> For the complete documentation index, see [llms.txt](/llms.txt).

# prequalification_202505

**Webhook event:** `prequalification_202505`

Sent when a file uploaded to the POST /prequalification_data endpoint has been processed.
Contains a quote for each business in the input file.
You can also retrieve the quotes from the GET /prequalification_data endpoint.
Instead of using this webhook, we recommend listening for the prequalification_data_file_processed_202510
webhook and calling the GET endpoint when you receive it.

## Header parameters
- `X-IW-Event-ID` (string, required) — UUID of the webhook event. Webhooks which do not deliver successfully are retried. This will be the same across retry attempts for the same webhook.
- `X-IW-Event-Type` (string, required) — The type of webhook being delivered — matches the `webhook_event_type` values from `GET /webhooks/event_types/`.
- `X-IW-Signature` (string, required) — HMAC-SHA256 signature of the request body, base64-encoded and prefixed with `sha256=`. The HMAC key is your webhook secret token (not your API token), which you can fetch from the iwoca Notifications API or the Developer Portal. Verify this header to confirm the webhook is genuinely from iwoca and to mitigate replay attacks (by also checking that `X-IW-Timestamp` is recent). Retried deliveries get a fresh timestamp and therefore a fresh signature.

```
message   = "{X-IW-Timestamp}.{raw_request_body}"
signature = "sha256=" + base64(hmac_sha256(secret, message))
```
- `X-IW-Timestamp` (string, required) — Unix timestamp (seconds) at which the delivery was initiated. If this delivery is a retry of an earlier failed delivery, the timestamp is of the current attempt, not the original delivery.

## Payload
```json
{
  "data": [
    {
      "click_out_url": "string",
      "external_customer_id": "string",
      "is_prequalified": true,
      "marketing_type": "prequalified_marketing",
      "prequalification_data_id": "prequal_partner-20260611000000000000.csv",
      "prequalified_amount": 50000,
      "product": "flexi_loan",
      "quote_id": "4f9db950-2b6d-424e-96e1-7910c878375e"
    }
  ]
}
```

### Payload fields
- `data` (array, required)
- `data[].click_out_url` (string) — If the customer should be marketed a credit card, they can click on this link to apply
- `data[].external_customer_id` (string, required) — The ID you used for this customer/business in the prequalification data file. We recommend sending this in the external_customer_id field of the POST /customers request if this customer subsequently signs up.
- `data[].is_prequalified` (boolean, required) — Deprecated: See the marketing_type field instead
- `data[].marketing_type` (string, required) — `no_marketing` means the product should not be marketed to this customer (for example, because they are ineligible). `generic_marketing` means iwoca did not generate a prequalified amount for this customer. The product can still be marketed to them, but without a prequalified amount. `prequalified_marketing` means the quote has a prequalified_amount which can be shown to the customer
- `data[].prequalification_data_id` (string, required) — ID of the file uploaded to POST /prequalification_data. Can be used to retrieve the quotes from GET /prequalification_data.
- `data[].prequalified_amount` (number)
- `data[].product` (string) — Indicates whether this quote is for a Flexi-Loan or Credit Card
- `data[].quote_id` (string, required)

## Responses
### 201 — Return status code 200 or 201 to acknowledge receipt of the webhook. Any non-2XX response code will result in iwoca retrying the delivery.
