POST /v1/loans call returns
an already-active loan — there is no separate approve or disburse
step.
1. Obtain a token
The API lives on two hosts:
Get a token by calling
GET /v1/auth/token on the auth host with your
partner email and password. This endpoint is the only place a token
comes from. Your email and password go to it and nowhere else — the
API host never accepts them; every other call carries the token as
Authorization: Bearer <token>.
{"token": "<JWT>"}. Tokens are valid for 365 days —
see Handling expiry for the
three recommended refresh patterns (proactive exp check, reactive
401 catch-and-retry, or a scheduled rotation cron).
All examples below assume TOKEN is set and BASE=https://api-staging.bsa.ai.
2. Create a customer
The only field you choose is your ownexternalId — the identifier
that ties the LMS customer record back to your system. Everything else
(office, names, legal form, activation date) is filled in server-side
and the customer is created Active immediately.
Response
id field — "42" as a string. Pass it back exactly as
received. firstname mirrors your externalId so the customer is
searchable by it; lastname is a fixed placeholder LMS requires for
person records.
3. Create a loan
Three required fields plus an optionalexternalId — your own
reference for the loan (e.g. a wallet transaction id). customerId
carries the customer’s externalId (the one you chose in step 2),
not the numeric LMS id — you never need to store LMS ids on your side.
Every loan term is inherited from the chosen product. The returned
loan is already Active.
Response (abbreviated)
principalOutstanding,
interestCharged, totalOutstanding, …) plus nextDueDate /
nextDueAmount and the amortisation repaymentSchedule. Partners can
render “you owe X, due Y” without a follow-up GET. dueDateTime is the
exact instant the loan falls due — seven days after disbursedAt to the
second for this product — and the instant a 10% of principal overdue
penalty is posted if the loan is still unpaid. See
Create a loan for the complete field reference and
the overdue penalty for the rules.
4. Record a repayment
Two equivalent forms — by the LMS numeric id, or by the loan’sexternalId you set above.
Always send your own idempotencyKey (your wallet transaction
reference) so a timed-out call can be retried safely, and
transactionAt (the instant the money moved) so a payment made before
dueDateTime is never penalised for reaching us late.
loanStatus, totalOutstanding,
availableCreditLimit). Re-sending the same key returns the same
transaction. To read the ledger back, use
GET /v1/loans/external/$LOAN_EXT/repayments (paginated, or
?idempotencyKey= to find one payment by your reference) — see
Repayments.
Next steps
- Browse the full Customers API
- Read Errors so you can branch on failure codes
- Learn how pagination works on list endpoints

