Ki Insurance · Authentication Profile

Ki Insurance Authentication

Authentication

Ki Insurance secures its APIs with http, openIdConnect, and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

InsuranceUnited KingdomLloyd's of LondonSpecialty InsuranceProperty and CasualtyUnderwritingInsurtechBrokersAlgorithmic UnderwritingReinsurance
Methods: http, openIdConnect, oauth2 Schemes: 3 OAuth flows: authorizationCode API key in:

Security Schemes

auth0Bearer http
scheme: bearer
auth0OpenId openIdConnect
auth0OAuth2 oauth2
· flows: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-07-25'
method: searched
source: https://login.ki-insurance.com/.well-known/openid-configuration
docs: https://login.ki-insurance.com/.well-known/openid-configuration
derived_from:
- openapi/ki-insurance-broker-platform-openapi.yml
- https://app.ki-insurance.com/config.js
summary:
  types:
  - http
  - openIdConnect
  - oauth2
  api_key_in: []
  oauth2_flows:
  - authorizationCode
  model: >-
    Partner-gated OAuth 2.0 / OpenID Connect. Ki fronts an Auth0 EU tenant at
    login.ki-insurance.com. The broker single-page app performs an
    authorization-code + PKCE login and then attaches the resulting Auth0 access
    token as `Authorization: Bearer <JWT>` to every call against the same-origin
    /api surface on app.ki-insurance.com. There is no API key, no mTLS scheme and
    no self-serve credential issuance published anywhere on Ki's public surface.
schemes:
- name: auth0Bearer
  type: http
  scheme: bearer
  bearerFormat: JWT
  description: >-
    Auth0-issued access token. Observed in the platform client's request helper,
    which sets `Authorization: Bearer <token>`, `Accept: application/json` and
    `Content-Type: application/json` on every request and uses
    `credentials: same-origin`.
  sources:
  - openapi/ki-insurance-broker-platform-openapi.yml
  - https://app.ki-insurance.com/assets/index-DgeF7w2c.js
- name: auth0OpenId
  type: openIdConnect
  openIdConnectUrl: https://login.ki-insurance.com/.well-known/openid-configuration
  description: Auth0 OIDC discovery for the partner login.
  sources:
  - openapi/ki-insurance-broker-platform-openapi.yml
- name: auth0OAuth2
  type: oauth2
  description: >-
    The underlying Auth0 authorization server. Flow values below are read verbatim
    from the anonymous discovery document; Ki publishes no business scopes.
  flows:
  - flow: authorizationCode
    authorizationUrl: https://login.ki-insurance.com/authorize
    tokenUrl: https://login.ki-insurance.com/oauth/token
    refreshUrl: https://login.ki-insurance.com/oauth/token
  sources:
  - https://login.ki-insurance.com/.well-known/openid-configuration
issuer:
  issuer: https://login.ki-insurance.com/
  audience: https://api.ki.com
  audience_note: >-
    The audience string is published in the platform runtime config at
    https://app.ki-insurance.com/config.js. It is an identifier, not a reachable
    host — api.ki.com resolves to a parked "Site Not Configured" page.
  tenant: Auth0 (EU region, ki-prod)
  endpoints:
    authorization: https://login.ki-insurance.com/authorize
    token: https://login.ki-insurance.com/oauth/token
    userinfo: https://login.ki-insurance.com/userinfo
    jwks: https://login.ki-insurance.com/.well-known/jwks.json
    revocation: https://login.ki-insurance.com/oauth/revoke
    device_authorization: https://login.ki-insurance.com/oauth/device/code
    dynamic_client_registration: https://login.ki-insurance.com/oidc/register
    mfa_challenge: https://login.ki-insurance.com/mfa/challenge
    global_token_revocation: https://login.ki-insurance.com/oauth/global-token-revocation/connection/{connectionName}
  grant_types_supported:
  - authorization_code
  - client_credentials
  - refresh_token
  - implicit
  - password
  - urn:ietf:params:oauth:grant-type:device_code
  - urn:ietf:params:oauth:grant-type:token-exchange
  - urn:ietf:params:oauth:grant-type:jwt-bearer
  code_challenge_methods_supported:
  - S256
  - plain
  token_endpoint_auth_methods_supported:
  - client_secret_basic
  - client_secret_post
  - private_key_jwt
  - none
  id_token_signing_alg_values_supported:
  - HS256
  - RS256
  - PS256
  response_modes_supported:
  - query
  - fragment
  - form_post
  backchannel_logout_supported: true
  mfa: >-
    The tenant advertises MFA grant types (mfa-oob, mfa-otp, mfa-recovery-code)
    and an /mfa/challenge endpoint; Ki does not document whether partner brokers
    are enrolled.
login_flow:
  entry: https://auth.ki-insurance.com/login?return_to=<url>
  note: >-
    Ki runs its own thin login/logout shim at auth.ki-insurance.com in front of
    Auth0. GET /login without return_to responds `Missing 'return_to' query
    parameter.` (HTTP 400); GET /logout (HTTP 302) redirects to
    https://login.ki-insurance.com/v2/logout. The shim is not an OIDC issuer —
    its /.well-known/openid-configuration is 404.
  callback: https://app.ki-insurance.com/auth/callback
gaps:
- No published scope model for the Ki API itself (see scopes/ki-insurance-scopes.yml).
- No API-key, mTLS, signed-request or partner-SAML scheme is documented publicly.
- No self-serve credential issuance; access is granted per partner broking house.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ki-insurance-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.