APRA website screenshot

APRA

The Australian Prudential Regulation Authority (APRA) is the Commonwealth statutory authority that prudentially supervises Australia's banks, credit unions, building societies, general insurers, life insurers, private health insurers, reinsurers and most of the superannuation industry, protecting depositors, policyholders and fund members under the Financial Sector (Collection of Data) Act 2001 and the Insurance Act 1973. Across insurance it authorises and registers general insurers, life insurers and friendly societies, and private health insurers; publishes prudential standards and practice guides; maintains public registers of authorised institutions; and runs the quarterly general, life and private health insurance performance statistics plus the National Claims and Policies Database. Its API posture is honestly none as of July 2026 — APRA operates no developer portal, publishes no OpenAPI or Swagger definition, and offers no self-serve API. Regulated entities lodge data through APRA Connect (connect.apra.gov.au), a browser-only portal gated behind the Australian Government Digital ID System (myID plus Relationship Authorisation Manager); APRA's own technical specification page lists the API Technical Specification as "to be provided when this functionality is available," so machine-to-machine submission remains a roadmap item and not a shipped surface. What APRA does publish machine-readably is a standards corpus rather than an API — per-industry APRA Connect taxonomy artefacts (XSD schemas, reporting taxonomy and validation rule workbooks) for General Insurance, Private Health Insurance and Life Insurance — while statistics ship as XLSX and Power BI, and the public insurer registers are HTML tables with no bulk export. No ACORD, AL3 or NGDS reference appears anywhere on apra.gov.au; APRA's reporting data model is its own XBRL/XSD taxonomy, not the insurance industry's ACORD standards.

APRA is profiled on the APIs.io network. Tagged areas include Insurance, Australia, Regulator, Prudential Regulation, and General Insurance.

APRA’s developer surface includes authentication, changelog, sandbox, documentation, getting-started guide, support, engineering blog, and 36 more developer resources.

35.0/100 thin ▬ flat Agent 16/100 agent aware Full breakdown ↓
scored 2026-07-27 · rubric v0.5
0 APIs
InsuranceAustraliaRegulatorPrudential RegulationGeneral InsuranceLife InsurancePrivate Health InsuranceRegulatory ReportingMarket InfrastructureRisk DataSuperannuationBanking

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 35.0/100 · thin
Contract Quality 0.0 / 25
Developer Ergonomics 10.4 / 20
Commercial Clarity 5.8 / 20
Operational Transparency 4.4 / 13
Governance 0.0 / 12
Discoverability 6.8 / 10
Agent readiness — 16/100 · agent aware
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 3 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/apra: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Apra Authentication

0 schemes

SECURITY

Apra Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Apra Vulnerability Disclosure

Bugcrowd · security.txt · contact published

SECURITY

Resources

Get Started 8

Portal, sign-up, and the first successful call

Scroll for all 8

Documentation 3

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Access & Security 6

Authentication, authorization, and security posture

Learn 1

Tutorials, courses, talks, and written guidance

Operate 5

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 4

The organization behind the API

Other 8

Properties that don't map to a standard resource type

Scroll for all 8

Source (apis.yml)

apis.yml Raw ↑
aid: apra
url: https://raw.githubusercontent.com/api-evangelist/apra/refs/heads/main/apis.yml
name: APRA
kind: company
description: The Australian Prudential Regulation Authority (APRA) is the Commonwealth statutory authority that prudentially
  supervises Australia's banks, credit unions, building societies, general insurers, life insurers, private health insurers,
  reinsurers and most of the superannuation industry, protecting depositors, policyholders and fund members under the Financial
  Sector (Collection of Data) Act 2001 and the Insurance Act 1973. Across insurance it authorises and registers general insurers,
  life insurers and friendly societies, and private health insurers; publishes prudential standards and practice guides; maintains
  public registers of authorised institutions; and runs the quarterly general, life and private health insurance performance
  statistics plus the National Claims and Policies Database. Its API posture is honestly none as of July 2026 — APRA operates
  no developer portal, publishes no OpenAPI or Swagger definition, and offers no self-serve API. Regulated entities lodge
  data through APRA Connect (connect.apra.gov.au), a browser-only portal gated behind the Australian Government Digital ID
  System (myID plus Relationship Authorisation Manager); APRA's own technical specification page lists the API Technical Specification
  as "to be provided when this functionality is available," so machine-to-machine submission remains a roadmap item and not
  a shipped surface. What APRA does publish machine-readably is a standards corpus rather than an API — per-industry APRA
  Connect taxonomy artefacts (XSD schemas, reporting taxonomy and validation rule workbooks) for General Insurance, Private
  Health Insurance and Life Insurance — while statistics ship as XLSX and Power BI, and the public insurer registers are HTML
  tables with no bulk export. No ACORD, AL3 or NGDS reference appears anywhere on apra.gov.au; APRA's reporting data model
  is its own XBRL/XSD taxonomy, not the insurance industry's ACORD standards.
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
tags:
- Insurance
- Australia
- Regulator
- Prudential Regulation
- General Insurance
- Life Insurance
- Private Health Insurance
- Regulatory Reporting
- Market Infrastructure
- Risk Data
- Superannuation
- Banking
created: '2026-07-25'
modified: '2026-07-25'
specificationVersion: '0.19'
apis: []
common:
- type: VulnerabilityDisclosure
  url: security/apra-vulnerability-disclosure.yml
- type: Security
  url: https://www.apra.gov.au/security
  note: Published vulnerability disclosure policy; reports go to the APRA Bugcrowd engagement. No monetary rewards and no
    testing authorisation.
- type: DomainSecurity
  url: security/apra-domain-security.yml
- type: SecurityTxt
  url: well-known/apra-security.txt
- type: WellKnown
  url: well-known/apra-well-known.yml
- type: Authentication
  url: authentication/apra-authentication.yml
  note: Documents the APRA Connect authentication model (myID + RAM). api_auth is none — APRA publishes no API auth scheme.
- type: Conformance
  url: conformance/apra-conformance.yml
- type: Compliance
  url: https://www.apra.gov.au/apra-portals/apra-connect/apra-connect-information-security-and-technical-specifications
  note: IRAP assessment against the Australian Government Information Security Manual, penetration testing, encryption in
    transit and at rest, Australian data residency. No commercial certifications (SOC 2 / ISO 27001) are claimed.
- type: ChangeLog
  url: changelog/apra-changelog.yml
- type: ChangeLog
  url: https://www.apra.gov.au/apra-portals/apra-connect/apra-connect-release-notes
  note: Dated APRA Connect release notes — the live source.
- type: Lifecycle
  url: lifecycle/apra-lifecycle.yml
- type: Deprecation
  url: https://www.apra.gov.au/news-and-publications/direct-apra-security-update-and-accelerated-decommission
  note: Decommission notice for the legacy Direct to APRA (D2A) submission client, taken offline 20 March 2026 with migration
    instructions to APRA Connect.
- type: DataModel
  url: data-model/apra-reporting-taxonomy.yml
  note: Verified inventory of the APRA Connect reporting taxonomy — 107 XSD schemas plus taxonomy and validation-rule workbooks
    across five industry packs.
- type: Sandbox
  url: sandbox/apra-sandbox.yml
- type: LLMsTxt
  url: llms/apra-llms.txt
- type: Documentation
  url: https://www.apra.gov.au/apra-portals/apra-connect/apra-connect-support-material
  note: APRA Connect Guide, FAR reporting form instruction guides, FAQs and webinar recordings.
- type: GettingStarted
  url: https://www.apra.gov.au/apra-portals/apra-connect/accessing-apra-connect
  note: Onboarding path — Digital ID (myID), RAM authorisation, RRA nomination, role assignment.
- type: Support
  url: https://www.apra.gov.au/contact-us
- type: Videos
  url: https://www.apra.gov.au/apra-portals/apra-connect/videos-apra-connect
- type: PrivacyPolicy
  url: https://www.apra.gov.au/privacy
- type: TermsOfService
  url: https://www.apra.gov.au/disclaimer
  note: Site disclaimer — the terms a user is deemed to accept by using apra.gov.au. APRA publishes no separate terms of service.
- type: License
  url: https://www.apra.gov.au/copyright
  note: Site material is licensed Creative Commons Attribution 4.0 International, excluding the Commonwealth Coat of Arms,
    APRA/APRA Connect logos and third-party material.
- type: Accessibility
  url: https://www.apra.gov.au/accessibility
- type: Website
  url: https://www.apra.gov.au/
- type: Blog
  url: https://www.apra.gov.au/news-and-publications
- type: BlogRSS
  url: https://www.apra.gov.au/rss.xml
- type: Portal
  url: https://www.apra.gov.au/apra-portals/apra-connect
  note: APRA Connect — regulatory data lodgement portal for supervised entities. Login-gated via the Australian Government
    Digital ID System (myID + RAM). Not a developer portal.
- type: Application
  url: https://connect.apra.gov.au
  note: APRA Connect production. Unauthenticated requests are rejected by the WAF.
- type: Sandbox
  url: https://connect-test.apra.gov.au
  note: APRA Connect test environment. RegTech access is granted only by signed deed after emailing dataanalytics@apra.gov.au
    — no API is offered, portal access only.
- type: TechnicalSpecification
  url: https://www.apra.gov.au/apra-portals/apra-connect/apra-connect-information-security-and-technical-specifications
  note: States "API Technical Specification — to be provided when this functionality is available" as of 2026-07-25.
- type: Schema
  url: https://www.apra.gov.au/apra-portals/apra-connect/apra-connect-taxonomy-artefacts
  note: Per-industry reporting taxonomy artefacts — XSD schemas, taxonomy workbooks and validation rules for General Insurance,
    Private Health Insurance, Life Insurance, ADI and Superannuation. The closest thing APRA publishes to a machine-readable
    contract.
- type: Standards
  url: https://www.apra.gov.au/prudential-standards-and-guidance
- type: Registry
  url: https://www.apra.gov.au/registers
  note: Public registers of APRA-authorised institutions. HTML tables only; no CSV, JSON or API export.
- type: Registry
  url: https://www.apra.gov.au/registers/list-general-insurance
- type: Registry
  url: https://www.apra.gov.au/registers/list-registered-life-insurers-and-friendly-societies
- type: Registry
  url: https://www.apra.gov.au/registers/list-registered-private-health-insurers
- type: Data
  url: https://www.apra.gov.au/statistics
  note: Statistical publications distributed as XLSX downloads plus embedded Power BI dashboards. No API, no bulk data endpoint.
- type: Data
  url: https://www.apra.gov.au/news-and-publications/quarterly-general-insurance-performance-statistics
- type: Data
  url: https://www.apra.gov.au/news-and-publications/quarterly-life-insurance-performance-statistics
- type: Data
  url: https://www.apra.gov.au/news-and-publications/quarterly-private-health-insurance-performance-statistics
- type: Data
  url: https://www.apra.gov.au/news-and-publications/national-claims-and-policies-database-statistics
- type: LinkedIn
  url: https://www.linkedin.com/company/apra
- type: Contact
  url: mailto:dataanalytics@apra.gov.au
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com