Cytora is a London-headquartered insurtech, founded in 2012 as a University of Cambridge spinout, that sells a digital risk processing platform to commercial insurers, wholesale brokers, MGAs and reinsurers. Its software ingests inbound submissions arriving as email, PDF, spreadsheet and broker API payloads, digitises them against pre-built line-of-business schemas (property, commercial combined, construction, cyber, fleet, general liability, professional liability, D&O, E&O, management liability), augments them from a data ecosystem of roughly sixty third-party risk-data partners, evaluates them against appetite and priority rules, and routes them into downstream underwriting and claims systems. Use cases span new business, renewals, mid-term adjustments, claims FNOL and post-FNOL intake, and facultative and treaty reinsurance submissions. Named customers include Zurich, Chubb, Markel, Beazley, Travelers, Tokio Marine, Ecclesiastical, Arch, Everest and TransRe. Applied Systems acquired Cytora in September 2025. Its API posture is partner-gated and enterprise-only: Cytora runs a real production API gateway at api.cytora.com and a real ReadMe-hosted API reference at docs.cytora.com, but the documentation site is entirely password-protected (HTTP 302 to a password wall, robots.txt Disallow) and the gateway resets anonymous TLS connections. There is no self-serve developer signup, no public OpenAPI, no public Postman collection and no published webhook or event catalog. The only externally verifiable technical surface is the Auth0 OIDC discovery document at auth.cytora.com, which confirms OAuth 2.0 client-credentials and authorization-code flows for provisioned partner integrations. The United Kingdom home market has no open-insurance mandate, so nothing compels Cytora to expose any of this publicly.
Cytora publishes 2 APIs on the APIs.io network. Tagged areas include Insurance, United Kingdom, Insurtech, Commercial Insurance, and Underwriting.
Cytora’s developer surface includes documentation, engineering blog, authentication, support, and 21 more developer resources.
Regulatory Posture applies to this provider. Its tags matched the
Insurance regime, so
Regulatory Posture carries 15 points of the composite.
If this regime is wrong for your business, say so on your
provider repo — the
applicability map is public and we will correct it.
Create-or-Update Ergonomics could not be measured. We hold no machine-readable contract for
this provider to read, so there is nothing to measure a write surface against. Excluded rather than scored zero:
never-measured and measured-empty are different facts. Publishing an OpenAPI is what makes this facet — and
several others — scorable at all.
The six quality facets above are damped to 85 points between them,
because the conditional facet above carries the other
15. That is why each facet's contribution is shown against a damped
maximum: raising a quality facet moves the composite by 85% of its nominal
weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/cytora: open an issue to ask a question, or submit a pull request to add artifacts.
Submit an artifact on GitHub — free →Manage your own listing — the Influence plan, $499/mo →
Cytora's production REST API for digital risk processing — the "preferred method" of submission intake described in its own Risk Flow Academy. The gateway is real (api.cytora.co...
The OAuth 2.0 / OpenID Connect authorization server that fronts every Cytora integration, running on an Auth0 EU tenant (cytora-prod.eu.auth0.com). This is the only Cytora surfa...
aid: cytora
url: https://raw.githubusercontent.com/api-evangelist/cytora/refs/heads/main/apis.yml
name: Cytora
kind: company
description: 'Cytora is a London-headquartered insurtech, founded in 2012 as a University of Cambridge spinout, that sells
a digital risk processing platform to commercial insurers, wholesale brokers, MGAs and reinsurers. Its software ingests
inbound submissions arriving as email, PDF, spreadsheet and broker API payloads, digitises them against pre-built line-of-business
schemas (property, commercial combined, construction, cyber, fleet, general liability, professional liability, D&O, E&O,
management liability), augments them from a data ecosystem of roughly sixty third-party risk-data partners, evaluates them
against appetite and priority rules, and routes them into downstream underwriting and claims systems. Use cases span new
business, renewals, mid-term adjustments, claims FNOL and post-FNOL intake, and facultative and treaty reinsurance submissions.
Named customers include Zurich, Chubb, Markel, Beazley, Travelers, Tokio Marine, Ecclesiastical, Arch, Everest and TransRe.
Applied Systems acquired Cytora in September 2025. Its API posture is partner-gated and enterprise-only: Cytora runs a real
production API gateway at api.cytora.com and a real ReadMe-hosted API reference at docs.cytora.com, but the documentation
site is entirely password-protected (HTTP 302 to a password wall, robots.txt Disallow) and the gateway resets anonymous
TLS connections. There is no self-serve developer signup, no public OpenAPI, no public Postman collection and no published
webhook or event catalog. The only externally verifiable technical surface is the Auth0 OIDC discovery document at auth.cytora.com,
which confirms OAuth 2.0 client-credentials and authorization-code flows for provisioned partner integrations. The United
Kingdom home market has no open-insurance mandate, so nothing compels Cytora to expose any of this publicly.'
deliveryModel:
model: saas
open_source: false
commercial: true
callable_host: false
label: Hosted service · you call their endpoint
confidence: medium
source:
- pricing
generated: '2026-08-28'
method: derived
accessModel:
pricing: unknown
onboarding: self-serve
trial: false
try_now: false
public: false
label: Self-serve signup
confidence: medium
source:
- authentication
- scopes
- security
generated: '2026-09-02'
method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
tags:
- Insurance
- United Kingdom
- Insurtech
- Commercial Insurance
- Underwriting
- Claims
- Risk Data
- Property and Casualty
- Reinsurance
- Brokers
- Submission Intake
- Document AI
tags_raw:
- Insurance
- United Kingdom
- Insurtech
- Commercial Insurance
- Underwriting
- Claims
- Risk Data
- Property and Casualty
- Reinsurance
- Broker
- Submission Intake
- Document AI
created: '2026-07-25'
modified: '2026-07-25'
specificationVersion: '0.23'
apis:
- name: Cytora Platform API
description: 'Cytora''s production REST API for digital risk processing — the "preferred method" of submission intake described
in its own Risk Flow Academy. The gateway is real (api.cytora.com resolves via gateway.cytora-prod.com to a Google Cloud
load balancer) and the API reference is real (a ReadMe site at docs.cytora.com), but both are closed: the documentation
host 302-redirects every path to a password wall and the gateway resets the TLS handshake for anonymous clients. No OpenAPI,
SDK, Postman collection or webhook catalog is published. Access is provisioned per contract via OAuth 2.0 client credentials
issued by Cytora''s Auth0 tenant. The resource surface observed in Cytora''s own published Risk Console client (workspaces,
inboxes, records, documents, extractors, transactions, deployments) is captured in conventions/cytora-conventions.yml
for discovery only.'
humanURL: https://docs.cytora.com/
baseURL: https://api.cytora.com
tags:
- Insurance
- Underwriting
- Claims
- Submission Intake
- Document AI
properties:
- type: Documentation
url: https://docs.cytora.com/
- type: Authentication
url: authentication/cytora-authentication.yml
- type: Conventions
url: conventions/cytora-conventions.yml
- type: Lifecycle
url: lifecycle/cytora-lifecycle.yml
- name: Cytora Identity (Auth0 OIDC)
description: 'The OAuth 2.0 / OpenID Connect authorization server that fronts every Cytora integration, running on an Auth0
EU tenant (cytora-prod.eu.auth0.com). This is the only Cytora surface that answers anonymously with real machine-readable
data: OpenID Connect Discovery, RFC 8414 authorization server metadata and JWKS all return 200. It advertises client_credentials
for machine-to-machine partner integrations, authorization_code with PKCE (S256) for the Risk Console, token exchange,
JWT bearer and device code grants, private_key_jwt client authentication and DPoP (ES256). Only stock OIDC identity scopes
are advertised; product scopes are not published.'
humanURL: https://auth.cytora.com/.well-known/openid-configuration
baseURL: https://auth.cytora.com
tags:
- Authentication
- OpenID Connect
- Identity
tags_raw:
- OAuth
- OpenID Connect
- Identity
properties:
- type: Authentication
url: authentication/cytora-authentication.yml
- type: OAuthScopes
url: scopes/cytora-scopes.yml
- type: WellKnown
url: well-known/cytora-well-known.yml
- type: OpenIDConnect
url: https://auth.cytora.com/.well-known/openid-configuration
common:
- type: DomainSecurity
url: security/cytora-domain-security.yml
- type: Website
url: https://cytora.com/
- type: Documentation
url: https://docs.cytora.com/
- type: Blog
url: https://cytora.com/risk-flow-center/blog
- type: StatusPage
url: https://status.cytora.com/
- type: Lifecycle
url: lifecycle/cytora-lifecycle.yml
- type: TrustCenter
url: https://trust.cytora.com/
- type: TrustCenter
url: security/cytora-trust-center.yml
- type: Compliance
url: https://trust.cytora.com/
- type: Conformance
url: conformance/cytora-conformance.yml
- type: Authentication
url: https://auth.cytora.com/.well-known/openid-configuration
- type: Authentication
url: authentication/cytora-authentication.yml
- type: OAuthScopes
url: scopes/cytora-scopes.yml
- type: WellKnown
url: well-known/cytora-well-known.yml
- type: Conventions
url: conventions/cytora-conventions.yml
- type: LLMsTxt
url: llms/cytora-llms.txt
- type: Login
url: https://uwp.cytora.com
- type: GitHubOrganization
url: https://github.com/cytora
- type: LinkedIn
url: https://www.linkedin.com/company/cytora
- type: Twitter
url: https://twitter.com/cytora
- type: PrivacyPolicy
url: https://cytora.com/privacy-policy
- type: CookiePolicy
url: https://cytora.com/cookie-policy
- type: Support
url: https://cytora.com/about-us/contact-us
- type: Customers
url: https://cytora.com/customers
- type: Partners
url: https://cytora.com/digital-risk-processing/data-ecosystem
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.