Update loan

Updates a loan. Only the fields you send change.

Authentication

AuthorizationBearer
Bearer token. Use `ss_live_…` for live data or `ss_test_…` for the sandbox (test mode). See [Authentication](https://docs.spreadspace.app/api/authentication).

Path parameters

idstringRequired
The loan's id.

Headers

Idempotency-KeystringOptional<=255 characters
Idempotency token. Retries that reuse the key within 24h replay the original response. Up to 255 characters; a UUID is typical. See [Idempotency](https://docs.spreadspace.app/api/idempotency).
SpreadSpace-VersionstringOptionalformat: "^\d{4}-\d{2}-\d{2}$"
Pin the API version, e.g. `2026-07-19`. Omit to get the latest. See [Versioning](https://docs.spreadspace.app/api/versioning).

Request

This endpoint expects an object.
loan_typestring or nullOptional<=100 characters
loan_sub_typestring or nullOptional<=100 characters
namestring or nullOptional<=200 characters
loan_numberstring or nullOptional<=100 characters
requested_amountdouble or nullOptional0-999999999999.99
rate_typestring or nullOptionalformat: "^(Fixed|SOFR|Prime)$"<=20 characters
interest_ratedouble or nullOptional0-99.999
term_monthsinteger or nullOptional1-600
notesstring or nullOptional<=2000 characters
statusstring or nullOptional<=50 characters
prioritystring or nullOptional<=20 characters
guarantorslist of strings or nullOptional

Guarantor names declared on the loan. Omit the field to leave the declared list untouched; a list replaces it wholesale, and an empty list clears it.

Response headers

X-Request-IDstringOptional
Correlation ID for this request. Quote it in support tickets.
Idempotency-Replayboolean

Set to true when the response is replayed from the idempotency cache for a request that re-presented an Idempotency-Key it had already used. Absent on the original (winner) response. Replays are byte-for-byte identical to the original response body.

SpreadSpace-VersionstringOptional

The API surface version the server resolved for this request. Always present, regardless of whether the client supplied the request-side SpreadSpace-Version header. Default: 2026-07-19.

RateLimit-Limitinteger
Request budget of the endpoint's rate-limit policy per 60-second sliding window. See [Rate limits](https://docs.spreadspace.app/api/rate-limits).
RateLimit-Remaininginteger

Requests left in the current window. Suppressed on 429 responses produced outside the rate limiter (for example a usage throttle), where a remaining budget would be misleading.

RateLimit-Resetinteger

Seconds until a guaranteed-fresh window.

RateLimit-PolicystringOptional

The active policy in limit;w=window-seconds form.

Response

OK
loan_idstring
borrower_idstring
assigneeslist of objects
statusstring
created_atdatetime
updated_atdatetime
borrowerobject or null

Borrower summary nested into a LoanResponse when the caller requests ?include=borrower on a loan list endpoint. Carries the borrower metadata the list surface already exposes (name, entity type, location, industry), never a tax identifier, so a per-loan borrower read is not needed.

borrower_namestring or nullOptional
loan_typestring or nullOptional
loan_sub_typestring or nullOptional
loan_type_labelstring or nullOptional
loan_sub_type_labelstring or nullOptional
namestring or nullOptional
loan_numberstring or nullOptional
requested_amountdouble or nullOptional
rate_typestring or nullOptional
interest_ratedouble or nullOptional
term_monthsinteger or nullOptional
prioritystring or nullOptional
notesstring or nullOptional
guarantorslist of strings or nullOptional

Guarantor names declared on the loan. Gated like Notes: null when the caller may not read the loan file, and null when none were declared.

documentslist of objects or nullOptional

Nested per-loan document summaries. Populated only when the loan list endpoint was called with ?include=documents and the caller may read this loan, and null otherwise. The field is always present on the wire; an empty list means the loan has no documents yet.

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
409
Conflict Error
429
Too Many Requests Error
500
Internal Server Error