First American Financial · Authentication Profile
First American Financial Authentication
Authentication
First American Financial secures its APIs with apiKey, http, and oauth2 across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).
Title InsuranceReal EstateSettlement ServicesFinancial ServicesMortgageProperty DataIdentity VerificationRegulatory ComplianceFortune 1000
Methods: apiKey, http, oauth2
Schemes: 4
OAuth flows: clientCredentials
API key in: header
Security Schemes
x-app-id apiKey
· in: header (x-app-id)
x-app-key apiKey
· in: header (x-app-key)
bearerAuth http
scheme: bearer
oauth2-client-credentials oauth2
Source
Authentication Profile
generated: '2026-09-09'
method: searched
source: openapi/ — 16 harvested Digital Gateway specifications
docs: https://developer.firstam.io/api/docs
note: >-
Upgraded from the mechanical derive. The derive found only the one declared securityScheme
(Title & Settlement's bearer JWT) because the fifteen Swagger 2.0 data-service specs carry no
`securityDefinitions` block at all — they express credentials as REQUIRED HEADER PARAMETERS on
every operation instead. That is a real, documented API-key scheme (140 header-parameter
declarations across 70 operations) and it would have scored as "no authentication" had it been
left to the spec's own security block.
summary:
types: [apiKey, http, oauth2]
api_key_in: [header]
oauth2_flows: [clientCredentials]
schemes:
- name: x-app-id
type: apiKey
in: header
parameter: x-app-id
aliases: [X-App-Id]
description: >-
Application ID. Issued per App in the Digital Gateway portal after an access request is
approved. Sent on EVERY Digital Gateway data-service call.
declared_as: required header parameter (not a securityDefinition)
operations: 70
sources:
- openapi/first-american-financial-4506c-openapi.yml
- openapi/first-american-financial-bankruptcy-openapi.yml
- openapi/first-american-financial-clearsearch-openapi.yml
- openapi/first-american-financial-identity-openapi.yml
- openapi/first-american-financial-income-estimate-openapi.yml
- openapi/first-american-financial-liens-judgments-fcra-openapi.yml
- openapi/first-american-financial-liens-judgments-non-fcra-openapi.yml
- openapi/first-american-financial-nmls-openapi.yml
- openapi/first-american-financial-occupancy-openapi.yml
- openapi/first-american-financial-ownership-openapi.yml
- openapi/first-american-financial-property-openapi.yml
- openapi/first-american-financial-reverse-address-openapi.yml
- openapi/first-american-financial-reverse-phone-openapi.yml
- openapi/first-american-financial-scra-openapi.yml
- openapi/first-american-financial-watchlist-openapi.yml
- name: x-app-key
type: apiKey
in: header
parameter: x-app-key
aliases: [X-App-Key]
description: >-
Application Key, the secret half of the App credential pair. Paired with x-app-id on every
data-service call. An invalid pair returns HTTP 401 "Invalid App ID or App Key".
declared_as: required header parameter (not a securityDefinition)
operations: 70
sources: [see x-app-id]
- name: bearerAuth
type: http
scheme: bearer
bearerFormat: JWT
description: >-
OAuth (a.k.a JWT) Authentication is mandatory. Applied to all 16 non-token operations of the
Title & Settlement (Mortgage Services) API.
sources:
- openapi/first-american-financial-title-settlement-openapi.yml
- name: oauth2-client-credentials
type: oauth2
flow: clientCredentials
token_endpoint: POST /api/token
token_endpoint_note: >-
The demonstration host in the spec is https://lvis-oauth-swagger.lvisqa.firstam.com and is
explicitly marked "THIS ENDPOINT IS FOR DEMONSTRATION PURPOSES ONLY". The real authentication
URL is issued privately - the spec says to contact LVIS.support@firstam.com to obtain the URL
along with client_id, client_secret, scope and grant_type.
request_fields: [client_id, client_secret, scope, grant_type]
scopes_published: false
scopes_note: >-
`scope` is a REQUIRED form field on the token request but no scope values are published
anywhere. No scopes/ artifact is written rather than invent one.
sources:
- openapi/first-american-financial-title-settlement-openapi.yml
onboarding:
self_service: false
steps:
- Sign up at https://developer.firstam.io/signup (two-factor by email).
- Account reviewed by a Digital Gateway administrator; access granted within 1-2 business days.
- Create an App, then request access to specific APIs; approval may be automatic or administrator-gated.
- App ID and App Key appear in the App's Credentials section once approved.
- Production access additionally requires the First American relationship team and may require a contract and/or SOW.
contact: DigitalGateway@firstam.io
additional:
shared_secret:
documented: true
description: >-
The glossary documents a Shared Secret Key used for message-level symmetric cryptography on
some APIs, assigned in the portal. Not expressed in any harvested contract.
source: https://developer.firstam.io/api/docs
app_source_header:
documented: true
description: >-
'AppSource' is required for customers using source-level credentials on the Title & Settlement
document, message and cancel operations.
source: openapi/first-american-financial-title-settlement-openapi.yml
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/first-american-financial-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.