QFAST API Documentation
    • Introduction
    • Authentication
    • Onboarding Flow
    • Loan Flow
    • Disbursement Flow
    • Repayment Flow
    • Area Reference
    • API
      • Obtain an Access Token
        POST
      • Onboarding Personal
        POST
      • Get Onboarding Status
        GET
      • Submit Loan
        POST
      • Update Loan
        PATCH
      • Get Loan
        GET
    • Webhook
      • Onboarding Webhooks
      • Loan Webhooks
      • Disbursement Webhooks
      • Repayment Webhooks

    Authentication

    All QFAST API requests require a Bearer token obtained via the OAuth2 Client Credentials grant — a server-to-server (machine-to-machine) flow with no user login.

    Credentials#

    QFAST provisions a client_id and client_secret for each lender during account setup. Contact the QFAST team to receive yours. Each credential pair is tied to your lender account and must be kept confidential.
    See Obtain an Access Token for the token endpoint.

    Use the Token#

    Include the access token in every API request:
    Authorization: Bearer <access_token>

    Example#


    Token Lifecycle#

    Token expiry is short (5 minutes). Your integration must renew tokens proactively.
    1.
    Request a token before making API calls.
    2.
    Cache the token and reuse it until expires_in seconds have elapsed.
    3.
    When the token is close to expiry (or a 401 is received), request a new one.
    4.
    Never hardcode tokens — always fetch them programmatically.

    Common Authentication Errors#

    HTTP StatusErrorCause
    401invalid_tokenMissing, invalid, or expired access token.
    403forbiddenToken is valid but the resource belongs to a different lender.
    {
      "error": "invalid_token",
      "error_description": "The access token is missing, invalid, or expired.",
      "code": 401
    }

    Webhook Security#

    Every webhook request sent by QFAST includes an HMAC-SHA256 signature in the Signature header. Always verify this signature before processing any webhook payload.
    HeaderDescription
    SignatureHMAC-SHA256 of the raw JSON body, computed using your webhook_secret.

    Verification Example (PHP)#

    Expected Response#

    Your webhook endpoint must return an HTTP 200 or HTTP 204 OK status code to acknowledge receipt. Any other status code triggers QFAST's retry policy.
    Previous
    Introduction
    Next
    Onboarding Flow
    Built with