> ## Documentation Index
> Fetch the complete documentation index at: https://developers.meet-oj.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Replace the partner policy

> Replaces the policy. Send the whole object. Fields you leave out return to their defaults. Changes apply to
new actions immediately and to in-flight referrals at their next step. Changing `require_send_approval`
never recalls a submission that has already gone to a lender.




## OpenAPI

````yaml /api-reference/openapi.yaml put /partner/policy
openapi: 3.1.0
info:
  title: O.J. Agent Development Kit (ADK)
  version: 0.5.1
  summary: >-
    Send O.J. a business. Get back named lender matches, what's needed, offers
    and funding status.
  description: >
    The O.J. ADK lets platforms with small-business customers offer financing
    without becoming a lender or a

    broker. You send a business as a **referral**. O.J. matches it to lender
    programs, collects documents,

    submits to lenders and tracks the deal to funding. You earn a share of the
    commission on every funded loan.


    Integrate with **O.J. Embed** (drop-in screens), the **REST API** with
    webhooks, or **MCP** for agents. All

    three read and write the same referral.


    Conventions: OAuth 2.0 client credentials, amounts in cents, prefixed ids,
    cursor pagination, an

    `Idempotency-Key` on every POST, RFC 9457 errors, and Standard Webhooks
    signatures.
  license:
    name: Proprietary — O.J. partner terms
    identifier: LicenseRef-OJ-Partner
  contact:
    name: O.J. Developer Support
    email: developers@meet-oj.com
servers:
  - url: https://sandbox.api.meet-oj.com/partner/v0
    description: Sandbox
  - url: https://api.meet-oj.com/partner/v0
    description: Production
security:
  - oauth2: []
tags:
  - name: Referrals
    description: >-
      A referral is one business you sent to O.J. Every other resource belongs
      to a referral.
  - name: Matches
    description: >-
      The lenders a business matches, named, with estimated limits. `POST
      /match_checks` screens raw numbers without creating a referral. A match is
      not a credit decision; the lender decides.
  - name: Documents
    description: >-
      Documents O.J. still needs, and uploads by API. Most integrations show the
      `next_action` button instead.
  - name: Offers
    description: >-
      Offers returned by lenders. Indicative terms computed before a lender
      replies are marked `binding: false`.
  - name: Sessions
    description: >-
      Create a session to open an O.J. screen: a `client_token` for Embed, or a
      hosted `url` to redirect to.
  - name: Events
    description: >-
      Every change to a referral is an event, delivered by webhook, streamed
      over SSE, and kept for 30 days at `GET /events`.
  - name: Payouts
    description: >-
      Your share of the commission on each funded referral. Match rows to your
      bank statement with `statement_descriptor`. Payout destinations are set
      during onboarding and cannot be changed by API.
  - name: Conversation
    description: >-
      The message thread between O.J., the borrower and your team on a referral,
      across every channel.
  - name: Channels
    description: >-
      Channel connectors let O.J. reach your borrowers through channels you own
      (in-app inbox, SMS, Apple Business Messages, email), in your brand.
  - name: Policy
    description: >-
      Account-level rules: send approval, allowed Embed origins, contact
      channels, default intent and reminder cadence.
  - name: Programs
    description: >-
      For lenders running a program on O.J.: receive submissions, record
      decisions and report funding.
  - name: Webhooks
    description: >-
      Register endpoints that receive signed events. Deliveries follow Standard
      Webhooks.
paths:
  /partner/policy:
    put:
      tags:
        - Policy
      summary: Replace the partner policy
      description: >
        Replaces the policy. Send the whole object. Fields you leave out return
        to their defaults. Changes apply to

        new actions immediately and to in-flight referrals at their next step.
        Changing `require_send_approval`

        never recalls a submission that has already gone to a lender.
      operationId: updatePolicy
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Policy'
      responses:
        '200':
          description: The policy as saved
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Policy'
        '422':
          $ref: '#/components/responses/Error'
components:
  schemas:
    Policy:
      type: object
      description: >
        The rules O.J. follows for your referrals. Read it to know how your
        account behaves. Replace it to change

        that. Every field has a default, so an empty policy is a working policy.
      properties:
        require_send_approval:
          type: boolean
          default: false
          description: >-
            When true, each lender submission waits for a person at your
            company. It arrives in `todos` as an `approve_send` item for your
            team, and the referral is `needs_partner` until someone approves.
            Lenders running a program on O.J. usually set this.
        allowed_origins:
          type: array
          items:
            type: string
          description: >-
            Web origins that may open O.J. Embed. localhost is always allowed in
            the sandbox.
          examples:
            - - https://app.partner.example.com
        contact_channels:
          type: array
          items:
            type: string
            enum:
              - sms
              - imessage
              - email
              - voice
          default:
            - sms
            - email
          description: >-
            Which of O.J.'s own channels may contact your borrowers. An empty
            list means O.J. only reaches them through your product: Embed,
            hosted pages you link to, or your channel connectors.
        default_intent:
          $ref: '#/components/schemas/Intent'
        reminders:
          type: object
          properties:
            cadence_days:
              type: array
              items:
                type: integer
              default:
                - 2
                - 5
                - 9
              description: Days after an action opens on which to remind.
            quiet_hours:
              type: object
              properties:
                start:
                  type: string
                end:
                  type: string
                timezone:
                  type: string
        next_action_ttl_days:
          type: integer
          default: 7
          description: How long a next action's hosted link stays valid without being read.
        updated_at:
          type: string
          format: date-time
          readOnly: true
    Intent:
      type: string
      description: >
        Who the borrower hears from. O.J. does the work either way. With
        `just_refer`, O.J. contacts the borrower

        directly, introducing itself as working with you, and sends the borrower
        the link for each to-do. With

        `work_this_deal`, O.J. never contacts the borrower; each to-do arrives
        in the referral's `todos` with a link

        you place in your own product, so the borrower acts inside your flow.
      enum:
        - work_this_deal
        - just_refer
    Error:
      type: object
      description: >
        RFC 9457 Problem Details, returned as `application/problem+json` with
        any 4xx or 5xx status. `type` is a

        URI that identifies the kind of problem and doubles as a link to its
        documentation; `title` is the short

        human name for that kind; `status` repeats the HTTP status; `detail`
        explains this occurrence for a

        developer; `instance` is the request path. Three extension members:
        `code`, a stable snake_case reason to

        branch on; `param`, the offending field when the request was invalid;
        `request_id`, to quote to support.

        One code deserves a note: `awaiting_approval` (HTTP 409) is not a
        failure. It means the action you asked

        for needs a person at your company to confirm it first, and the referral
        shows `needs_partner` until they do.
      required:
        - type
        - title
        - status
        - code
        - request_id
      properties:
        type:
          type: string
          format: uri
          examples:
            - https://api.meet-oj.com/problems/duplicate-external-id
        title:
          type: string
          examples:
            - Referral already exists
        status:
          type: integer
          examples:
            - 409
        detail:
          type: string
          examples:
            - >-
              A referral with external_id cust_8842 was created on 2026-09-20 as
              ref_01K5X3K7Q2.
        instance:
          type: string
          examples:
            - /partner/v0/referrals
        code:
          type: string
          description: >-
            Stable machine-readable reason. Categories are the prefixes;
            specific codes follow.
          examples:
            - invalid_request
            - authentication_failed
            - permission_denied
            - not_found
            - duplicate_external_id
            - business_already_referred
            - missing_consent
            - required_documents_missing
            - idempotency_key_reused
            - rate_limited
            - awaiting_approval
            - internal_error
        param:
          type: string
          description: The field that caused an invalid_request, in dot notation.
        request_id:
          type: string
          examples:
            - req_01K5X4A9M2
  responses:
    Error:
      description: Problem Details (RFC 9457)
      headers:
        OJ-Request-Id:
          $ref: '#/components/headers/RequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Error'
  headers:
    RequestId:
      description: >-
        Unique id for this request. Quote it to support; it is also in Problem
        Details as `request_id` and in O.J.'s traces.
      schema:
        type: string
        examples:
          - req_01K5X4A9M2
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        One client per partner per environment. Access tokens expire after 15
        minutes. Scopes are granted per client. Sandbox clients use
        https://sandbox.api.meet-oj.com/oauth/token.
      flows:
        clientCredentials:
          tokenUrl: https://api.meet-oj.com/oauth/token
          scopes:
            referrals:write: Create referrals and upload documents
            referrals:read: Read referrals, matches, document requests, offers, events
            match_checks:write: Run identity-free match checks
            sessions:write: Mint hosted-session links
            webhooks:manage: Register and list webhook endpoints
            payouts:read: >-
              Read payouts (your statement). There is no payouts:write;
              destinations are managed in hosted onboarding by a person.
            messages:read: Read a referral's conversation
            messages:write: >-
              Send messages into a referral's conversation on behalf of the
              partner or the borrower
            channels:manage: Register and remove channel connectors
            policy:manage: Read and change the partner policy
            submissions:read: >-
              For banks running a program. List and read submissions awaiting
              review
            submissions:write: For banks running a program. Record decisions and report funding

````