If this is a Polaris system, it sounds like they might be using a default loan period. I wonder if the Communico app is logging in using a weird/different branch that they don’t have loan rules set up for?
Just to clarify what we’ve seen in this regard, some vendors mistakenly believed they needed to put their product version or the version of the base Polaris system in their PAPI URLs; this was never documented to work that way, but prior to 7.6, the Polaris API accepted any version number. After 7.6, it is only accepting the versions that were specified in the documentation, primarily v1, but for some PAPI calls, v2 is also accepted. You can find out more here: Polaris 7.6+ potentially breaks 3rd party integrations using PAPI