Create a case
curl --request POST \
--url https://app.sahlfinancial.com/api/v1/cases \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"applicant_name": "Test Client",
"applicant_cin": "AB123456",
"borrower_type": "private_sector",
"priority": "medium",
"environment": "sandbox"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
applicant_name: 'Test Client',
applicant_cin: 'AB123456',
borrower_type: 'private_sector',
priority: 'medium',
environment: 'sandbox'
})
};
fetch('https://app.sahlfinancial.com/api/v1/cases', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/cases"
payload = {
"applicant_name": "Test Client",
"applicant_cin": "AB123456",
"borrower_type": "private_sector",
"priority": "medium",
"environment": "sandbox"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "7e3b9a14-2d6c-4c85-b1f0-6a8d4e2c9b37",
"tenant_id": "0b6f5a3e-7c1d-4e0a-9d2f-3a1c5e8b7f10",
"document_id": null,
"applicant_name": "Test Client",
"applicant_cin": "AB123456",
"borrower_type": "private_sector",
"status": "new",
"priority": "medium",
"score": null,
"risk_level": null,
"eligible_amount": null,
"score_breakdown": null,
"ai_insight": null,
"decision": null,
"decision_at": null,
"decision_by": null,
"decision_note": null,
"assigned_to": null,
"environment": "sandbox",
"external_reference": null,
"metadata_json": null,
"created_at": "2026-10-07T09:14:22Z",
"updated_at": "2026-10-07T09:14:22Z"
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": "Document not found"
}{
"detail": [
{
"type": "missing",
"loc": [
"body",
"bank_code"
],
"msg": "Field required",
"input": {}
}
]
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Create a case
Who can call it: tenant_admin, tenant_reviewer, tenant_api_manager or platform_admin. A tenant_viewer is read-only and gets 403.
environment in the body picks the workspace (default sandbox). Fires the case.created webhook. In production on the Free plan: 403 work_email_required without a verified work email, 429 production_case_limit_reached past the monthly Production cases.
Auth: dashboard session (Authorization: Bearer <access token>). Not available with a partner API key.
Create a case
curl --request POST \
--url https://app.sahlfinancial.com/api/v1/cases \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"applicant_name": "Test Client",
"applicant_cin": "AB123456",
"borrower_type": "private_sector",
"priority": "medium",
"environment": "sandbox"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
applicant_name: 'Test Client',
applicant_cin: 'AB123456',
borrower_type: 'private_sector',
priority: 'medium',
environment: 'sandbox'
})
};
fetch('https://app.sahlfinancial.com/api/v1/cases', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/cases"
payload = {
"applicant_name": "Test Client",
"applicant_cin": "AB123456",
"borrower_type": "private_sector",
"priority": "medium",
"environment": "sandbox"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "7e3b9a14-2d6c-4c85-b1f0-6a8d4e2c9b37",
"tenant_id": "0b6f5a3e-7c1d-4e0a-9d2f-3a1c5e8b7f10",
"document_id": null,
"applicant_name": "Test Client",
"applicant_cin": "AB123456",
"borrower_type": "private_sector",
"status": "new",
"priority": "medium",
"score": null,
"risk_level": null,
"eligible_amount": null,
"score_breakdown": null,
"ai_insight": null,
"decision": null,
"decision_at": null,
"decision_by": null,
"decision_note": null,
"assigned_to": null,
"environment": "sandbox",
"external_reference": null,
"metadata_json": null,
"created_at": "2026-10-07T09:14:22Z",
"updated_at": "2026-10-07T09:14:22Z"
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": "Document not found"
}{
"detail": [
{
"type": "missing",
"loc": [
"body",
"bank_code"
],
"msg": "Field required",
"input": {}
}
]
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Authorizations
The access token (JWT) of a signed-in console user, from POST /v1/auth/login. It lasts 30 minutes. It is not an API key: a partner API key is refused here. There is no cookie.
Body
application/json
Maximum string length:
255Maximum string length:
32Available options:
private_sector, public_sector, retiree, professional, merchant Available options:
low, medium, high, urgent Available options:
sandbox, production Response
Created