Skip to content
Developer guide

Upload documents and signatures

Browse developer guides

Use an existing applicationId from application setup. These upload routes accept document bytes as a JSON base64 string and metadata in the query string.

Choose an upload route

PurposeMethod and routeRequired query parameters
Bank statementPOST /api/Application/submit-bankstatement-document/{applicationId}fileName
Requested supporting documentPOST /api/ApplicationApproval/submit-required-document/{applicationId}supportingDocumentId, fileType, fileName
Other supporting documentPOST /api/ApplicationApproval/submit-document/{applicationId}fileType, fileName

For a requested document, first call GET /api/ApplicationApproval/get-required-documents/{applicationId} and use the returned requirement identifier. Use the required document type for fileType; do not assume it is the HTTP content type. The generic submit-document route still requires fileType even though the current handler does not use it when storing the file.

Encode and send the file

Read the original file as bytes, base64-encode it, and JSON-encode that string. The complete body is the quoted string. Do not wrap it in a fileData object, use a multipart file field, or send unencoded binary bytes.

The following Bash example uses Python 3 to encode the file and curl to submit it. It assumes BASE_URL, TOKEN and APPLICATION_ID are already set. Run it only with a test file in your assigned test environment.

python -c 'import base64,json,pathlib; print(json.dumps(base64.b64encode(pathlib.Path("statement.pdf").read_bytes()).decode("ascii")))' > document-body.json
curl --request POST "$BASE_URL/api/Application/submit-bankstatement-document/$APPLICATION_ID?fileName=statement.pdf" \
  --header "Authorization: Bearer $TOKEN" \
  --header 'Content-Type: application/json' \
  --data-binary @document-body.json

URL-encode metadata values such as filenames. Delete temporary encoded documents when finished. The encoding follows Json.NET's byte-array serialization, used by this API.

Check the result and limits

The current handlers return HTTP 200 with true when successful. Some Swagger responses omit that body schema; clients should not expect a document object from those operations.

Files must be non-empty and at most 15 MiB (15 × 1024 × 1024 decoded bytes). Base64 increases the HTTP body size, and the host can reject a large request before controller validation. Approval document uploads also require an unexpired offer; the bank-statement handler instead checks that the application exists.

Sign a contract

Read the contract details and applicant list before calling POST /api/ApplicationApproval/sign-contract/{applicationId}/{applicantId}. Use the applicant ID from that application.

SignaturesRequest contains ipAddress, mimeType, signature, signature2 and secondaryApplicant. Both signatures must contain non-empty base64-encoded image bytes. Here, the encoded strings are properties in a JSON object, unlike the document-upload body. Supply the actual captured signatures and matching MIME type. Signing also requires an unexpired offer.

If an upload or signing request fails, use error handling and verify the application's state before resubmitting.