Steadfast Group

Steadfast Group Limited (ASX:SDF) is the largest general insurance broker network and the largest group of insurance underwriting agencies in Australasia, headquartered in Sydney, Australia. It is a broker-intermediary rather than a risk carrier: the Steadfast Network comprises 414 independent brokerages placing approximately $12.7 billion in gross written premium, alongside 31 underwriting agencies writing roughly 100 products across business pack, liability, professional indemnity, cyber, construction, marine, aviation, farm, strata, motor and home and contents lines, plus complementary businesses covering premium funding (IQumulate), life insurance, workplace risk, legal and compliance. Its trading technology is the Steadfast Client Trading Platform (SCTP), launched in 2009, which lets network brokers send one question set to a panel of insurers for instant comparative quotes and which transacted over $1.5 billion in GWP in CY25 across 9 insurer lines and 23 connected partners; SCTP and the INSIGHT policy management platform are being consolidated into a broader "Steadfast Apps" broking platform. API posture, recorded honestly - Steadfast Group publishes NO developer portal, NO API documentation and NO specification of any kind, and a full crawl of all 311 pages in the public sitemap returned zero references to a developer portal, REST API, OpenAPI or Swagger. Two genuinely machine-readable surfaces nonetheless exist and neither is announced anywhere. The consumer Flood Risk Tracker is backed by a public, anonymous, undocumented JSON API that resolves Australian addresses against the national G-NAF dataset and returns Swiss Re river-flood and storm-surge risk layers, returning RFC 9457 problem details and advertising api-supported-versions 1.0; the OpenAPI in this record was derived from the tool's own client JavaScript and from live probes. Separately, idp.steadfast.com.au is an Okta-hosted OpenID Connect provider publishing a complete anonymous discovery document with PKCE S256 and DPoP, though client registration is commercially gated. The commercial surfaces remain closed: broker.steadfast.com.au is a credentialed broker login wall, and api.steadfast.com.au and api-sf.steadfast.com.au are live but undocumented hosts returning HTTP 403 at the root. Insurer and partner connectivity into SCTP is arranged commercially, not through self-serve onboarding. The company's most notable standards signal is governance rather than implementation: founder, Managing Director and CEO Robert B. Kelly AM is Chair of the ACORD Board in New York, though no ACORD, AL3, ACORD XML or NGDS implementation detail is published anywhere on the public site. Australia has the legal machinery for open insurance but no live obligation - the Consumer Data Right was designated to extend to general insurance and then deferred, so no regulatory forcing function pushes a broker network of this scale toward a public API.

Steadfast Group publishes 1 API on the APIs.io network: Steadfast Flood Risk Tracker API. Tagged areas include Insurance, Australia, Broker, Insurance Broker Network, and General Insurance.

Steadfast Group’s developer surface includes engineering blog, legal docs, tooling, support, authentication, and 29 more developer resources.

39.1/100 thin ▬ flat Agent 58/100 agent ready Full breakdown ↓
scored 2026-07-27 · rubric v0.5
2 APIs 1 MCP Servers
InsuranceAustraliaBrokerInsurance Broker NetworkGeneral InsuranceProperty and CasualtyUnderwriting AgencyAgency ManagementACORDPartner GatedNew Zealand

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 39.1/100 · thin
Contract Quality 14.4 / 25
Developer Ergonomics 4.8 / 20
Commercial Clarity 4.2 / 20
Operational Transparency 0.0 / 13
Governance 0.0 / 12
Discoverability 9.3 / 10
Agent readiness — 58/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 5 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/steadfast-group: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 2

Individual APIs this provider publishes, each with its own machine-readable definition.

Steadfast Flood Risk Tracker API

The public, anonymous, read-only JSON API behind Steadfast Group's consumer Flood Risk Tracker tool. Two GET operations resolve a free-text Australian street address against the...

Steadfast Identity (OpenID Connect)

Steadfast Group's Okta-hosted OpenID Connect provider, issuer https://idp.steadfast.com.au. It fronts the credentialed broker portal used by the Steadfast Network's 414 brokerag...

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Steadfast Group Authentication

none/openIdConnect/oauth2 · 2 schemes

SECURITY

Steadfast Group Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Steadfast Group Scopes

7 scopes · authorizationCode/implicit/deviceCode/password

7 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Steadfast Group Agentic Access

2 operations

2 operations · 0 acting

AGENTIC

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 10

The organization behind the API

Scroll for all 10

Other 3

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: steadfast-group
url: https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/apis.yml
name: Steadfast Group
kind: company
description: 'Steadfast Group Limited (ASX:SDF) is the largest general insurance broker network and the largest group of insurance
  underwriting agencies in Australasia, headquartered in Sydney, Australia. It is a broker-intermediary rather than a risk
  carrier: the Steadfast Network comprises 414 independent brokerages placing approximately $12.7 billion in gross written
  premium, alongside 31 underwriting agencies writing roughly 100 products across business pack, liability, professional indemnity,
  cyber, construction, marine, aviation, farm, strata, motor and home and contents lines, plus complementary businesses covering
  premium funding (IQumulate), life insurance, workplace risk, legal and compliance. Its trading technology is the Steadfast
  Client Trading Platform (SCTP), launched in 2009, which lets network brokers send one question set to a panel of insurers
  for instant comparative quotes and which transacted over $1.5 billion in GWP in CY25 across 9 insurer lines and 23 connected
  partners; SCTP and the INSIGHT policy management platform are being consolidated into a broader "Steadfast Apps" broking
  platform. API posture, recorded honestly - Steadfast Group publishes NO developer portal, NO API documentation and NO specification
  of any kind, and a full crawl of all 311 pages in the public sitemap returned zero references to a developer portal, REST
  API, OpenAPI or Swagger. Two genuinely machine-readable surfaces nonetheless exist and neither is announced anywhere. The
  consumer Flood Risk Tracker is backed by a public, anonymous, undocumented JSON API that resolves Australian addresses against
  the national G-NAF dataset and returns Swiss Re river-flood and storm-surge risk layers, returning RFC 9457 problem details
  and advertising api-supported-versions 1.0; the OpenAPI in this record was derived from the tool''s own client JavaScript
  and from live probes. Separately, idp.steadfast.com.au is an Okta-hosted OpenID Connect provider publishing a complete anonymous
  discovery document with PKCE S256 and DPoP, though client registration is commercially gated. The commercial surfaces remain
  closed: broker.steadfast.com.au is a credentialed broker login wall, and api.steadfast.com.au and api-sf.steadfast.com.au
  are live but undocumented hosts returning HTTP 403 at the root. Insurer and partner connectivity into SCTP is arranged commercially,
  not through self-serve onboarding. The company''s most notable standards signal is governance rather than implementation:
  founder, Managing Director and CEO Robert B. Kelly AM is Chair of the ACORD Board in New York, though no ACORD, AL3, ACORD
  XML or NGDS implementation detail is published anywhere on the public site. Australia has the legal machinery for open insurance
  but no live obligation - the Consumer Data Right was designated to extend to general insurance and then deferred, so no
  regulatory forcing function pushes a broker network of this scale toward a public API.'
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
tags:
- Insurance
- Australia
- Broker
- Insurance Broker Network
- General Insurance
- Property and Casualty
- Underwriting Agency
- Agency Management
- ACORD
- Partner Gated
- New Zealand
created: '2026-07-25'
modified: '2026-07-25'
specificationVersion: '0.19'
apis:
- aid: steadfast-group:flood-risk-tracker
  name: Steadfast Flood Risk Tracker API
  description: The public, anonymous, read-only JSON API behind Steadfast Group's consumer Flood Risk Tracker tool. Two GET
    operations resolve a free-text Australian street address against the national G-NAF address dataset and then return Swiss
    Re natural-catastrophe risk layers for that address - river/fluvial flood and coastal storm surge - each with a hazard
    value, intensity, risk index and risk band. This is the only publicly reachable API surface in the entire Steadfast estate.
    Steadfast publishes no specification, no documentation and no support commitment for it; the OpenAPI in this repository
    was derived by API Evangelist from the tool's own client JavaScript and from live anonymous probes, and every field, status
    code and example in it was observed in a real response.
  humanURL: https://floodrisktracker.steadfast.com.au/
  baseURL: https://floodrisktracker.steadfast.com.au
  tags:
  - Flood Risk
  - Natural Catastrophe
  - Address
  - Geospatial
  - Insurance
  - Australia
  properties:
  - type: OpenAPI
    url: openapi/steadfast-group-flood-risk-tracker-openapi.yml
    name: Flood Risk Tracker OpenAPI 3.1 (derived from observed traffic)
  - type: Overlay
    url: overlays/steadfast-group-flood-risk-tracker-overlay.yaml
  - type: Examples
    url: examples/steadfast-group-flood-risk-tracker-examples.yml
    name: Verbatim live request and response pairs
  - type: ErrorCatalog
    url: errors/steadfast-group-problem-types.yml
  - type: DataModel
    url: data-model/steadfast-group-data-model.yml
  - type: Conventions
    url: conventions/steadfast-group-conventions.yml
  - type: MCPServer
    url: mcp/steadfast-group-mcp.yml
    name: Candidate MCP tools derived from the OpenAPI (no Steadfast MCP server exists)
  - type: ToolCrosswalk
    url: mcp/steadfast-group-tool-crosswalk.yml
  - type: AgentSkill
    url: skills/steadfast-group-flood-risk-lookup.md
  - type: Authentication
    url: authentication/steadfast-group-authentication.yml
    name: No authentication required or accepted
- aid: steadfast-group:identity
  name: Steadfast Identity (OpenID Connect)
  description: Steadfast Group's Okta-hosted OpenID Connect provider, issuer https://idp.steadfast.com.au. It fronts the credentialed
    broker portal used by the Steadfast Network's 414 brokerages and, by inference from the shared estate, internal and partner
    applications. The discovery document is anonymously readable and advertises authorization, token, userinfo, JWKS, introspection,
    revocation, device-authorization, dynamic-client-registration and logout endpoints, with PKCE S256 and DPoP proof-of-possession
    supported. Client credentials are not self-serve - anonymous dynamic client registration returns 403 - so this is a discoverable
    but commercially gated surface, listed because its contract is genuinely machine-readable.
  humanURL: https://broker.steadfast.com.au/
  baseURL: https://idp.steadfast.com.au
  tags:
  - Identity
  - OpenID Connect
  - OAuth 2.0
  - Single Sign-On
  - Partner Gated
  properties:
  - type: OpenIDConnect
    url: well-known/steadfast-group-openid-configuration.json
    name: OpenID Connect discovery document (harvested verbatim)
  - type: WellKnown
    url: well-known/steadfast-group-well-known.yml
  - type: OAuthScopes
    url: scopes/steadfast-group-scopes.yml
  - type: Authentication
    url: authentication/steadfast-group-authentication.yml
common:
- type: AgenticAccess
  url: agentic-access/steadfast-group-agentic-access.yml
- type: DomainSecurity
  url: security/steadfast-group-domain-security.yml
- type: Website
  url: https://www.steadfast.com.au/
- type: About
  url: https://www.steadfast.com.au/about-us/
- type: BoardAndManagement
  url: https://www.steadfast.com.au/about-us/board-and-management/
- type: InvestorRelations
  url: https://investor.steadfast.com.au/investor-centre/
- type: LinkedIn
  url: https://www.linkedin.com/company/steadfast-group-limited/
- type: Blog
  url: https://www.steadfast.com.au/well-covered/
- type: Contact
  url: https://www.steadfast.com.au/contact-us/
- type: PrivacyPolicy
  url: https://www.steadfast.com.au/privacy-policy/
- type: Legal
  url: https://www.steadfast.com.au/legal/
- type: CodeOfPractice
  url: https://www.steadfast.com.au/codes-of-practice/
- type: PartnerPortal
  url: https://broker.steadfast.com.au/
  name: Steadfast Broker Login - credentialed broker portal (login wall, not a developer portal)
- type: Website
  url: https://steadfastagencies.com.au/
  name: Steadfast Underwriting Agencies
- type: Website
  url: https://www.steadfastlife.com.au/
  name: Steadfast Life
- type: Website
  url: https://www.steadfastnz.nz/
  name: Steadfast New Zealand
- type: Website
  url: https://www.steadfast.com.sg/
  name: Steadfast Singapore
- type: Tool
  url: https://floodrisktracker.steadfast.com.au/
  name: Steadfast Flood Risk Tracker - public web tool; its undocumented JSON API is captured in openapi/
- type: Support
  url: https://www.steadfast.com.au/contact-us/
  name: Contact Steadfast - the only support channel; there is no developer support surface
- type: TermsOfService
  url: https://www.steadfast.com.au/legal/
  name: Website legal terms and disclaimer (Steadfast Group Limited ABN 98 073 659 677)
- type: Careers
  url: https://www.steadfast.com.au/about-us/careers/
- type: FindABroker
  url: https://www.steadfast.com.au/find-an-insurance-broker
  name: Find an insurance broker in the Steadfast Network
- type: WellKnown
  url: well-known/steadfast-group-well-known.yml
  name: Every /.well-known/ probe across the Steadfast estate, with HTTP status
- type: OpenIDConnect
  url: well-known/steadfast-group-openid-configuration.json
  name: OpenID Connect discovery document for idp.steadfast.com.au (harvested verbatim)
- type: Authentication
  url: authentication/steadfast-group-authentication.yml
- type: OAuthScopes
  url: scopes/steadfast-group-scopes.yml
- type: Conventions
  url: conventions/steadfast-group-conventions.yml
- type: Conformance
  url: conformance/steadfast-group-conformance.yml
- type: Lifecycle
  url: lifecycle/steadfast-group-lifecycle.yml
- type: ErrorCatalog
  url: errors/steadfast-group-problem-types.yml
- type: DataModel
  url: data-model/steadfast-group-data-model.yml
- type: Packages
  url: packages/steadfast-group-packages.yml
  name: No first-party client libraries exist - registries searched, homonym traps recorded
- type: LLMsTxt
  url: llms/steadfast-group-llms.txt
- type: AgentSkill
  url: skills/_index.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com