Documentation index for AI agents (llms.txt)

Append .md to any page URL for its markdown source, or fetch llms-full.txt for the complete corpus.

Webhooks

customer_funded

Sent when a customer draws down funds from an offer which originated from an application you introduced. This can happen multiple times. For example, if the customer initially draws down part of the offer amount, and later draws down the rest.

Webhook eventcustomer_funded

Header parameters

X-IW-Event-IDstringrequired

UUID of the webhook event. Webhooks which do not deliver successfully are retried. This will be the same across retry attempts for the same webhook.

X-IW-Event-Typestringrequired

The type of webhook being delivered — matches the webhook_event_type values from GET /webhooks/event_types/.

X-IW-Signaturestringrequired

HMAC-SHA256 signature of the request body, base64-encoded and prefixed with sha256=. The HMAC key is your webhook secret token (not your API token), which you can fetch from the iwoca Notifications API or the Developer Portal. Verify this header to confirm the webhook is genuinely from iwoca and to mitigate replay attacks (by also checking that X-IW-Timestamp is recent). Retried deliveries get a fresh timestamp and therefore a fresh signature.

message   = "{X-IW-Timestamp}.{raw_request_body}"
signature = "sha256=" + base64(hmac_sha256(secret, message))
X-IW-Timestampstringrequired

Unix timestamp (seconds) at which the delivery was initiated. If this delivery is a retry of an earlier failed delivery, the timestamp is of the current attempt, not the original delivery.

Payload

amount_fundednumberrequired
funded_datetimestring<date-time>required
loan_idstringrequired
state_keystring<uuid>required

customer_id

Responses

Return status code 200 or 201 to acknowledge receipt of the webhook. Any non-2XX response code will result in iwoca retrying the delivery.