First American Financial · Authentication Profile

First American Financial Authentication

Authentication

First American Financial secures its APIs with apiKey, http, and oauth2 across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).

Title InsuranceReal EstateSettlement ServicesFinancial ServicesMortgageProperty DataIdentity VerificationRegulatory ComplianceFortune 1000
Methods: apiKey, http, oauth2 Schemes: 4 OAuth flows: clientCredentials API key in: header

Security Schemes

x-app-id apiKey
· in: header (x-app-id)
x-app-key apiKey
· in: header (x-app-key)
bearerAuth http
scheme: bearer
oauth2-client-credentials oauth2

Source

Authentication Profile

Raw ↑
generated: '2026-09-09'
method: searched
source: openapi/ — 16 harvested Digital Gateway specifications
docs: https://developer.firstam.io/api/docs
note: >-
  Upgraded from the mechanical derive. The derive found only the one declared securityScheme
  (Title & Settlement's bearer JWT) because the fifteen Swagger 2.0 data-service specs carry no
  `securityDefinitions` block at all — they express credentials as REQUIRED HEADER PARAMETERS on
  every operation instead. That is a real, documented API-key scheme (140 header-parameter
  declarations across 70 operations) and it would have scored as "no authentication" had it been
  left to the spec's own security block.
summary:
  types: [apiKey, http, oauth2]
  api_key_in: [header]
  oauth2_flows: [clientCredentials]
schemes:
  - name: x-app-id
    type: apiKey
    in: header
    parameter: x-app-id
    aliases: [X-App-Id]
    description: >-
      Application ID. Issued per App in the Digital Gateway portal after an access request is
      approved. Sent on EVERY Digital Gateway data-service call.
    declared_as: required header parameter (not a securityDefinition)
    operations: 70
    sources:
      - openapi/first-american-financial-4506c-openapi.yml
      - openapi/first-american-financial-bankruptcy-openapi.yml
      - openapi/first-american-financial-clearsearch-openapi.yml
      - openapi/first-american-financial-identity-openapi.yml
      - openapi/first-american-financial-income-estimate-openapi.yml
      - openapi/first-american-financial-liens-judgments-fcra-openapi.yml
      - openapi/first-american-financial-liens-judgments-non-fcra-openapi.yml
      - openapi/first-american-financial-nmls-openapi.yml
      - openapi/first-american-financial-occupancy-openapi.yml
      - openapi/first-american-financial-ownership-openapi.yml
      - openapi/first-american-financial-property-openapi.yml
      - openapi/first-american-financial-reverse-address-openapi.yml
      - openapi/first-american-financial-reverse-phone-openapi.yml
      - openapi/first-american-financial-scra-openapi.yml
      - openapi/first-american-financial-watchlist-openapi.yml
  - name: x-app-key
    type: apiKey
    in: header
    parameter: x-app-key
    aliases: [X-App-Key]
    description: >-
      Application Key, the secret half of the App credential pair. Paired with x-app-id on every
      data-service call. An invalid pair returns HTTP 401 "Invalid App ID or App Key".
    declared_as: required header parameter (not a securityDefinition)
    operations: 70
    sources: [see x-app-id]
  - name: bearerAuth
    type: http
    scheme: bearer
    bearerFormat: JWT
    description: >-
      OAuth (a.k.a JWT) Authentication is mandatory. Applied to all 16 non-token operations of the
      Title & Settlement (Mortgage Services) API.
    sources:
      - openapi/first-american-financial-title-settlement-openapi.yml
  - name: oauth2-client-credentials
    type: oauth2
    flow: clientCredentials
    token_endpoint: POST /api/token
    token_endpoint_note: >-
      The demonstration host in the spec is https://lvis-oauth-swagger.lvisqa.firstam.com and is
      explicitly marked "THIS ENDPOINT IS FOR DEMONSTRATION PURPOSES ONLY". The real authentication
      URL is issued privately - the spec says to contact LVIS.support@firstam.com to obtain the URL
      along with client_id, client_secret, scope and grant_type.
    request_fields: [client_id, client_secret, scope, grant_type]
    scopes_published: false
    scopes_note: >-
      `scope` is a REQUIRED form field on the token request but no scope values are published
      anywhere. No scopes/ artifact is written rather than invent one.
    sources:
      - openapi/first-american-financial-title-settlement-openapi.yml
onboarding:
  self_service: false
  steps:
    - Sign up at https://developer.firstam.io/signup (two-factor by email).
    - Account reviewed by a Digital Gateway administrator; access granted within 1-2 business days.
    - Create an App, then request access to specific APIs; approval may be automatic or administrator-gated.
    - App ID and App Key appear in the App's Credentials section once approved.
    - Production access additionally requires the First American relationship team and may require a contract and/or SOW.
  contact: DigitalGateway@firstam.io
additional:
  shared_secret:
    documented: true
    description: >-
      The glossary documents a Shared Secret Key used for message-level symmetric cryptography on
      some APIs, assigned in the portal. Not expressed in any harvested contract.
    source: https://developer.firstam.io/api/docs
  app_source_header:
    documented: true
    description: >-
      'AppSource' is required for customers using source-level credentials on the Title & Settlement
      document, message and cancel operations.
    source: openapi/first-american-financial-title-settlement-openapi.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/first-american-financial-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.