Application Onboarding API Integration Guide

Step-by-step guidance for integrating with the Application Onboarding APIs, including authentication and best practices.

The integration is designed around an event-driven model:

  • The broker submits a new Individual or Joint Application.

  • The broker (or customer) uploads the required disclosure and ID documents.

  • Dorman verifies that all required documents have been received.

  • Dorman sends webhook notifications when the application status changes.

This integration relies on webhook callbacks to notify you when an application's status changes. For guidance on registering your webhook endpoint and the full reference of event types and payload formats, see the [Application Webhook Guide].

Webhook notifications are the primary method for receiving status updates. The Get Application Status API is available as a fallback mechanism when webhook notifications are unavailable.

Overview

    Register Webhook (If you want to receive application status webhook callbacks)        
│
▼
Create Application (Individual or Joint)
│
▼
Upload Required Documents
│
▼
Dorman Verifies Completion
│
▼
Receive Webhook Event
│
▼
Update Customer Status
│
▼
(Optional) Get Application Status API

Before You Begin

Before integrating the Application Onboarding APIs, ensure you have:

  • Broker API Key – Used to authenticate all API requests

  • Registered Webhook Endpoint – Required to receive application status callbacks; see the [Application Webhook Guide] to register

    • Webhook Authentication Logic – Validates Authorization header

    • HMAC Signature Validation – Validates webhook authenticity

Authentication

All Application Onboarding APIs require the broker API key.

Example:

Ocp-Apim-Subscription-Key: your-api-key

If authentication fails, the API returns standard HTTP responses such as:

  • 400 – Missing header

  • 401 – Broker inactive

  • 404 – Invalid broker key

Authentication requirements apply to all Application Onboarding APIs.

API 1 – Create Individual Application

Broker Integration Guidelines

This API creates a new Individual application for a customer, capturing profile, address, employment, asset, trading profile, and representation details in a single submission.

Endpoint:

POST /api/application/addindividualapplication

Information required

The request captures the applicant's full profile in sections — Profile, Residential Address, Employment, Asset, Trading Profile, and Representation. See the interactive API reference for the complete field list.

When to call this API

Call this API when submitting a new Individual application on behalf of a customer.

Before calling this API

Verify that you have:

  • Complete and accurate applicant details for every required section

  • A valid residential (and mailing, if different) address with a supported country code

  • A registered webhook endpoint

  • Your broker API key

After receiving the response

Store the following value immediately:

  • ApplicationId

The ApplicationId is the primary identifier for the application and should be retained for:

  • status lookups,

  • document uploads,

  • troubleshooting,

  • customer support.

What happens next

After the application is created:

  1. Dorman marks the application InProgress and sends a webhook notification to your registered endpoint.

  2. The broker or customer uploads the required documents using the Upload Document API.

  3. Once all required documents are received, Dorman marks the application Complete and sends another webhook notification.

No additional action is required while documents are being collected. See the [Application Webhook Guide] for the exact event types and payload format.

Best Practices

  • Persist the ApplicationId immediately.

  • Validate country codes and required fields client-side before submitting, to reduce rejected requests.

  • Use the Get Application Status API to confirm which documents are still outstanding.

API 2 – Create Joint Application

Broker Integration Guidelines

This API creates a new Joint application, capturing full profile details for both the Primary and Secondary applicants in a single submission.

Endpoint:

POST /api/application/addjointapplication

Information required

The request contains two applicant objects — Primary and Secondary — each with the same Profile, Residential Address, Employment, Asset, Trading Profile, and Representation sections used by the Individual Application API. See the interactive API reference for the complete field list.

When to call this API

Call this API when submitting a new Joint application on behalf of two customers.

Before calling this API

Verify that you have:

  • Complete and accurate details for both the Primary and Secondary applicant

  • Valid residential (and mailing, if different) addresses with supported country codes for both applicants

  • A registered webhook endpoint

  • Your broker API key

After receiving the response

Store both of the following values immediately:

  • ApplicationId (Primary applicant)

  • SecondaryApplicationId (Secondary applicant)

Both IDs should be retained for status lookups, document uploads, troubleshooting, and customer support. Documents for the Secondary applicant (e.g., their government-issued ID) are uploaded against the Primary ApplicationId.

What happens next

After the application is created:

  1. Dorman marks both the Primary and Secondary records InProgress and sends a separate webhook notification for each applicant.

  2. The broker or customer uploads the required documents using the Upload Document API.

  3. Once all required documents are received, Dorman marks the application Complete and sends another webhook notification.

Best Practices

  • Persist both the ApplicationId and SecondaryApplicationId immediately.

  • Track document requirements separately for the Primary and Secondary applicant — Joint applications require a government-issued ID for both applicants.

  • Use the Get Application Status API to confirm which documents are still outstanding.

API 3 – Upload Document

Broker Integration Guidelines

This API uploads a single required document (disclosure or identification) against an existing Individual or Joint application.

Endpoint:

POST /api/application/uploaddocument

Information required

Submitted as multipart/form-data:

Field and Description

  • ApplicationId :The application to attach the document to

  • ApplicationType : Individual or Joint

  • DocumentId :Identifies which required document is being uploaded

  • File :The document file (PDF, PNG, JPEG, or GIF)

When to call this API

Call this API once per required document, after an Individual or Joint application has been created.

Before calling this API

Verify that you have:

  • A valid ApplicationId from a previously created application

  • The correct ApplicationType for that application

  • The correct DocumentId for the document being uploaded

  • A file in one of the supported formats (PDF, PNG, JPEG, GIF)

Document rules

  • Most documents can only be uploaded once per application; re-uploading the same document returns an error.

  • Additional supporting uploads may be submitted multiple times.

  • Individual applications require one government-issued ID (Primary Applicant). Joint applications require a government-issued ID for both the Primary and Secondary (Joint) applicant.

  • The required identity-verification document depends on the applicant's US citizenship status.

What happens next

Once all required documents for an application have been received:

  1. Dorman marks the application Complete and sends a webhook notification.

  2. For qualifying US citizen Individual applications, Dorman automatically initiates additional account verification — no action is required on your end.

See the [Application Webhook Guide] for the exact event types and payload format.

Best Practices

  • Upload documents as soon as they're available rather than batching all uploads together, to speed up completion.

  • Use the Get Application Status API response to confirm exactly which documents are still missing before re-uploading.

  • Handle the "already uploaded" error gracefully — treat it as informational rather than a failure.

API 4 – Get Application Status

Broker Integration Guidelines

This API provides the latest status for an application — including any missing required documents — and is intended primarily as a fallback mechanism when webhook notifications cannot be received.

Endpoint:

POST /api/application/getapplicationstatus

Information required

json:

{   
"ApplicationId": 10245,
"ApplicationType": "Individual"
}

When to call this API

Use this API only when necessary, including:

  • webhook delivery failure,

  • manual status refresh,

  • customer support investigations,

  • recovery after application downtime.

How to use the response

Use the returned status to update the customer experience.

Examples:

  • InProgress – Application created; one or more required documents are still outstanding. The response includes a list of the missing document names.

  • Complete – All required documents received and verified.

Best Practices

  • Always use the ApplicationId returned from the Create Application call.

  • For Joint applications, the response includes the SecondaryApplicationId when available.

  • Continue relying on webhook notifications whenever possible.

  • Avoid frequent polling.

  • Use this API only when the current status is unknown.