Ki Insurance · Authentication Profile

Ki Insurance Authentication

Authentication

Ki Insurance secures its APIs with http, openIdConnect, and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

InsuranceUnited KingdomLloyd's of LondonSpecialty InsuranceProperty and CasualtyUnderwritingInsurtechBrokerAlgorithmic UnderwritingReinsurance
Methods: http, openIdConnect, oauth2 Schemes: 3 OAuth flows: authorizationCode API key in:

Security Schemes

auth0Bearer http
scheme: bearer
auth0OpenId openIdConnect
auth0OAuth2 oauth2
· flows: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-07-25'
method: searched
source: https://login.ki-insurance.com/.well-known/openid-configuration
docs: https://login.ki-insurance.com/.well-known/openid-configuration
derived_from:
- openapi/ki-insurance-broker-platform-openapi.yml
- https://app.ki-insurance.com/config.js
summary:
  types:
  - http
  - openIdConnect
  - oauth2
  api_key_in: []
  oauth2_flows:
  - authorizationCode
  model: >-
    Partner-gated OAuth 2.0 / OpenID Connect. Ki fronts an Auth0 EU tenant at
    login.ki-insurance.com. The broker single-page app performs an
    authorization-code + PKCE login and then attaches the resulting Auth0 access
    token as `Authorization: Bearer <JWT>` to every call against the same-origin
    /api surface on app.ki-insurance.com. There is no API key, no mTLS scheme and
    no self-serve credential issuance published anywhere on Ki's public surface.
schemes:
- name: auth0Bearer
  type: http
  scheme: bearer
  bearerFormat: JWT
  description: >-
    Auth0-issued access token. Observed in the platform client's request helper,
    which sets `Authorization: Bearer <token>`, `Accept: application/json` and
    `Content-Type: application/json` on every request and uses
    `credentials: same-origin`.
  sources:
  - openapi/ki-insurance-broker-platform-openapi.yml
  - https://app.ki-insurance.com/assets/index-DgeF7w2c.js
- name: auth0OpenId
  type: openIdConnect
  openIdConnectUrl: https://login.ki-insurance.com/.well-known/openid-configuration
  description: Auth0 OIDC discovery for the partner login.
  sources:
  - openapi/ki-insurance-broker-platform-openapi.yml
- name: auth0OAuth2
  type: oauth2
  description: >-
    The underlying Auth0 authorization server. Flow values below are read verbatim
    from the anonymous discovery document; Ki publishes no business scopes.
  flows:
  - flow: authorizationCode
    authorizationUrl: https://login.ki-insurance.com/authorize
    tokenUrl: https://login.ki-insurance.com/oauth/token
    refreshUrl: https://login.ki-insurance.com/oauth/token
  sources:
  - https://login.ki-insurance.com/.well-known/openid-configuration
issuer:
  issuer: https://login.ki-insurance.com/
  audience: https://api.ki.com
  audience_note: >-
    The audience string is published in the platform runtime config at
    https://app.ki-insurance.com/config.js. It is an identifier, not a reachable
    host — api.ki.com resolves to a parked "Site Not Configured" page.
  tenant: Auth0 (EU region, ki-prod)
  endpoints:
    authorization: https://login.ki-insurance.com/authorize
    token: https://login.ki-insurance.com/oauth/token
    userinfo: https://login.ki-insurance.com/userinfo
    jwks: https://login.ki-insurance.com/.well-known/jwks.json
    revocation: https://login.ki-insurance.com/oauth/revoke
    device_authorization: https://login.ki-insurance.com/oauth/device/code
    dynamic_client_registration: https://login.ki-insurance.com/oidc/register
    mfa_challenge: https://login.ki-insurance.com/mfa/challenge
    global_token_revocation: https://login.ki-insurance.com/oauth/global-token-revocation/connection/{connectionName}
  grant_types_supported:
  - authorization_code
  - client_credentials
  - refresh_token
  - implicit
  - password
  - urn:ietf:params:oauth:grant-type:device_code
  - urn:ietf:params:oauth:grant-type:token-exchange
  - urn:ietf:params:oauth:grant-type:jwt-bearer
  code_challenge_methods_supported:
  - S256
  - plain
  token_endpoint_auth_methods_supported:
  - client_secret_basic
  - client_secret_post
  - private_key_jwt
  - none
  id_token_signing_alg_values_supported:
  - HS256
  - RS256
  - PS256
  response_modes_supported:
  - query
  - fragment
  - form_post
  backchannel_logout_supported: true
  mfa: >-
    The tenant advertises MFA grant types (mfa-oob, mfa-otp, mfa-recovery-code)
    and an /mfa/challenge endpoint; Ki does not document whether partner brokers
    are enrolled.
login_flow:
  entry: https://auth.ki-insurance.com/login?return_to=<url>
  note: >-
    Ki runs its own thin login/logout shim at auth.ki-insurance.com in front of
    Auth0. GET /login without return_to responds `Missing 'return_to' query
    parameter.` (HTTP 400); GET /logout (HTTP 302) redirects to
    https://login.ki-insurance.com/v2/logout. The shim is not an OIDC issuer —
    its /.well-known/openid-configuration is 404.
  callback: https://app.ki-insurance.com/auth/callback
gaps:
- No published scope model for the Ki API itself (see scopes/ki-insurance-scopes.yml).
- No API-key, mTLS, signed-request or partner-SAML scheme is documented publicly.
- No self-serve credential issuance; access is granted per partner broking house.