Get the current application (v2)
curl --request GET \
--url https://api.next.orenda.finance/v2/applications \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.next.orenda.finance/v2/applications"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.next.orenda.finance/v2/applications', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.next.orenda.finance/v2/applications",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.next.orenda.finance/v2/applications"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.next.orenda.finance/v2/applications")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.next.orenda.finance/v2/applications")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"application": {
"applicationId": "app_5e8d2f1a",
"customerId": "cust_3f9a2b7e",
"isCompany": false,
"role": {
"key": "PROGRAM_CUSTOMER",
"alias": "PROGRAM_CUSTOMER",
"name": "Customer"
},
"capabilities": {
"ownAccounts": true,
"funding": "OWN",
"delegate": null
},
"primaryApplicant": {
"firstName": "Ada",
"lastName": "Lovelace",
"email": "ada.lovelace@example.com"
},
"ubos": [],
"legalAccepted": true,
"kycResult": null,
"createdAt": "2026-06-18T10:32:00Z",
"updatedAt": "2026-06-18T10:44:12Z"
},
"status": {
"currentStep": "KYC_FORM",
"requiredActions": [
"complete-kyc-form"
]
}
}
}
Onboarding
Get the current application
Poll the application and render its current step.
GET
/
v2
/
applications
Get the current application (v2)
curl --request GET \
--url https://api.next.orenda.finance/v2/applications \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.next.orenda.finance/v2/applications"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.next.orenda.finance/v2/applications', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.next.orenda.finance/v2/applications",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.next.orenda.finance/v2/applications"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.next.orenda.finance/v2/applications")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.next.orenda.finance/v2/applications")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"application": {
"applicationId": "app_5e8d2f1a",
"customerId": "cust_3f9a2b7e",
"isCompany": false,
"role": {
"key": "PROGRAM_CUSTOMER",
"alias": "PROGRAM_CUSTOMER",
"name": "Customer"
},
"capabilities": {
"ownAccounts": true,
"funding": "OWN",
"delegate": null
},
"primaryApplicant": {
"firstName": "Ada",
"lastName": "Lovelace",
"email": "ada.lovelace@example.com"
},
"ubos": [],
"legalAccepted": true,
"kycResult": null,
"createdAt": "2026-06-18T10:32:00Z",
"updatedAt": "2026-06-18T10:44:12Z"
},
"status": {
"currentStep": "KYC_FORM",
"requiredActions": [
"complete-kyc-form"
]
}
}
}
Poll this endpoint (the reference app polls about once a second) and render the screen for
status.currentStep. On IN_REVIEW, poll every 30 seconds or so instead: a review can take
hours. The application advances on its own as each step completes, so the
value changes between polls.
- v2 (recommended)
- v1
GET /v2/applications returns { application, status }.status.currentStepis always one of ten values, one per screen. The overview lists them and what to render.status.requiredActionslists what the user must do on that screen. It is empty while you wait: for example, for a few seconds after the KYC form is submitted or legal agreements are accepted,currentStepisPROCESSING. Show a loader and keep polling.- A change you’ve already made to an existing application is reflected immediately, so a
poll right after an accepted request shows
PROCESSINGrather than asking again. Right after creating an application, use the onePOST /v2/applicationsreturned; this read can briefly return404until the new application is indexed. - If the platform can’t finish a step in time (a few minutes; up to 20 for a KYC form), the step comes back so the user can try again. Treat any value as possible after any other.
currentStep is COMPLETED, onboarding is done.A 403 can mean the access token expired, not only that a management token was used:
refresh the token and retry before treating it as a permissions error.GET /v1/applications still works and is unchanged. It returns the stored application record,
with status both at the top level and inside application, and currentStep holds detailed
internal step names (see the v1 tab in the overview).It doesn’t report steps the platform is still finishing. For a few seconds after legal
agreements are accepted it still shows LEGAL_AGREEMENTS, so after a successful accept keep a
loader up until currentStep changes. When currentStep is CUSTOMER or MEMBER, onboarding is done.