Guidewire · Authentication Profile

Guidewire Authentication

Authentication

Guidewire secures its APIs with http-basic and bearer-jwt across 2 declared security schemes, as derived from its OpenAPI definitions.

InsurancePolicyClaimsBillingP&C
Methods: http-basic, bearer-jwt Schemes: 2 OAuth flows: API key in:

Security Schemes

BearerJWT http
scheme: bearer
HTTPBasic http
scheme: basic

Source

Authentication Profile

Raw ↑
generated: '2026-09-12'
method: searched
source: >-
  Guidewire InsuranceSuite Cloud API Configuration & Authentication Guide, read from
  docs.guidewire.com (public, no credentials).
docs: https://docs.guidewire.com/cloud/is/202607/cloudapica/cloudAPI/AuthChoose/p_choosing-an-authentication-flow.html
provider: guidewire
providerId: guidewire
api: InsuranceSuite Cloud API
supersedes: >-
  A derived profile written from openapi/*.yml on 2026-09-12 that reported an OAuth 2.0
  authorizationCode flow at https://login.guidewire.com/oauth/authorize and /oauth/token. That host
  does NOT RESOLVE (NXDOMAIN, checked 2026-09-12) and appears nowhere in Guidewire's documentation.
  The value came from the documentation-shaped scaffold specs in openapi/, not from Guidewire. This
  file replaces it with what Guidewire actually publishes.
summary:
  types: [http-basic, bearer-jwt]
  oauth2_authorization_server: null
  scope_catalog: false
  authorization_model: named API roles (role.yaml), resource access, proxy-user access
schemes:
  - name: BearerJWT
    type: http
    scheme: bearer
    bearer_format: JWT
    applies_to: [internal user, external user, anonymous user, standalone service, service-for-user, service-for-service]
    description: >-
      The caller presents a JSON Web Token. The JWT carries BOTH authentication and authorization
      information as token claims. This is the only method supported in production.
    token_issuer: >-
      The customer's identity provider, configured per Guidewire Cloud deployment. Guidewire does not
      operate a public authorization server for Cloud API and publishes no authorization_endpoint,
      token_endpoint, JWKS URI or grant-type list.
    docs: https://docs.guidewire.com/cloud/is/202607/cloudapica/cloudAPI/AuthChoose/overview-authentication/c_authentication-methods.html
    construct_jwt_docs: https://docs.guidewire.com/cloud/is/202607/cloudapica/cloudAPI/AuthChoose/overview-authentication/c_constructing_jwts.html
  - name: HTTPBasic
    type: http
    scheme: basic
    applies_to: [internal user]
    description: >-
      User name and password in the request header; authentication and authorization are read from the
      operational database.
    production_supported: false
    constraint: >-
      "Basic authentication is not supported in production environments. It can only be used in
      development environments." Quoted verbatim.
    docs: https://docs.guidewire.com/cloud/is/202607/cloudapica/cloudAPI/AuthFlows/basic-auth/c_basic-authentication.html
caller_types:
  types:
  - internal user
  - external user
  - anonymous user
  - standalone service
  - service with user context (GW-User-Context header)
  - service with service-account mapping
  docs_note: Each caller type has its own documented authentication flow.
  docs: https://docs.guidewire.com/cloud/is/202607/cloudapica/cloudAPI/AuthChoose/overview-authentication/c_types-of-callers.html
authorization:
  model: API roles
  description: >-
    Access is granted through named API roles defined in role.yaml files and assigned to callers. A
    role names the endpoints it opens, the operations allowed on them, and the fields readable or
    writable. Three orthogonal access types apply: endpoint access (all callers), resource access
    (users only, in the base configuration) and proxy-user access (external users and services only).
  reserved_roles: true
  docs: https://docs.guidewire.com/cloud/is/202607/cloudapica/cloudAPI/AuthImplement/endpoint-access/c_API-role-files.html
  access_types_docs: https://docs.guidewire.com/cloud/is/202607/cloudapica/cloudAPI/AuthChoose/overview-authentication/c_types_of_access.html
failure_handling:
  docs: https://docs.guidewire.com/cloud/is/202607/cloudapica/cloudAPI/AuthChoose/overview-authentication/c_authentication-failure-error-messages.html
unauthenticated_surface:
  endpoints:
  - path: <applicationURL>/rest/<APIpath>/openapi.json
    note: >-
      "In the base configuration, the API definition endpoints are available to any caller, including
      unauthenticated" callers. Deployments may restrict this.
    docs: https://docs.guidewire.com/cloud/cc/202511/cloudapibf/cloudAPI/topics/101-Fund/01-overview-of-Cloud-API/c_viewing-API-definitions.html

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/guidewire-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.