---
title: "How webhooks work"
description: "Receive real-time notifications when application statuses change"
---

> For the complete documentation index, see [llms.txt](/llms.txt).

iwoca sends webhooks to your endpoint when key events occur – application approvals, declines, offers, and funding.
No polling required.

<CardGroup cols={2}>
  <Card title="Event types" icon="list" href="/guides/webhooks/event-types">
    Available events and example payloads
  </Card>
  <Card title="Security" icon="shield" href="/guides/webhooks/security">
    Signature verification and retry behaviour
  </Card>
</CardGroup>

## Getting started

<Steps>
  <Step title="Get your webhook secret token">
    Retrieve your token via `GET /webhooks/configuration/` or from the Developer Portal (sandbox only).
  </Step>
  <Step title="Configure your webhook URL">
    Set the URL where iwoca should send events using `PUT /webhooks/configuration/` or the Developer Portal.
  </Step>
  <Step title="Subscribe to events">
    Choose which events you want to receive using `POST /webhooks/subscriptions/` or the Developer Portal.
  </Step>
  <Step title="Implement signature verification">
    Verify the `X-IW-Signature` header on incoming webhooks to confirm they're from iwoca.
    See [Security](/guides/webhooks/security) for code examples.
  </Step>
  <Step title="Test in sandbox">
    Trigger test events in the sandbox environment before going live.
  </Step>
</Steps>

<Warning>
Your webhook endpoint should respond with a `2xx` status code to confirm receipt.
Failed deliveries are retried up to 10 times over roughly 16 hours – see [retry behaviour](/guides/webhooks/security#retry-behaviour).
</Warning>

## Base URL

Webhook configuration and subscription endpoints use the same base URL as the rest of the lending API:

<Tabs>
  <Tab title="Production">
    | API | Base URL |
    |---|---|
    | Lending | `https://www.iwoca.co.uk/api/lending/v2.2` |
  </Tab>
  <Tab title="Sandbox">
    | API | Base URL |
    |---|---|
    | Lending | `https://stage.iwoca-dev.co.uk/api/lending/v2.2` |
  </Tab>
</Tabs>

Authenticate with your Bearer token, the same as any other lending API request.
