Skip to main content
WEBHOOK

Authorizations

Authorization
string
header
required

One client per partner per environment. Access tokens expire after 15 minutes. Scopes are granted per client. Sandbox clients use https://sandbox.api.meet-oj.com/oauth/token.

Headers

webhook-id
string
required

Unique delivery id (Standard Webhooks). The same id is reused on retries so receivers can dedupe.

webhook-timestamp
string
required

Unix seconds. Reject deliveries older than 5 minutes.

webhook-signature
string
required

v1,<base64 HMAC-SHA256 of "<webhook-id>.<webhook-timestamp>.<raw body>" with the endpoint secret> (Standard Webhooks).

Body

application/json

A record that something happened. type says what, referral_id says to which referral, and data is a copy of the object concerned (the referral, the offer, the document request, and so on) as it looked at that moment. The same event, with the same id, is delivered by webhook and kept at GET /events, so you can safely ignore a duplicate.

id
string
required
Example:

"evt_01K5X3W0F3"

type
enum<string>
required

The kinds of events O.J. sends. The name is object.what_happened. The Webhooks section of the docs explains when each one fires.

Available options:
referral.received,
referral.matches_updated,
referral.needs_partner,
referral.needs_borrower,
message.sent,
message.received,
referral.reminder_due,
submission.awaiting_review,
submission.decided,
document_request.opened,
document_request.satisfied,
referral.submitted,
offer.received,
offer.accepted,
referral.funded,
referral.declined,
referral.closed,
payout.updated
created_at
string<date-time>
required
data
object
required

The object the event is about (referral, document_request, offer, message, or payout), as of the event.

object
string
Allowed value: "event"
referral_id
string

Response

2XX

Acknowledged