> ## Documentation Index
> Fetch the complete documentation index at: https://developers.meet-oj.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Run a match check

> Returns the lenders a business would match, from numbers only, without creating a referral. This is how a
processor or a bank screens its customer base before approaching anyone.

Send structured data under a `reference` of your own, such as a hashed customer id. Do not send a name or an
EIN. O.J. stores only an audit line keyed by your reference. No deal is opened, nobody is contacted, and no
credit is pulled, so matches that depend on credit use the `credit_band` you send, if any.

This endpoint is rate-limited per partner.




## OpenAPI

````yaml /api-reference/openapi.yaml post /match_checks
openapi: 3.1.0
info:
  title: O.J. Agent Development Kit (ADK)
  version: 0.5.1
  summary: >-
    Send O.J. a business. Get back named lender matches, what's needed, offers
    and funding status.
  description: >
    The O.J. ADK lets platforms with small-business customers offer financing
    without becoming a lender or a

    broker. You send a business as a **referral**. O.J. matches it to lender
    programs, collects documents,

    submits to lenders and tracks the deal to funding. You earn a share of the
    commission on every funded loan.


    Integrate with **O.J. Embed** (drop-in screens), the **REST API** with
    webhooks, or **MCP** for agents. All

    three read and write the same referral.


    Conventions: OAuth 2.0 client credentials, amounts in cents, prefixed ids,
    cursor pagination, an

    `Idempotency-Key` on every POST, RFC 9457 errors, and Standard Webhooks
    signatures.
  license:
    name: Proprietary — O.J. partner terms
    identifier: LicenseRef-OJ-Partner
  contact:
    name: O.J. Developer Support
    email: developers@meet-oj.com
servers:
  - url: https://sandbox.api.meet-oj.com/partner/v0
    description: Sandbox
  - url: https://api.meet-oj.com/partner/v0
    description: Production
security:
  - oauth2: []
tags:
  - name: Referrals
    description: >-
      A referral is one business you sent to O.J. Every other resource belongs
      to a referral.
  - name: Matches
    description: >-
      The lenders a business matches, named, with estimated limits. `POST
      /match_checks` screens raw numbers without creating a referral. A match is
      not a credit decision; the lender decides.
  - name: Documents
    description: >-
      Documents O.J. still needs, and uploads by API. Most integrations show the
      `next_action` button instead.
  - name: Offers
    description: >-
      Offers returned by lenders. Indicative terms computed before a lender
      replies are marked `binding: false`.
  - name: Sessions
    description: >-
      Create a session to open an O.J. screen: a `client_token` for Embed, or a
      hosted `url` to redirect to.
  - name: Events
    description: >-
      Every change to a referral is an event, delivered by webhook, streamed
      over SSE, and kept for 30 days at `GET /events`.
  - name: Payouts
    description: >-
      Your share of the commission on each funded referral. Match rows to your
      bank statement with `statement_descriptor`. Payout destinations are set
      during onboarding and cannot be changed by API.
  - name: Conversation
    description: >-
      The message thread between O.J., the borrower and your team on a referral,
      across every channel.
  - name: Channels
    description: >-
      Channel connectors let O.J. reach your borrowers through channels you own
      (in-app inbox, SMS, Apple Business Messages, email), in your brand.
  - name: Policy
    description: >-
      Account-level rules: send approval, allowed Embed origins, contact
      channels, default intent and reminder cadence.
  - name: Programs
    description: >-
      For lenders running a program on O.J.: receive submissions, record
      decisions and report funding.
  - name: Webhooks
    description: >-
      Register endpoints that receive signed events. Deliveries follow Standard
      Webhooks.
paths:
  /match_checks:
    post:
      tags:
        - Matches
      summary: Run a match check
      description: >
        Returns the lenders a business would match, from numbers only, without
        creating a referral. This is how a

        processor or a bank screens its customer base before approaching anyone.


        Send structured data under a `reference` of your own, such as a hashed
        customer id. Do not send a name or an

        EIN. O.J. stores only an audit line keyed by your reference. No deal is
        opened, nobody is contacted, and no

        credit is pulled, so matches that depend on credit use the `credit_band`
        you send, if any.


        This endpoint is rate-limited per partner.
      operationId: createMatchCheck
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MatchCheckCreate'
      responses:
        '200':
          description: Lenders the business would match
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MatchCheck'
        '400':
          $ref: '#/components/responses/Error'
        '422':
          $ref: '#/components/responses/Error'
        '429':
          $ref: '#/components/responses/Error'
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: true
      description: >
        IETF `Idempotency-Key` semantics
        (draft-ietf-httpapi-idempotency-key-header). Send a fresh unique value

        (a UUID) with every new request. A retry with the same key and the same
        payload returns the original

        response with the header `Idempotent-Replayed: true`. The same key with
        a different payload is rejected with

        422 and code `idempotency_key_reused`. Keys are kept for 24 hours.
      schema:
        type: string
        maxLength: 255
  schemas:
    MatchCheckCreate:
      type: object
      description: >
        The body for a match check, which screens a business without identifying
        it. Instead of a name and EIN you send

        a `reference` — your own merchant id, or a hash of it — that O.J. echoes
        back and never tries to resolve.

        Add the ledger months and, if you have them, the state and industry.
        O.J. learns who the business is only if you refer it with consent.
      required:
        - reference
        - context
      properties:
        reference:
          type: string
          maxLength: 128
          description: Opaque partner-side id or hash. Echoed back; never resolved by O.J.
        business:
          type: object
          description: Optional, identity-free attributes that affect which lenders match.
          properties:
            state:
              type: string
              pattern: ^[A-Z]{2}$
            naics:
              type: string
              pattern: ^[0-9]{6}$
            industry:
              type: string
            formation_date:
              type: string
              format: date
            entity_type:
              type: string
              enum:
                - sole_prop
                - llc
                - s_corp
                - c_corp
                - partnership
                - nonprofit
        contacts:
          type: array
          items:
            $ref: '#/components/schemas/Contact'
        requested_amount:
          $ref: '#/components/schemas/Money'
        product_hint:
          $ref: '#/components/schemas/Product'
        context:
          $ref: '#/components/schemas/Context'
    MatchCheck:
      type: object
      required:
        - reference
        - matches
        - checked_at
      properties:
        reference:
          type: string
        matches:
          type: array
          items:
            $ref: '#/components/schemas/Match'
        checked_at:
          type: string
          format: date-time
    Contact:
      type: object
      description: >
        A person at the business. At least one contact is required, and one
        should be marked `is_primary` — that is

        who O.J. or the partner will talk to. Lenders also want to know every
        owner with a 20% or larger stake, so

        list them with `ownership_pct`. Never send Social Security numbers: O.J.
        collects them on its own screen

        when the owner authorizes the credit check. If the owner has told you
        their score range, or you hold it in

        your own records, send `credit_band` and O.J. uses it for early matches
        until the check completes. Never send a

        score you pulled from a credit bureau.
      required:
        - first_name
        - last_name
      properties:
        first_name:
          type: string
        last_name:
          type: string
        title:
          type: string
        email:
          type: string
          format: email
        phone:
          type: string
        ownership_pct:
          type: number
          minimum: 0
          maximum: 100
        credit_band:
          type: string
          enum:
            - under_600
            - 600_659
            - 660_699
            - 700_plus
            - unknown
        is_primary:
          type: boolean
    Money:
      type: integer
      description: >-
        A dollar amount expressed in whole US cents, so $85,000.00 is `8500000`.
        Cents avoid rounding errors that decimals cause in some languages.
    Product:
      type: string
      description: >
        A kind of financing. When you pass one as `product_hint`, O.J. still
        checks every product it can place, but

        lists the hinted one first. `revenue_based_financing` is repaid as a
        share of sales; `term_loan` is a fixed

        amount repaid over a fixed period; `business_line_of_credit` can be
        drawn and repaid repeatedly; `sba_7a` is a

        government-guaranteed bank loan; `invoice_factoring` advances money
        against unpaid invoices;

        `asset_based_lending` is secured by inventory or equipment;
        `hard_money_lending` is secured by real estate.
      enum:
        - revenue_based_financing
        - term_loan
        - business_line_of_credit
        - sba_7a
        - invoice_factoring
        - asset_based_lending
        - hard_money_lending
    Context:
      type: object
      description: >
        Everything you already know about the business, in whatever combination
        you have. The more you send, the more

        of the matching O.J. can do immediately, before any documents arrive.
        Figures you report are later checked

        against the borrower's bank data; if they disagree by more than a small
        tolerance, an O.J. reviewer looks at

        the file before it goes to lenders.
      properties:
        ledger:
          type: array
          maxItems: 24
          items:
            $ref: '#/components/schemas/LedgerMonth'
        listing:
          $ref: '#/components/schemas/Listing'
        bank_connection:
          type: object
          description: >-
            A Plaid processor token issued for O.J. It replaces bank statements.
            If the Item includes Auth, the borrower can also choose it as the
            funding account later without connecting again.
          required:
            - provider
            - token
          properties:
            provider:
              type: string
              enum:
                - plaid
            token:
              type: string
              writeOnly: true
        relationship:
          type: object
          properties:
            customer_since:
              type: string
              format: date
            products_used:
              type: array
              items:
                type: string
            monthly_processing_volume:
              $ref: '#/components/schemas/Money'
        notes:
          type: string
          maxLength: 2000
          description: >-
            Free text from the partner. Becomes the first line of the deal
            thread.
    Match:
      type: object
      description: >
        A lender program the business matches, named from the moment it matches.
        `amount_max` and `term_months`

        come from the program's own limits; they are estimates, not offers.
        `state` follows the program through

        submission to an offer or a decision.
      required:
        - id
        - lender
        - product
        - state
      properties:
        id:
          type: string
          examples:
            - mat_01K5X3M1A4
        lender:
          type: string
          examples:
            - Example Capital
        program:
          type: string
          examples:
            - Revenue-based financing
        product:
          $ref: '#/components/schemas/Product'
        amount_max:
          $ref: '#/components/schemas/Money'
        term_months:
          type: array
          items:
            type: integer
          minItems: 2
          maxItems: 2
          examples:
            - - 6
              - 12
        speed:
          type: string
          description: How long the lender usually takes to decide, in words.
          examples:
            - 1–2 business days
        state:
          type: string
          enum:
            - matched
            - submitted
            - offer
            - declined
            - withdrawn
    Error:
      type: object
      description: >
        RFC 9457 Problem Details, returned as `application/problem+json` with
        any 4xx or 5xx status. `type` is a

        URI that identifies the kind of problem and doubles as a link to its
        documentation; `title` is the short

        human name for that kind; `status` repeats the HTTP status; `detail`
        explains this occurrence for a

        developer; `instance` is the request path. Three extension members:
        `code`, a stable snake_case reason to

        branch on; `param`, the offending field when the request was invalid;
        `request_id`, to quote to support.

        One code deserves a note: `awaiting_approval` (HTTP 409) is not a
        failure. It means the action you asked

        for needs a person at your company to confirm it first, and the referral
        shows `needs_partner` until they do.
      required:
        - type
        - title
        - status
        - code
        - request_id
      properties:
        type:
          type: string
          format: uri
          examples:
            - https://api.meet-oj.com/problems/duplicate-external-id
        title:
          type: string
          examples:
            - Referral already exists
        status:
          type: integer
          examples:
            - 409
        detail:
          type: string
          examples:
            - >-
              A referral with external_id cust_8842 was created on 2026-09-20 as
              ref_01K5X3K7Q2.
        instance:
          type: string
          examples:
            - /partner/v0/referrals
        code:
          type: string
          description: >-
            Stable machine-readable reason. Categories are the prefixes;
            specific codes follow.
          examples:
            - invalid_request
            - authentication_failed
            - permission_denied
            - not_found
            - duplicate_external_id
            - business_already_referred
            - missing_consent
            - required_documents_missing
            - idempotency_key_reused
            - rate_limited
            - awaiting_approval
            - internal_error
        param:
          type: string
          description: The field that caused an invalid_request, in dot notation.
        request_id:
          type: string
          examples:
            - req_01K5X4A9M2
    LedgerMonth:
      type: object
      description: >
        One month of money in and out of the business, as recorded by a system
        you already run: a bank account, a

        bill-pay product, or a card-processing account. Send as many months as
        you have, up to 24. For a processor,

        put card settlements in `sales_deposits`. `nsf_count` is the number of
        times a payment bounced for

        insufficient funds that month, which almost every lender program checks.
      required:
        - month
      properties:
        month:
          type: string
          pattern: ^[0-9]{4}-[0-9]{2}$
        sales_deposits:
          $ref: '#/components/schemas/Money'
        total_inflows:
          $ref: '#/components/schemas/Money'
        total_outflows:
          $ref: '#/components/schemas/Money'
        average_daily_balance:
          $ref: '#/components/schemas/Money'
        ending_balance:
          $ref: '#/components/schemas/Money'
        nsf_count:
          type: integer
          minimum: 0
        chargeback_count:
          type: integer
          minimum: 0
          description: Processors only.
        transaction_count:
          type: integer
          minimum: 0
    Listing:
      type: object
      description: >
        For platforms that list businesses for sale. It carries what a listing
        already knows about the company being

        bought, which is most of what an SBA acquisition loan needs.
        `sde_trailing_12` is seller's discretionary

        earnings over the last twelve months (profit before the owner's pay and
        one-off expenses).

        `buyer_equity_injection_pct` is the share of the price the buyer is
        putting in as cash. These feed the SBA

        acquisition rules that took effect on October 1, 2026 (SOP 50 10 8.1):
        debt-service coverage of at least 1.25

        on historical earnings, a 10% injection with limits on where it can come
        from, and a mandatory quality-of-

        earnings review when the price is $3M or more.
      properties:
        listing_id:
          type: string
          description: Your listing id.
        asking_price:
          $ref: '#/components/schemas/Money'
        sde_trailing_12:
          $ref: '#/components/schemas/Money'
        ebitda_trailing_12:
          $ref: '#/components/schemas/Money'
        revenue_trailing_12:
          $ref: '#/components/schemas/Money'
        includes_real_estate:
          type: boolean
        real_estate_value:
          $ref: '#/components/schemas/Money'
        buyer_equity_injection_pct:
          type: number
          minimum: 0
          maximum: 100
        seller_note_pct:
          type: number
          minimum: 0
          maximum: 100
        buyer_industry_experience_years:
          type: integer
          minimum: 0
        financials_available:
          type: array
          items:
            $ref: '#/components/schemas/DocumentType'
    DocumentType:
      type: string
      description: >-
        The kinds of documents O.J. can request or accept. `cim` is a
        confidential information memorandum, the summary document a business
        broker prepares for a sale. `quality_of_earnings` is an accountant's
        review of reported earnings, required by the SBA for acquisitions of $3M
        or more. `funding_account_auth` is the funding account verified through
        Plaid; `voided_check` is the fallback when the bank can't be verified.
      enum:
        - bank_statement
        - processing_statement
        - voided_check
        - funding_account_auth
        - tax_return
        - profit_and_loss
        - balance_sheet
        - ar_aging
        - ap_aging
        - debt_schedule
        - business_license
        - government_id
        - lease
        - ownership_document
        - cim
        - purchase_agreement
        - quality_of_earnings
        - other
  responses:
    Error:
      description: Problem Details (RFC 9457)
      headers:
        OJ-Request-Id:
          $ref: '#/components/headers/RequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Error'
  headers:
    RequestId:
      description: >-
        Unique id for this request. Quote it to support; it is also in Problem
        Details as `request_id` and in O.J.'s traces.
      schema:
        type: string
        examples:
          - req_01K5X4A9M2
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        One client per partner per environment. Access tokens expire after 15
        minutes. Scopes are granted per client. Sandbox clients use
        https://sandbox.api.meet-oj.com/oauth/token.
      flows:
        clientCredentials:
          tokenUrl: https://api.meet-oj.com/oauth/token
          scopes:
            referrals:write: Create referrals and upload documents
            referrals:read: Read referrals, matches, document requests, offers, events
            match_checks:write: Run identity-free match checks
            sessions:write: Mint hosted-session links
            webhooks:manage: Register and list webhook endpoints
            payouts:read: >-
              Read payouts (your statement). There is no payouts:write;
              destinations are managed in hosted onboarding by a person.
            messages:read: Read a referral's conversation
            messages:write: >-
              Send messages into a referral's conversation on behalf of the
              partner or the borrower
            channels:manage: Register and remove channel connectors
            policy:manage: Read and change the partner policy
            submissions:read: >-
              For banks running a program. List and read submissions awaiting
              review
            submissions:write: For banks running a program. Record decisions and report funding

````