Vitality Partner API Gateway
Vitality's production API gateway, running WSO2 API Manager at apis.vitality.co.uk (origin wso2-prd-apigw.tvc.vitality.co.uk:8243 behind an AWS load balancer in eu-west-1). The gateway is publicly resolvable and returns HTTP 200, and its OAuth2/OpenID Connect identity layer is fully published anonymously — discovery document, JWKS, authorization, token, userinfo, introspection, revocation, device-authorization and logout endpoints are all live. The business APIs behind it are not: no API catalogue, no reference documentation and no machine-readable contract are exposed, every WSO2 developer-portal route returns the 404 fault document, and the token endpoint rejects anonymous callers with invalid_client. Credentials are issued through commercial partner onboarding rather than a signup form. This entry records a real, verified, undocumented API surface — it is not a claim that Vitality operates a public API programme.