Skip to main content
POST
Register a webhook for one referral

Authorizations

Authorization
string
header
required

One client per partner per environment. Access tokens expire after 15 minutes. Scopes are granted per client. Sandbox clients use https://sandbox.api.meet-oj.com/oauth/token.

Headers

Idempotency-Key
string
required

IETF Idempotency-Key semantics (draft-ietf-httpapi-idempotency-key-header). Send a fresh unique value (a UUID) with every new request. A retry with the same key and the same payload returns the original response with the header Idempotent-Replayed: true. The same key with a different payload is rejected with 422 and code idempotency_key_reused. Keys are kept for 24 hours.

Maximum string length: 255

Path Parameters

referral_id
string
required
Example:

"ref_01K5X3K7Q2"

Body

application/json
url
string<uri>
required
token
string

Returned to you in the OJ-Webhook-Token header on every delivery.

signing
enum<string>
default:hmac
Available options:
hmac,
jwt
event_types
enum<string>[]

Omit to receive every event for the referral.

The kinds of events O.J. sends. The name is object.what_happened. The Webhooks section of the docs explains when each one fires.

Available options:
referral.received,
referral.matches_updated,
referral.needs_partner,
referral.needs_borrower,
message.sent,
message.received,
referral.reminder_due,
submission.awaiting_review,
submission.decided,
document_request.opened,
document_request.satisfied,
referral.submitted,
offer.received,
offer.accepted,
referral.funded,
referral.declined,
referral.closed,
payout.updated
expires_at
string<date-time>

Response

Webhook registered

A webhook that receives events for one referral only. It is removed automatically when the referral reaches a final status.

id
string
required
Example:

"rwh_01K5X8C3D4"

referral_id
string
required
url
string<uri>
required
signing
enum<string>
required
Available options:
hmac,
jwt
status
enum<string>
required
Available options:
enabled,
disabled,
expired
created_at
string<date-time>
required
object
string
Allowed value: "referral_webhook"
secret
string

For hmac. Returned once, on creation.

event_types
enum<string>[]

The kinds of events O.J. sends. The name is object.what_happened. The Webhooks section of the docs explains when each one fires.

Available options:
referral.received,
referral.matches_updated,
referral.needs_partner,
referral.needs_borrower,
message.sent,
message.received,
referral.reminder_due,
submission.awaiting_review,
submission.decided,
document_request.opened,
document_request.satisfied,
referral.submitted,
offer.received,
offer.accepted,
referral.funded,
referral.declined,
referral.closed,
payout.updated
expires_at
string<date-time>