/applicationsCreate application
Open a loan application for a Kenyan borrower with ODPC consent and KYC references.
Loading officer dashboard…
Interactive REST API explorer for Kenyan fintech integrators, with sandbox data, M-Pesa fixtures, webhook delivery controls, scoped keys, and production-parity rate limits.
Baseline auth profiles include OAuth 2.0 PKCE + mTLS and Signed HMAC-SHA256 + mTLS.
| Endpoint | Auth | Status | Hash |
|---|---|---|---|
| Credit Decisioning API | OAuth 2.0 PKCE + mTLS | within | 44441fd09aa084074e9225631439997c97c1ec5046ef3723f20c69dc915b99cd |
| Loan Origination API | OAuth 2.0 client credentials + mTLS | within | 4594765d2abe2e96cc6eb063f1c6eaf6a5e9dc7bbd6f48e4711f250cf69c1a74 |
| Risk-Based Pricing API | OAuth 2.0 client credentials + mTLS | within | 4fc5d8fa5f80c885d8b69d164bb9a328ad696197f438722080d15a0d5b7042f8 |
| CRB Score Pull API | OAuth 2.0 + consent token + mTLS | within | cb0e599a4c2e2073f1359009ce8aaa653e538b440685bf514de46b76461fec3e |
| Daftari Attestation API | OAuth 2.0 client credentials + mTLS | within | 1ec3585c3cf949fee1feada9aa9e77f00cdd7f6d843e3162dddcce1e65a8915e |
| Webhook Events API | Signed HMAC-SHA256 + mTLS | within | 6ff87c71bb4fe554da7fadc89226f9bab2122851dbc104b0174be21658158bfa |
| Partner | Scope | Status | Hash |
|---|---|---|---|
| BancABC Kenya | prequalify and underwrite with borrower consent | within | 3646764bd6e9fa67a262c7fe97e776b796644266e845ca9ce21896685145cb23 |
| Equity Bank LaaS | loan origination and event delivery | within | a35aa31e8e50f677f26c5067abc15c46095ef9e29c200750ea5ac6bb5b8af9fe |
| Safaricom M-Pesa Extend | payment initiation and webhook delivery | within | 0c59bc00cdf193e1366601c87dd111f4a5fedccdc2d6614142b22b203e619ece |
| Nairobi County CDA | sandbox prequalification and consented bureau pulls | within | 6e1a3114bd82074a544e9d4ffc80759c835923a17b4f0b7f7fd6af80a5519d70 |
| Situ White-label MFI | quarantined full-catalogue integration | within | 4cd8e19dbc040a35b0ea58f3ff2adc200f9fef327eaee79d615120a9300b9b8e |
| Tier | Throttle | Status | Hash |
|---|---|---|---|
| Sandbox | tenant token bucket plus sandbox isolation | within | 32b1ef2089d5b3e4606b143b87227a387cff5d15b4bccfe6bd4f932c538ee279 |
| Starter | tenant token bucket plus concurrency limiter | within | 47bd720b28510617213393aab1735ac2792403fdb9d562f4ba9b00368c72b244 |
| Growth | tenant token bucket, burst shaping, and circuit breaker | within | 4481e2c21749a592ae7b303444d5b55e8c1ae3acf63623126a2f4dfae1216082 |
| Enterprise | custom tenant policy, WAF, circuit breaker, and back-pressure | within | 05ae2b9b2694adc23dde449915dd84cd6a9fd7f44a75990a624e467851f15586 |
| Risk control | Owner | Status | Hash |
|---|---|---|---|
| Financial-grade API authentication, mTLS, and client assertion controls | identity platform and API security | within | c29c94ba51f4c09e0c0baac53ad92ac8228176485b46763d0b54c9eaab258f2a |
| Object-level authorization and tenant-scoped permission boundaries | API platform engineering | within | 4d7f30ce5fae30ef54be0ce7c41e09adc618a114235b5ded0fa147304191b835 |
| Rate limiting, quota, burst, concurrency, and resource protection | platform reliability | within | 4d0387d892b33a7381a325979809125eb1491bb54604b15dd9a8cdd5f1d9bcac |
| Schema validation, deterministic sandbox, and contract documentation | developer platform | within | bc151f4aea5c7064250587408b1d09a06a49a2a1484fd262e9c641a32b456acd |
| Consent-scoped borrower data sharing and revocation-ready access | privacy office and API product | within | a8c7a73ea7a6942d0432c59781a76714b5baef2b0c4ee23412b82e69b17d09ac |
| Webhook signing, replay control, and non-repudiation | integration platform | within | d8a6b4fb355103a1e5e2b23f061d0ec69653f7b043504842c34c8ac948bd84d8 |
| Secure API change, release, and assurance evidence | application security and release engineering | within | abdb690fa3c75491afd96650a5ebb4c0582835a1c6ad6068b1d7e053bb595228 |
| API evidence custody, risk-data aggregation, and supervisory reproduction | examiner platform and data governance | within | e8c05fdd5a13e36859fa0e602091755519cc649113d48a1d65e2cfc2cd0082e0 |
| Control | Metric | Status | Hash |
|---|---|---|---|
| Financial-grade API authentication coverage | Partner endpoints using OAuth, mTLS, signed HMAC, and verified auth | within | 5752448b7d28f4141cbf8e30b8a2ad627ccc73ccb07824a2ff07ba871dd23688 |
| Consent-scoped borrower data access | Endpoints with borrower or bureau fields protected by consent scope | within | b613adb20c4a46632c1fb5838a26cdae2dbad0f04a138d7b8b51d55d9656b0db |
| Schema validation and deterministic sandbox isolation | Endpoints with documented schemas and sandbox examples | within | 003e96a2d0dfb5f5e96a3bba31fd97fb22f34c7744c833de013228415eb318b8 |
| Rate limit, quota, burst, concurrency, and resilience control | Partner tiers with throttle mode, SLA, and concurrency controls | within | 5068cd08956e5f78069c6be9ecf9ec20dd39462693f7ca29f0d4e70c9e0a0f72 |
| Partner health, incident, and quarantine governance | Partners inside error/security tolerance or suspended when unhealthy | within | 6dd684e170f0146f47ad6e29e265f26afdb5f8ff88f7eca416e8fed8b1a52d26 |
| Webhook integrity, replay resistance, and non-repudiation | Webhook endpoints using signed HMAC and mTLS with event custody | within | 8e678325f6418a9977db2100fb97e57159d8a8e93ce29c1b9f928735bf23745b |
| API platform controls mapped to enterprise evidence manifest | FAPI, OWASP API, NIST SSDF, consent, webhook, and custody controls with mapped evidence | within | 9acc8794a17fa28ccc6dbcfb83b60acbd94882d60d06a56e96aed74a1270b96c |
| API platform evidence custody and supervisory reproducibility | Endpoint, partner, rate-limit, risk-control, action, and manifest evidence with SHA-256 hashes | within | 846eb7c4cd6d99b838d4593437f1fc59f8d65b3ebe2ac8fdf9390fa3b6337d86 |
| Trigger | Owner | Deadline | Hash |
|---|---|---|---|
| No API platform governance action packs are required for the current evidence set.86a98e4b4b6e0c8cf1f33ce3b6a9acabd00ef44a3cee4adefa901a59404a4a6d | |||
Consumer-permissioned data sharing, scope minimization, revocation, portability, recipient oversight, reconciliation, live-read controls, and evidence custody.
| Consent journey | Purpose and categories | Disclosure controls | Status | Hash |
|---|---|---|---|---|
Prequalification income and cashflow consent mobile / BancABC Kenya / age 12/90d | prequalify credit affordability / income, cashflow | plain ready / granular ready / bounded ready / revoke ready / live ready | within | ac33a4943532...f29b7c3e |
Credit bureau data access consent web / Nairobi County CDA / age 18/90d | credit bureau pull / identity, bureau score | plain ready / granular ready / bounded ready / revoke ready / live ready | within | e0d0f212c10a...e2bef5fc |
Repayment history sharing consent borrower portal / Equity Bank LaaS / age 8/90d | repayment history verification / loan balance, repayment history | plain ready / granular ready / bounded ready / revoke ready / live ready | within | b018398e8710...bd344ebe |
Wallet cashflow sharing consent superapp / Safaricom M-Pesa Extend / age 20/90d | wallet cashflow assessment / wallet transactions, merchant receipts | plain ready / granular ready / bounded ready / revoke ready / live ready | within | fec8973954ea...5d233792 |
Affordability open-finance consent agent assisted / Situ White-label MFI / age 15/90d | affordability review / income, obligations, expense proxy | plain ready / granular ready / bounded ready / revoke ready / live ready | within | f35290e02b67...c55d208a |
| Grant | Scope | Access controls | Status | Hash |
|---|---|---|---|---|
BancABC Kenya /v1/prequalify / API platform | 4/4 / 100.0% / expires 28/90d | auth ready / token ready / least privilege ready / minimized ready / log ready | within | 9eb27bcc4868...844c2d07 |
Nairobi County CDA /v1/credit-bureau/pulls / API platform | 3/3 / 100.0% / expires 25/90d | auth ready / token ready / least privilege ready / minimized ready / log ready | within | d69e323f6752...9947218c |
Equity Bank LaaS /v1/loans/repayment-history / loan servicing operations | 5/5 / 100.0% / expires 30/90d | auth ready / token ready / least privilege ready / minimized ready / log ready | within | 8d27dc0fda36...bfaba17b |
Safaricom M-Pesa Extend /v1/wallet/cashflow / payments operations | 4/4 / 100.0% / expires 21/90d | auth ready / token ready / least privilege ready / minimized ready / log ready | within | 8cbe0db6e5f4...eecdd226 |
Situ White-label MFI /v1/underwrite / underwriting operations | 6/6 / 100.0% / expires 27/90d | auth ready / token ready / least privilege ready / minimized ready / log ready | within | d856711c04d9...2a52aacb |
| Rights request | SLA | Propagation controls | Status | Hash |
|---|---|---|---|---|
revocation MSME borrower / privacy operations | 4/24h | propagated ready / token ready / partner ready / confirmation ready / DSAR ready | within | cb894974c800...133e167f |
portability consumer borrower / privacy operations | 10/72h | propagated ready / token ready / partner ready / confirmation ready / DSAR ready | within | 246e8d7b8fd8...45d19bf3 |
restriction merchant borrower / payments operations | 8/48h | propagated ready / token ready / partner ready / confirmation ready / DSAR ready | within | 336c0ef0df69...a35d5a2b |
deletion closed loan borrower / records manager | 16/72h | propagated ready / token ready / partner ready / confirmation ready / DSAR ready | within | e79ec4a32d00...a15eee99 |
revocation vulnerable customer / conduct risk | 6/24h | propagated ready / token ready / partner ready / confirmation ready / DSAR ready | within | fa3b1aa69a4d...492863f5 |
| Recipient | Review | Third-party duties | Status | Hash |
|---|---|---|---|---|
BancABC Kenya bank partner / partner operations | 22/90d / incidents 0 | diligence ready / data-use ready / onward blocked / breach ready / deletion ready | within | 2647f95083b0...b7baa1da |
Nairobi County CDA public-sector credit program / partner operations | 45/90d / incidents 0 | diligence ready / data-use ready / onward blocked / breach ready / deletion ready | within | 4eab1dce4ae5...50863c0c |
Safaricom M-Pesa Extend payment partner / payments operations | 18/90d / incidents 0 | diligence ready / data-use ready / onward blocked / breach ready / deletion ready | within | 03537e71546f...bfd849c9 |
Situ White-label MFI white-label lender / vendor risk | 31/90d / incidents 0 | diligence ready / data-use ready / onward blocked / breach ready / deletion ready | within | 1bb050f6feb0...94c85160 |
| Reconciliation | Match | Breaks | Status | Hash |
|---|---|---|---|---|
Consent ledger to API token consent ledger to API gateway token store / privacy operations | 150/150 / 100.0% | 0 breaks / age 0/24h | within | 27cc168a2f1f...b0277634 |
Revocation to partner access withdrawal queue to partner access registry / privacy operations | 62/62 / 100.0% | 0 breaks / age 0/24h | within | ffd4004e6942...7de60de8 |
Consent scope to data field consent scope catalog to API response schema / data governance | 88/88 / 100.0% | 0 breaks / age 0/24h | within | 2438ff39d5e7...5fd13ba0 |
Recipient contract to sharing log contract register to data sharing log / vendor risk | 42/42 / 100.0% | 0 breaks / age 0/24h | within | 564d1e493bb1...d500e069 |
DSAR to portability export DSAR queue to portability export ledger / records manager | 36/36 / 100.0% | 0 breaks / age 0/24h | within | bebe278b95fc...d318e5ca |
| Control | Metric | Current / limit | Status | Hash |
|---|---|---|---|---|
Open-finance consent disclosure and scope governance Consumer-permissioned data sharing is transparent, specific, time-bound, revocable, and evidenced before data leaves the platform. | consent journeys with plain language, granular scope, bounded duration, revocation route, notice, live-read, and custody controls | 100.00% / 100.00% | within | 3810f52ba85f...ec7243a0 |
Open-finance data access grant minimization Partner access grants expose only approved data through authenticated, token-bound, logged, and time-limited access. | data access grants with full approved scope coverage, authentication, token binding, least privilege, minimization, refresh review, access log, and custody controls | 100.00% / 100.00% | within | d30526df7b0d...7e6c61f7 |
Open-finance revocation, portability, restriction, and deletion SLA Revocation, portability, restriction, and deletion requests propagate to tokens, partners, records, customer confirmations, and DSAR evidence on time. | rights requests inside SLA with propagation, token disablement, partner notice, customer confirmation, DSAR linkage, and custody controls | 100.00% / 100.00% | within | 48f689809184...1ea98868 |
Open-finance data recipient third-party controls Data recipients are controlled through due diligence, contract limits, onward-sharing restrictions, breach notice, deletion evidence, and security reviews. | data recipients with current diligence, data-use limits, onward-sharing prohibition, incident notice, deletion certificate, security review, and custody controls | 100.00% / 100.00% | within | 9c8b5c688288...37537681 |
Open-finance consent, token, partner, schema, and DSAR reconciliation completeness Consent ledgers reconcile to tokens, partner access, response fields, DSAR exports, revocation queues, and customer impact evidence. | reconciliations with full match rate, zero breaks, break age inside limit, customer impact review, partner access tie-out, revocation tie-out, and custody controls | 100.00% / 100.00% | within | 3dcb0c530361...4da1f434 |
Open-finance customer notice and confirmation control Customers receive clear notices when data is shared and confirmations when rights requests are fulfilled. | consent journeys and rights requests with customer notices, confirmations, and evidence controls | 100.00% / 100.00% | within | 9fa42cbec0b9...b26d3bec |
Open-finance live-read and synthetic-action blocking Open-finance actions fail closed when live consent reads are unavailable or synthetic data would drive sharing. | consent journeys sourced from live read paths with synthetic action blocked | 100.00% / 100.00% | within | 65b970d9cd4a...bc83eea6 |
Open-finance enterprise manifest coverage Open-finance governance maps to API platform, identity, privacy, records, customer outcomes, third-party, cyber, risk data, board, live-read, and auditability controls. | domain controls mapped to required enterprise controls without open findings | 100.00% / 100.00% | within | ffe68b7e90ff...6c1f1c9e |
Open-finance evidence custody Every open-finance row carries reproducible custody for customer, partner, audit, board, and supervisory review. | journey, grant, rights request, recipient, reconciliation, domain-control, and control rows with custody-ready hashes and ready statuses | 100.00% / 100.00% | within | 55bfa838f16c...3f0c8e09 |
Zero overdue open-finance rights request posture Open-finance rights requests are propagated, confirmed, and evidenced before SLA. | revocation, portability, restriction, or deletion requests older than SLA awaiting propagation, token disablement, partner notice, confirmation, DSAR, or custody | 0 / 0 | within | 7ddcf7b82355...167b3a20 |
| Trigger | Owner | Action | Deadline | Status |
|---|---|---|---|---|
| No open-finance consent governance action packs are required for the current evidence set. | ||||
Sandbox request composed for submit decision.
| Name | Type | Required | Description | Example |
|---|---|---|---|---|
| id | path | yes | Situ application identifier. | app_KE_240711_9F3D |
| notify_borrower | query | no | Send borrower SMS after decision. | true |
| Name | Type | Required | Description | Example |
|---|---|---|---|---|
| Authorization | string | yes | Bearer JWT issued from the Situ developer console. | Bearer sit_sandbox_ke_JWT... |
| Idempotency-Key | string | no | Required on POST/PUT money movement and decision endpoints. | idem_KE_240711_001 |
| X-Situ-Tenant | string | yes | Partner tenant short code. | ke-msme-alpha |
{
"decision": "approved",
"approved_amount_kes": 320000,
"term_months": 12,
"apr_percent": 18.4,
"repayment_day": 28,
"explainability": {
"risk_band": "B",
"top_positive_factor": "Consistent M-Pesa inflows",
"top_negative_factor": "Thin CRB repayment history"
},
"officer_reference": "NBO-CRO-118"
}{
"application_id": "app_KE_240711_9F3D",
"decision": "approved",
"loan_id": "loan_KE_240711_6H2Q",
"approved_amount_kes": 320000,
"monthly_instalment_kes": 30210,
"disclosure_url": "https://sandbox.situ.co.ke/disclosures/app_KE_240711_9F3D",
"mpesa_reference": "MP240711123456",
"webhook_queued": true
}Scoped keys for sandbox, production, and webhook automation.
Create a scoped key for a partner integration. The secret is revealed once.
| Key name | Prefix | Created | Last used | Scope | Status | Secret | Actions |
|---|---|---|---|---|---|---|---|
| Sandbox Partner App | sk_sbox_8KJ4 | 2026-07-04 | 2 minutes ago | readwritewebhooks | active | Revealsk_sbox_8KJ4u2QvMfiNairobi0711 | RevokeConfirm revocation for Sandbox Partner App. Existing requests using this key will fail with SITU-401-AUTH. |
| Equity production sync | sk_live_EQT9 | 2026-06-18 | 11 minutes ago | readwriteadmin | rotating | Revealsk_live_EQT9p7mLaaSProduction | RevokeConfirm revocation for Equity production sync. Existing requests using this key will fail with SITU-401-AUTH. |
| Webhook replay worker | sk_sbox_WH3R | 2026-05-29 | 3 hours ago | webhooks | active | Revealsk_sbox_WH3RreplayWorker2407 | RevokeConfirm revocation for Webhook replay worker. Existing requests using this key will fail with SITU-401-AUTH. |
| Old mobile pilot | sk_sbox_OLD2 | 2026-03-01 | 31 days ago | read | revoked | Revealsk_sbox_OLD2revokedPilotKey | revoked |
Signed delivery endpoints, event subscriptions, and replay controls.
Register an HTTPS endpoint and generate a signing secret for HMAC-SHA256 verification.
| URL | Events subscribed | Secret prefix | Last delivery | Status |
|---|---|---|---|---|
https://mfi.example.co.ke/situ/events | application.decidedloan.createdrepayment.received | whsec_9F3D | 4 minutes ago | healthy |
https://payments.partner.co.ke/situ/mpesa | mpesa.payment.completedmpesa.b2c.completed | whsec_MP24 | 18 minutes ago | healthy |
https://archive.partner.co.ke/cbk/situ | cbk.return.submittedloan.settled | whsec_CBK7 | retrying now | retrying |
| Webhook | Event | Status | Code | Latency | Payload preview | Retry |
|---|---|---|---|---|---|---|
| MFI core banking events | application.decided | delivered | 200 | 84 ms | app_KE_240711_9F3D approved for KES 320,000 | |
| M-Pesa reconciliation | mpesa.payment.completed | delivered | 204 | 117 ms | MP240711998877 allocated to loan_KE_240711_6H2Q | |
| Regulatory archive | cbk.return.submitted | retrying | 503 | 3010 ms | cbk_2026_06_KE_992 accepted with 1 warning |
Per-key and per-endpoint quota tracking with reset countdowns.
Deterministic Kenya-context data for integration testing.
National ID, KRA PIN, phone, county profiles
Active, arrears, settled, and written-off loans
STK, paybill, B2C, reversals, statement rows
Metropol and TransUnion score fixtures
OpenAPI-style endpoint cards, authentication, errors, and version history.
/applicationsOpen a loan application for a Kenyan borrower with ODPC consent and KYC references.
/applications/{id}Fetch application status, underwriting state, and document checklist.
/applications/{id}/decisionApprove, counter-offer, or decline an application with pricing and explainability metadata.
/loansPage through partner-scoped loans with status, arrears, product, and county filters.
/loans/{id}/scheduleRetrieve instalment schedule with expected principal, interest, fees, and penalties.
/loans/{id}/amortizationShow principal and interest splits over the loan lifecycle.
/repaymentsPost a partner-originated repayment and allocate it to fees, interest, and principal.
/repayments/historyRetrieve repayment history by loan, borrower phone, M-Pesa reference, or date range.
/loans/{id}/settleSettle a loan using an approved quote and payment reference.
/loans/{id}/settlement-quoteGenerate an early settlement quote with accrued interest and waiver rules.
/disbursementsSend loan proceeds to M-Pesa B2C, bank account, or partner wallet.
/disbursements/{id}Track disbursement provider state and final recipient confirmation.
/mpesa/stk-pushInitiate a repayment or fee collection STK push through Daraja sandbox.
/mpesa/b2cSend funds to a customer wallet for approved loan disbursements or refunds.
/mpesa/statementRetrieve normalized M-Pesa cashflow rows for consented affordability analysis.
/crb/pullRequest Metropol or TransUnion Kenya bureau data with borrower consent.
/crb/{id}/reportRetrieve normalized bureau score, tradelines, adverse listings, and freshness metadata.
/cbk/returns/submitSubmit a signed monthly credit return package for CBK reporting.
/cbk/returns/{period}Retrieve return status, validation warnings, and signed package hash.
/webhooksList registered endpoints, subscribed events, health, and delivery statistics.
/webhooksRegister a signed webhook endpoint with event subscriptions and replay policy.
/webhooks/{id}Deactivate a webhook and stop future deliveries. Historical delivery logs remain available.
Authorization: Bearer <token> and X-Situ-Tenant on every call.Idempotency-Key on write and money movement requests.| Code | Status | Meaning | Recovery |
|---|---|---|---|
| SITU-400-VALIDATION | 400 | Request body or query failed schema validation. | Fix field path returned in errors[].path. |
| SITU-401-AUTH | 401 | Bearer token missing, expired, or signed for another environment. | Refresh JWT or switch sandbox/production token. |
| SITU-403-SCOPE | 403 | API key lacks required scope. | Create a scoped key with read, write, webhooks, or admin permission. |
| SITU-409-IDEMPOTENCY | 409 | Idempotency key re-used with a different payload. | Replay the original payload or generate a new key. |
| SITU-429-RATE_LIMIT | 429 | Tenant, endpoint, or burst limit exceeded. | Wait until reset time or request a higher tier. |
| SITU-502-PROVIDER | 502 | Downstream provider such as Daraja or CRB failed. | Retry with exponential backoff and same idempotency key. |
Added transaction classification, inflow bands, and duplicate MP ref suppression.
Retry endpoint now preserves original signature timestamp and delivery id.
Introduced signed digital-credit monthly return package endpoint.
Added provider field and normalized Metropol, TransUnion, and Creditinfo scores.
Decision payloads now include borrower-safe positive and negative risk factors.