curl --request GET \
--url https://api.next.orenda.finance/v1/applications/{applicationId}/documents/legal/acceptance \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.next.orenda.finance/v1/applications/{applicationId}/documents/legal/acceptance', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.next.orenda.finance/v1/applications/{applicationId}/documents/legal/acceptance"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"success": true,
"data": {
"applicationId": "app-123",
"accountType": "consumer",
"acceptanceStatus": "accepted",
"currentDocumentSetVersion": "2.0.0",
"acceptance": {
"documentSetVersion": "2.0.0",
"acceptedAt": "2026-02-05T10:30:00.000Z",
"acceptedByIdentity": "user-456",
"acceptedByEmail": "applicant@example.com",
"ipAddress": "203.0.113.10",
"ipCountry": "GBR",
"userAgent": "Mozilla/5.0",
"acceptedDocuments": [
{
"id": "privacy_policy",
"name": "Privacy Policy",
"location": "https://assets.orenda.finance/term-docs/Privacy_Policy.pdf",
"version": "1",
"hash": "sha256:e5f6a7b8c9d0",
"required": true,
"applicableTo": [
"consumer",
"business"
],
"effectiveDate": "2026-02-05"
}
]
}
}
}{
"success": false,
"code": "VALIDATION_ERROR",
"message": "applicationId is required"
}{
"message": "Unauthorized"
}{
"success": false,
"code": "FORBIDDEN",
"message": "Back Office access is required"
}{
"success": false,
"code": "RESOURCE_NOT_FOUND",
"message": "Application not found"
}{
"success": false,
"code": "INTERNAL_SERVER_ERROR",
"message": "Internal Server Error"
}Get legal document acceptance
Returns the stored legal-document acceptance audit record for an application and compares its document-set version with the current program configuration. This is a read-only back-office endpoint: it does not accept documents, enqueue agreement processing, contact a provider, or advance onboarding.
acceptanceStatus is accepted when the stored and current document-set versions match, not_accepted when no acceptance is stored, stale when the stored version is older or otherwise different, and indeterminate when an acceptance exists but no current program document set is available.
Auth: bearer JWT with a back-office role and applications.agreements.view permission.
curl --request GET \
--url https://api.next.orenda.finance/v1/applications/{applicationId}/documents/legal/acceptance \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.next.orenda.finance/v1/applications/{applicationId}/documents/legal/acceptance', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.next.orenda.finance/v1/applications/{applicationId}/documents/legal/acceptance"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"success": true,
"data": {
"applicationId": "app-123",
"accountType": "consumer",
"acceptanceStatus": "accepted",
"currentDocumentSetVersion": "2.0.0",
"acceptance": {
"documentSetVersion": "2.0.0",
"acceptedAt": "2026-02-05T10:30:00.000Z",
"acceptedByIdentity": "user-456",
"acceptedByEmail": "applicant@example.com",
"ipAddress": "203.0.113.10",
"ipCountry": "GBR",
"userAgent": "Mozilla/5.0",
"acceptedDocuments": [
{
"id": "privacy_policy",
"name": "Privacy Policy",
"location": "https://assets.orenda.finance/term-docs/Privacy_Policy.pdf",
"version": "1",
"hash": "sha256:e5f6a7b8c9d0",
"required": true,
"applicableTo": [
"consumer",
"business"
],
"effectiveDate": "2026-02-05"
}
]
}
}
}{
"success": false,
"code": "VALIDATION_ERROR",
"message": "applicationId is required"
}{
"message": "Unauthorized"
}{
"success": false,
"code": "FORBIDDEN",
"message": "Back Office access is required"
}{
"success": false,
"code": "RESOURCE_NOT_FOUND",
"message": "Application not found"
}{
"success": false,
"code": "INTERNAL_SERVER_ERROR",
"message": "Internal Server Error"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Application identifier.
Query Parameters
Program to inspect. Required for back-office tokens that do not already carry a program context.