Api Master

API Master

How each lender API operates and what emails fire on send.

CFG Merchant Solutions·sandbox
Bitty Advance·dev
Credibly·uat

CFG Merchant Solutions

Dual Email

Synchronous merchant application + bank statements push (CFGMS App Submission API v1.4.0).

Secrets OKActive env: sandbox
Endpoints
sandbox
https://app-submit-sandbox.cfgms.com/application
prod
(not issued — CFGMS provides after sandbox validation)
Authentication

Basic HTTP Auth — API key as username, empty password

CFGMS_API_KEY ✓
Payload Sent
  • ▸isoName, appPurpose, amountRequested (cents), avgMonthlyRevenue (cents)
  • ▸business { name, address, ein, dba, industry, startDate, website }
  • ▸owner1 + owner2 (if has_second_owner) — home address only, no mortgage fallback
  • ▸applicationPdf (base64, watermarked, unredacted)
  • ▸bankStatementPdfs (up to 4, base64, watermarked, unredacted)

grossAnnualRevenue removed. Owner home address read directly (no applicant_primary_residence fallback). All PDFs watermarked, contact info unredacted.

Dual Email on API SendOn a 201 success, emails a full package copy (application PDF + up to 4 bank statements) to api_email_recipients. Defaults ON when no partner record exists. CC's submission_email_2 if set.

No FundingPartner record with api_partner_key="cfgms" exists yet. Create one on the Partners page to enable email controls.

Bitty Advance

No Dual Email

Bitty Advance Portal Submission API V3 — instant pre-offer / decline / duplicate response.

Secrets MissingActive env: dev
Endpoints
dev
https://dev.bittyadvance.com/api/submit
prod
https://broker.bittyadvance.com/api/submit
Authentication

API key in JSON body (apikey field, not a header)

BITTY_API_KEY ✗
Payload Sent
  • ▸apikey, development (bool), leadid, campaign, subid1
  • ▸legal_name, dba_name, business address, ein, start_date, website
  • ▸bank_name, bank_routing, bank_account
  • ▸owners[] (up to 2 — address, phone, dob, ssn, fico, ownership %)
  • ▸requested_amount, average_revenue, advance_current + up to 2 positions
  • ▸files[] (type 1=App PDF, 2=Bank Statements x4, 3=DL, 4=Voided Check — base64, watermarked, unredacted)

Up to 4 bank statements attached. All PDFs watermarked, contact info unredacted.

Dual Email on API SendNo dual email in the Bitty function. Email fields on the partner record are not used by this integration.

Credibly

No Dual Email

Credibly ISO API — builds SubmissionRequest (business_overview, account_overview, principals) from the application and POSTs to /v2/submissions.

Secrets MissingActive env: uat
Endpoints
uat
https://api-uat.credibly.com/v2/submissions
prod
https://api.credibly.com/v2/submissions
Authentication

JWT Bearer — fetched via /v2/get-jwt using X-API-KEY header (CREDIBLY_JWT_BEARER_UAT)

CREDIBLY_JWT_BEARER_UAT ✓
CREDIBLY_API_KEY_UAT ✗
CREDIBLY_API_KEY_PROD ✗
Payload Sent
  • ▸business_overview { legal_name, dba, business_address, city, state, zip, ownership_type, federal_tax_id (XX-XXXXXXX), start_date, website }
  • ▸account_overview { avg_monthly_deposits }
  • ▸principals[] { first_name, last_name, percent_ownership, ssn (XXX-XX-XXXX), address, city, state, zip, dob, email }
  • ▸amount_requested (integer, optional — from product_requested_amounts.mca or requested_amount)

Builds the full Credibly SubmissionRequest from the application. EIN formatted XX-XXXXXXX, SSN formatted XXX-XX-XXXX, dates ISO-8601. Up to 2 principals. JWT auth via shared crediblyAuth module (X-API-KEY header).

Dual Email on API SendNo dual email. Pass-through does not send a package copy.