> ## Documentation Index
> Fetch the complete documentation index at: https://developers.meet-oj.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Register a webhook endpoint

> Registers a URL on your server that O.J. will send events to. The response includes the signing secret for
this endpoint. It is shown once, so store it. Deliveries follow the Standard Webhooks specification, are
retried with increasing delays for up to 72 hours if your server does not respond, and can be replayed from
`GET /events`.




## OpenAPI

````yaml /api-reference/openapi.yaml post /webhook_endpoints
openapi: 3.1.0
info:
  title: O.J. Agent Development Kit (ADK)
  version: 0.5.1
  summary: >-
    Send O.J. a business. Get back named lender matches, what's needed, offers
    and funding status.
  description: >
    The O.J. ADK lets platforms with small-business customers offer financing
    without becoming a lender or a

    broker. You send a business as a **referral**. O.J. matches it to lender
    programs, collects documents,

    submits to lenders and tracks the deal to funding. You earn a share of the
    commission on every funded loan.


    Integrate with **O.J. Embed** (drop-in screens), the **REST API** with
    webhooks, or **MCP** for agents. All

    three read and write the same referral.


    Conventions: OAuth 2.0 client credentials, amounts in cents, prefixed ids,
    cursor pagination, an

    `Idempotency-Key` on every POST, RFC 9457 errors, and Standard Webhooks
    signatures.
  license:
    name: Proprietary — O.J. partner terms
    identifier: LicenseRef-OJ-Partner
  contact:
    name: O.J. Developer Support
    email: developers@meet-oj.com
servers:
  - url: https://sandbox.api.meet-oj.com/partner/v0
    description: Sandbox
  - url: https://api.meet-oj.com/partner/v0
    description: Production
security:
  - oauth2: []
tags:
  - name: Referrals
    description: >-
      A referral is one business you sent to O.J. Every other resource belongs
      to a referral.
  - name: Matches
    description: >-
      The lenders a business matches, named, with estimated limits. `POST
      /match_checks` screens raw numbers without creating a referral. A match is
      not a credit decision; the lender decides.
  - name: Documents
    description: >-
      Documents O.J. still needs, and uploads by API. Most integrations show the
      `next_action` button instead.
  - name: Offers
    description: >-
      Offers returned by lenders. Indicative terms computed before a lender
      replies are marked `binding: false`.
  - name: Sessions
    description: >-
      Create a session to open an O.J. screen: a `client_token` for Embed, or a
      hosted `url` to redirect to.
  - name: Events
    description: >-
      Every change to a referral is an event, delivered by webhook, streamed
      over SSE, and kept for 30 days at `GET /events`.
  - name: Payouts
    description: >-
      Your share of the commission on each funded referral. Match rows to your
      bank statement with `statement_descriptor`. Payout destinations are set
      during onboarding and cannot be changed by API.
  - name: Conversation
    description: >-
      The message thread between O.J., the borrower and your team on a referral,
      across every channel.
  - name: Channels
    description: >-
      Channel connectors let O.J. reach your borrowers through channels you own
      (in-app inbox, SMS, Apple Business Messages, email), in your brand.
  - name: Policy
    description: >-
      Account-level rules: send approval, allowed Embed origins, contact
      channels, default intent and reminder cadence.
  - name: Programs
    description: >-
      For lenders running a program on O.J.: receive submissions, record
      decisions and report funding.
  - name: Webhooks
    description: >-
      Register endpoints that receive signed events. Deliveries follow Standard
      Webhooks.
paths:
  /webhook_endpoints:
    post:
      tags:
        - Webhooks
      summary: Register a webhook endpoint
      description: >
        Registers a URL on your server that O.J. will send events to. The
        response includes the signing secret for

        this endpoint. It is shown once, so store it. Deliveries follow the
        Standard Webhooks specification, are

        retried with increasing delays for up to 72 hours if your server does
        not respond, and can be replayed from

        `GET /events`.
      operationId: createWebhookEndpoint
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - url
              properties:
                url:
                  type: string
                  format: uri
                event_types:
                  type: array
                  items:
                    $ref: '#/components/schemas/EventType'
                  description: Omit to receive every event.
      responses:
        '201':
          description: Endpoint registered
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebhookEndpoint'
        '400':
          $ref: '#/components/responses/Error'
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: true
      description: >
        IETF `Idempotency-Key` semantics
        (draft-ietf-httpapi-idempotency-key-header). Send a fresh unique value

        (a UUID) with every new request. A retry with the same key and the same
        payload returns the original

        response with the header `Idempotent-Replayed: true`. The same key with
        a different payload is rejected with

        422 and code `idempotency_key_reused`. Keys are kept for 24 hours.
      schema:
        type: string
        maxLength: 255
  schemas:
    EventType:
      type: string
      description: >-
        The kinds of events O.J. sends. The name is `object.what_happened`. The
        Webhooks section of the docs explains when each one fires.
      enum:
        - referral.received
        - referral.matches_updated
        - referral.needs_partner
        - referral.needs_borrower
        - message.sent
        - message.received
        - referral.reminder_due
        - submission.awaiting_review
        - submission.decided
        - document_request.opened
        - document_request.satisfied
        - referral.submitted
        - offer.received
        - offer.accepted
        - referral.funded
        - referral.declined
        - referral.closed
        - payout.updated
    WebhookEndpoint:
      type: object
      description: >-
        A URL on your server that O.J. sends events to. `event_types` limits
        which events are sent; leave it empty to receive all of them. `secret`
        is the key used to sign each delivery and is returned only when the
        endpoint is created, so store it then.
      required:
        - id
        - url
        - status
        - created_at
      properties:
        id:
          type: string
          examples:
            - whe_01K5X3Y1G5
        object:
          type: string
          const: webhook_endpoint
        url:
          type: string
          format: uri
        event_types:
          type: array
          items:
            $ref: '#/components/schemas/EventType'
        secret:
          type: string
          description: Returned once, on creation. `whsec_…`
        status:
          type: string
          enum:
            - enabled
            - disabled
        created_at:
          type: string
          format: date-time
    Error:
      type: object
      description: >
        RFC 9457 Problem Details, returned as `application/problem+json` with
        any 4xx or 5xx status. `type` is a

        URI that identifies the kind of problem and doubles as a link to its
        documentation; `title` is the short

        human name for that kind; `status` repeats the HTTP status; `detail`
        explains this occurrence for a

        developer; `instance` is the request path. Three extension members:
        `code`, a stable snake_case reason to

        branch on; `param`, the offending field when the request was invalid;
        `request_id`, to quote to support.

        One code deserves a note: `awaiting_approval` (HTTP 409) is not a
        failure. It means the action you asked

        for needs a person at your company to confirm it first, and the referral
        shows `needs_partner` until they do.
      required:
        - type
        - title
        - status
        - code
        - request_id
      properties:
        type:
          type: string
          format: uri
          examples:
            - https://api.meet-oj.com/problems/duplicate-external-id
        title:
          type: string
          examples:
            - Referral already exists
        status:
          type: integer
          examples:
            - 409
        detail:
          type: string
          examples:
            - >-
              A referral with external_id cust_8842 was created on 2026-09-20 as
              ref_01K5X3K7Q2.
        instance:
          type: string
          examples:
            - /partner/v0/referrals
        code:
          type: string
          description: >-
            Stable machine-readable reason. Categories are the prefixes;
            specific codes follow.
          examples:
            - invalid_request
            - authentication_failed
            - permission_denied
            - not_found
            - duplicate_external_id
            - business_already_referred
            - missing_consent
            - required_documents_missing
            - idempotency_key_reused
            - rate_limited
            - awaiting_approval
            - internal_error
        param:
          type: string
          description: The field that caused an invalid_request, in dot notation.
        request_id:
          type: string
          examples:
            - req_01K5X4A9M2
  responses:
    Error:
      description: Problem Details (RFC 9457)
      headers:
        OJ-Request-Id:
          $ref: '#/components/headers/RequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Error'
  headers:
    RequestId:
      description: >-
        Unique id for this request. Quote it to support; it is also in Problem
        Details as `request_id` and in O.J.'s traces.
      schema:
        type: string
        examples:
          - req_01K5X4A9M2
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        One client per partner per environment. Access tokens expire after 15
        minutes. Scopes are granted per client. Sandbox clients use
        https://sandbox.api.meet-oj.com/oauth/token.
      flows:
        clientCredentials:
          tokenUrl: https://api.meet-oj.com/oauth/token
          scopes:
            referrals:write: Create referrals and upload documents
            referrals:read: Read referrals, matches, document requests, offers, events
            match_checks:write: Run identity-free match checks
            sessions:write: Mint hosted-session links
            webhooks:manage: Register and list webhook endpoints
            payouts:read: >-
              Read payouts (your statement). There is no payouts:write;
              destinations are managed in hosted onboarding by a person.
            messages:read: Read a referral's conversation
            messages:write: >-
              Send messages into a referral's conversation on behalf of the
              partner or the borrower
            channels:manage: Register and remove channel connectors
            policy:manage: Read and change the partner policy
            submissions:read: >-
              For banks running a program. List and read submissions awaiting
              review
            submissions:write: For banks running a program. Record decisions and report funding

````