving a confirmed offer closes the application. Sometimes iwoca returns a confirmed offer for a smaller amount alongside an indicative offer for a larger amount, and the application remains open.
- `data.max_amount` (number, required)
- `data.offer_id` (string, required)
- `data.payment_interval` (string, required) — How often repayments are due. (In practice, monthly).
- `data.personal_guarantee_proportion` (number, required) — What percentage of the loan will be covered by a personal guarantee. For example, 100 for a normal loan or 0 for a loan with no PG required
- `data.product_type` (string, required) — iwoca product name
- `data.promotions` (array, required) — Unused
- `data.revoked_at` (string, required) — If the offer has been revoked, shows the date and time at which it was revoked. Otherwise null.

## Responses
### 201 — Return status code 200 or 201 to acknowledge receipt of the webhook. Any non-2XX response code will result in iwoca retrying the delivery.
