client_id and client_secret for each lender during account setup. Contact the QFAST team to receive yours. Each credential pair is tied to your lender account and must be kept confidential.Authorization: Bearer <access_token>expires_in seconds have elapsed.401 is received), request a new one.| HTTP Status | Error | Cause |
|---|---|---|
401 | invalid_token | Missing, invalid, or expired access token. |
403 | forbidden | Token is valid but the resource belongs to a different lender. |
{
"error": "invalid_token",
"error_description": "The access token is missing, invalid, or expired.",
"code": 401
}Signature header. Always verify this signature before processing any webhook payload.| Header | Description |
|---|---|
Signature | HMAC-SHA256 of the raw JSON body, computed using your webhook_secret. |