Create intake

Creates a borrower and loan for one submission and returns an upload URL for it. Reusing a clientReference returns the same borrower and loan instead of creating another pair.

Authentication

AuthorizationBearer
Bearer token. Use `ss_live_…` for live data or `ss_test_…` for the sandbox (test mode). See [Authentication](https://docs.spreadspace.app/api/authentication).

Headers

Idempotency-KeystringOptional<=255 characters
Idempotency token. Retries that reuse the key within 24h replay the original response. Up to 255 characters; a UUID is typical. See [Idempotency](https://docs.spreadspace.app/api/idempotency).
SpreadSpace-VersionstringOptionalformat: "^\d{4}-\d{2}-\d{2}$"
Pin the API version, e.g. `2026-07-19`. Omit to get the latest. See [Versioning](https://docs.spreadspace.app/api/versioning).

Request

This endpoint expects an object.
file_namestringRequired<=255 characters
content_typestringRequired<=100 characters
file_sizelong or nullOptional1-104857600

Optional file size in bytes, reported by the client. The upload itself is capped server-side.

content_hashstring or nullOptionalformat: "^[a-fA-F0-9]{64}$"<=64 characters

SHA-256 hex digest of the file, computed client-side. Used for within-loan duplicate detection. Verified server-side during processing.

client_referencestring or nullOptional<=128 characters

Customer-supplied idempotency / grouping key. Unique per tenant: repeat submissions for the same end-borrower pile onto the same auto-provisioned loan. Omit to always create a new submission.

borrower_namestring or nullOptional<=256 characters

Optional human-readable borrower name. When omitted, the auto-provisioned borrower gets a placeholder name; the is_intake flag (not the name) marks it as not-yet-completed. Completion renames the borrower in place.

Response headers

X-Request-IDstringOptional
Correlation ID for this request. Quote it in support tickets.
Idempotency-Replayboolean

Set to true when the response is replayed from the idempotency cache for a request that re-presented an Idempotency-Key it had already used. Absent on the original (winner) response. Replays are byte-for-byte identical to the original response body.

SpreadSpace-VersionstringOptional

The API surface version the server resolved for this request. Always present, regardless of whether the client supplied the request-side SpreadSpace-Version header. Default: 2026-07-19.

RateLimit-Limitinteger
Request budget of the endpoint's rate-limit policy per 60-second sliding window. See [Rate limits](https://docs.spreadspace.app/api/rate-limits).
RateLimit-Remaininginteger

Requests left in the current window. Suppressed on 429 responses produced outside the rate limiter (for example a usage throttle), where a remaining budget would be misleading.

RateLimit-Resetinteger

Seconds until a guaranteed-fresh window.

RateLimit-PolicystringOptional

The active policy in limit;w=window-seconds form.

Response

OK
job_idstring
loan_idstring
borrower_idstring
upload_urlstring
expires_in_secondsinteger

Errors

400
Bad Request Error
401
Unauthorized Error
402
Payment Required Error
403
Forbidden Error
404
Not Found Error
409
Conflict Error
429
Too Many Requests Error
500
Internal Server Error