Documentation index for AI agents (llms.txt)

Append .md to any page URL for its markdown source, or fetch llms-full.txt for the complete corpus.

Webhooks

indicative_offer_created

Sent when an indicative offer is created

Webhook eventindicative_offer_created

Header parameters

X-IW-Event-IDstringrequired

UUID of the webhook event. Webhooks which do not deliver successfully are retried. This will be the same across retry attempts for the same webhook.

X-IW-Event-Typestringrequired

The type of webhook being delivered — matches the webhook_event_type values from GET /webhooks/event_types/.

X-IW-Signaturestringrequired

HMAC-SHA256 signature of the request body, base64-encoded and prefixed with sha256=. The HMAC key is your webhook secret token (not your API token), which you can fetch from the iwoca Notifications API or the Developer Portal. Verify this header to confirm the webhook is genuinely from iwoca and to mitigate replay attacks (by also checking that X-IW-Timestamp is recent). Retried deliveries get a fresh timestamp and therefore a fresh signature.

message   = "{X-IW-Timestamp}.{raw_request_body}"
signature = "sha256=" + base64(hmac_sha256(secret, message))
X-IW-Timestampstringrequired

Unix timestamp (seconds) at which the delivery was initiated. If this delivery is a retry of an earlier failed delivery, the timestamp is of the current attempt, not the original delivery.

Payload

application_idstring<uuid>required
customer_idstring<uuid>required

Use this field to determine next steps for your customer if the offer is not of type 'confirmed'.

Array of object
categorystring
Allowed values:contractualcredit_rulesid_checkscontact_detailspaymentsenhanced_security_checkdocumentscompany_datapersonal_datatrading_history
amountnumber<float>required
unitstringrequired

In practice, always days

Allowed values:daysmonthsyears
external_customer_idstring

The optional external_customer_id you sent in the POST /customers request when creating the customer

interest_ratenumber<float>

Interest rate as a decimal. For example, 0.028 means the interest rate is 2.8%. Note that this may differ to how this field is presented in the /offers endpoint, depending on which version you're using.

is_suggestedbooleanrequired

Whether in iwoca's opinion this offer is the one which best matches the parameters requested in the application

max_amountnumber<float>required
offer_idstring<uuid>required
probability_of_offerstring
Allowed values:low_probability_of_offermedium_probability_of_offerhigh_probability_of_offer
product_typestringrequired
Allowed values:flexi_loanbusiness_loaniwocapaycbilsflexi24recovery_loanrevenue_based_loan
timeoutstringrequired

Expiry datetime of the indicative offer

Responses

Return status code 200 or 201 to acknowledge receipt of the webhook. Any non-2XX response code will result in iwoca retrying the delivery.