generated: '2026-07-20' method: searched source: https://developers.opercredits.com/ (Oper Connect Documentation — Authentication, API usage guidelines) + openapi/oper-credits-api-openapi.json summary: >- Cross-cutting request/response semantics for the Oper Connect / Oper Mortgage API, a multi-tenant Django REST Framework platform. Auth is JWT bearer with refresh tokens; collections are page-number paginated; the central object is the loan request, under which all other resources are nested. authentication: style: jwt-bearer header: 'Authorization: Bearer ' scheme: openapi/oper-credits-api-openapi.json#/components/securitySchemes/jwtAuth refresh: Access tokens have a limited lifetime and are refreshed with a refresh token. notes: >- Some tenants add an OTP step on Journey Builder (e.g. Fundamenta) requiring user credentials plus a code sent to the user's phone; other tenants require only user credentials. docs: https://developers.opercredits.com/#/guides cross_ref: authentication/oper-credits-authentication.yml pagination: style: page-number params: - name: page in: query description: Page number of the result set. - name: page_size in: query description: Number of results per page. derived_from: openapi/oper-credits-api-openapi.json idempotency: supported: false notes: >- No idempotency-key header or parameter is declared in the OpenAPI or documented. Write safety is achieved by persisting to a durable loan-request object model rather than an idempotency contract. versioning: scheme: resource-versioned webhook_versions: ['1.0', '1.1', '1.2', '1.3', '1.4'] webhook_current_stable: '1.3' webhook_beta: '1.4' notes: >- The Loan Request Webhook API is versioned 1.0-1.4 (1.3 stable, 1.4 beta). The core REST API operations are unversioned in-path (paths under /api/ and /resources/). error_envelope: format: drf-detail shape: '{ "detail": "" } (and per-field validation maps on 400)' notes: >- Standard Django REST Framework error envelope; the OpenAPI declares only 2xx responses, so 400/401/403/404 shapes are the DRF defaults rather than in-spec. cross_ref: errors/oper-credits-problem-types.yml data_model: central_object: loan_request nesting: All resources (clients, realties, offers, documents, guarantees, ...) are proprietary to a single loan request and addressed under /api/loan-requests/{loan_request_id}/. cross_ref: data-model/oper-credits-data-model.yml privacy: gdpr: Loan request data is anonymised after a configurable retention period (expressed in months) to conform with GDPR.