How webhooks work
Receive real-time notifications when application statuses change
iwoca sends webhooks to your endpoint when key events occur – application approvals, declines, offers, and funding. No polling required.
Getting started
- 1Get your webhook secret token
Retrieve your token via
GET /webhooks/configuration/or from the Developer Portal (sandbox only). - 2Configure your webhook URL
Set the URL where iwoca should send events using
PUT /webhooks/configuration/or the Developer Portal. - 3Subscribe to events
Choose which events you want to receive using
POST /webhooks/subscriptions/or the Developer Portal. - 4Implement signature verification
Verify the
X-IW-Signatureheader on incoming webhooks to confirm they're from iwoca. See Security for code examples. - 5Test in sandbox
Trigger test events in the sandbox environment before going live.
Your webhook endpoint should respond with a 2xx status code to confirm receipt.
Failed deliveries are retried up to 10 times over roughly 16 hours – see retry behaviour.
Base URL
Webhook configuration and subscription endpoints use the same base URL as the rest of the lending API:
| API | Base URL |
|---|---|
| Lending | https://www.iwoca.co.uk/api/lending/v2.2 |
Authenticate with your Bearer token, the same as any other lending API request.