Authentication Overview
Lendflow uses bearer token authentication for API requests. The type of token you should use depends on whether you are connecting an external integration or authenticating a temporary user session. Include the selected token in theAuthorization header:
Choose an Authentication Method
Integration Tokens
Use an Integration Token for:- Lendflow MCP
- External AI agents
- Server-to-server integrations
- Scripts and scheduled automations
- Long-running services that should not store a user’s password
Login Bearer Tokens
Use the authentication endpoints when your application needs to start a temporary session using a Lendflow user’s email and password. Login bearer tokens:- Represent the authenticated user
- Expire after two hours
- Can be refreshed through the Refresh Access Token endpoint
- Require your application to securely handle user credentials and token refresh
Legacy Static API Bearer Tokens
Some existing integrations may still use a static API bearer token from the dashboard. Before migrating an existing integration, confirm that its required API actions are available in the Integration Token permission list. Test the replacement token before revoking the existing credential.Common Authentication Scenarios
Connecting Lendflow MCP
Create a dedicated Integration Token with the Mcp Server Tools permission group. Add it to the MCP client’sAuthorization header.
Connect Lendflow MCP
Running a Backend Integration
Create a dedicated Integration Token for the service. Select only the permissions required by that integration and store the token in a server-side secret manager. Use a separate token for each integration so that one connection can be rotated or revoked without affecting another.Authenticating a Temporary User Session
Use the Get Bearer Token endpoint, send the returned token with API requests, and refresh it before it expires. Never expose the user’s password or bearer token in client-side logs.Using the Lendflow Dashboard
The Lendflow dashboard manages its own authenticated session. You do not need to manually create or provide an Integration Token for normal dashboard use.Permissions and Data Access
A token does not grant more access than its user already has. For an API request to succeed:- The token must be active and valid.
- An Integration Token must include the permission required by the endpoint.
- The associated user role must allow the action.
- The user must have access to the requested client, deal, or other resource.
Store Tokens Securely
- Store tokens in a secret manager or protected server environment variable.
- Never place tokens in frontend code, mobile applications, screenshots, or shared documents.
- Never commit tokens to source control.
- Use one Integration Token per external integration.
- Grant only the permissions the integration needs.
- Set an expiration when practical.
- Revoke and replace a token immediately if it may have been exposed.
- Avoid writing tokens to application or request logs.
Authentication Errors
401 Unauthorized
The token is missing, incomplete, expired, revoked, or otherwise invalid. Confirm the Authorization: Bearer <token> header and the token’s current status.
403 Forbidden
The token is valid, but its permissions or the associated user’s role do not allow the requested action.
429 Too Many Requests
The request exceeded the applicable rate limit. Wait for the limit to reset or review the Integration Token’s configured rate limit.
Recommended Setup
- Identify whether the connection is an external integration or a temporary user session.
- Create an Integration Token or obtain a login bearer token as appropriate.
- Store the credential securely.
- Test a read-only API request.
- Add only the additional permissions required by the integration.
- Document how the token will be rotated and revoked.
Next steps
Integration Tokens
Create, permission, and revoke a token in the Lendflow Dashboard.
Connect Lendflow MCP
Use an Integration Token to connect an MCP client.
Errors
Read status codes and the
message / errors body on a failed request.Getting Started with Lendflow
Authenticate, submit an application, and embed the Application Widget or Borrower Platform.