> For the complete documentation index, see [llms.txt](/llms.txt).

# funding_created_202607

**Webhook event:** `funding_created_202607`

Sent when funds are sent to a customer. If the funding originated from an application, `application_id` is populated.

## Header parameters
- `X-IW-Event-ID` (string, required) — UUID of the webhook event. Webhooks which do not deliver successfully are retried. This will be the same across retry attempts for the same webhook.
- `X-IW-Event-Type` (string, required) — The type of webhook being delivered — matches the `webhook_event_type` values from `GET /webhooks/event_types/`.
- `X-IW-Signature` (string, required) — HMAC-SHA256 signature of the request body, base64-encoded and prefixed with `sha256=`. The HMAC key is your webhook secret token (not your API token), which you can fetch from the iwoca Notifications API or the Developer Portal. Verify this header to confirm the webhook is genuinely from iwoca and to mitigate replay attacks (by also checking that `X-IW-Timestamp` is recent). Retried deliveries get a fresh timestamp and therefore a fresh signature.

```
message   = "{X-IW-Timestamp}.{raw_request_body}"
signature = "sha256=" + base64(hmac_sha256(secret, message))
```
- `X-IW-Timestamp` (string, required) — Unix timestamp (seconds) at which the delivery was initiated. If this delivery is a retry of an earlier failed delivery, the timestamp is of the current attempt, not the original delivery.

## Payload
```json
{
  "data": {
    "application_id": "48ac72d0-a829-4896-a067-dcb1c2b0f30c",
    "customer_id": "07072be0-a15a-4070-bc88-baf6b866b359",
    "external_customer_id": "12345",
    "funding_amount": 1000,
    "funding_created_at": "2019-08-24T14:15:22Z",
    "funding_fee_amount": 50,
    "funding_id": "37301ec7-fce0-4953-a34c-83756823b32d",
    "offer_duration_in_days": 730,
    "offer_fee_percentage": 3,
    "offer_id": "d5a7a5b7-a4a3-49e7-9c69-b44d2cbe15cf",
    "offer_max_amount": 2000,
    "offer_monthly_interest_percentage": 3
  }
}
```

### Payload fields
- `data` (object, required)
- `data.application_id` (string) — Identifies the application this funding resulted from, if any. Omitted for fundings not associated with an application (e.g. pre-approval drawdowns).
- `data.customer_id` (string, required)
- `data.external_customer_id` (string) — The optional external_customer_id you sent in the POST /customers request when creating the customer
- `data.funding_amount` (number, required) — The amount transferred to the customer
- `data.funding_created_at` (string, required) — The time at which the customer initiated the sending of the funds. This is usually when the funds were sent, except in cases where there was a delay.
- `data.funding_fee_amount` (number, required) — The amount added on to the loan as a fee for this funding. This corresponds to the funding_amount and offer_fee_percentage.
- `data.funding_id` (string, required) — A unique identifier for this funding
- `data.offer_duration_in_days` (integer, required) — The duration of the loan. The end date of the loan is this many days from the first funding. (Later fundings from the same offer will show the same offer_duration_in_days, but are due to be repaid by the same time as the original funding).
- `data.offer_fee_percentage` (number, required) — What percentage of the amount borrowed was added to the loan as a fee when the customer took the money
- `data.offer_id` (string, required) — Identifies the formal offer that the customer accepted. The fields offer_max_amount, offer_monthly_interest_percentage, offer_fee_percentage and offer_duration_in_days will be the same for fundings that have the same offer_id, because these are properties of the offer. They correspond to fields in the /offers endpoint and are duplicated here for convenience.
- `data.offer_max_amount` (number, required) — The maximum funding the customer can take from this offer.
- `data.offer_monthly_interest_percentage` (number, required) — Monthly interest rate as a percentage (e.g. 3.0 means 3% per month)

## Responses
### 201 — Return status code 200 or 201 to acknowledge receipt of the webhook. Any non-2XX response code will result in iwoca retrying the delivery.
