Skip to main content
POST
Create Personal Access Token

Authorizations

Authorization
string
header
required


You can register for a new Lendflow API key on our client portal in less than 60 seconds. The Bearer Token needs to be included in all API requests made to the API Service in the following form:

Authorization: Bearer [YOUR_TOKEN]
You must replace [YOUR_TOKEN] with your personal API key.

Body

application/json
name
string
required

Access token name. Must not be greater than 255 characters.

Example:

"b"

abilities
enum<string>[]
required
Available options:
ai-agent-session:create,
ai-agent-session:view,
application:assign-role,
application:create,
application:delete,
application:duplicate,
application:enrich,
application:manually-sign-application,
application:move-stage,
application:sign-application,
application:update,
application:view,
application:view-any,
attribute:create,
attribute:delete,
attribute:evaluate,
attribute:update,
attribute:update-values,
attribute:view,
attribute:view-any,
application-note:create,
application-note:view-any,
client:create,
client:update,
client:upload-signed-document,
client:view,
client:view-any,
comment:create,
comment:view-any,
comment:update,
comment:delete,
communication-log:create,
communication-template:view,
data-orchestration:run,
data-orchestration:view-any,
file:create,
file:update,
file:upload-contract,
file:upload-file-of-type,
file:upload-stip,
file:view,
funder:view,
funder:view-any,
metadata:view,
metadata:view-any,
metadata:create,
metadata:update,
metadata:delete,
note:create,
note:update,
note:view-any,
offer:confirm,
offer:create,
offer:delete,
offer:duplicate,
offer:update,
offer:update-status,
offer:view,
offer:view-any,
placement:create,
placement:update-status,
placement:view,
placement:view-any,
score-card-group:run,
score-card-group:run-any,
sms-conversation:view,
tracking-token:create,
tracking-token:delete,
tracking-token:update,
tracking-token:view-any,
user:impersonate,
workflow-snapshot:view,
workflow-template:apply-to-application,
workflow-template:view,
workflow-template:view-any
Example:
description
string | null

Access token description. Must not be greater than 1000 characters.

Example:

"Et animi quos velit et fugiat."

expires_at
string | null

Access token expiration data. Must be a valid date. Must be a date after now.

Example:

"2052-11-01"

rate_limits
(object | null)[]

Optional array of rate limits for this token. Each rate limit must specify max_attempts (1-10,000), decay_minutes (1-1440), and scope (, , , , , , , , ). Use '*' for a wildcard that applies to all scopes. Example: [{'max_attempts': 100, 'decay_minutes': 1, 'scope': 'api'}].

Example:

null

Response

200 - application/json
data
object