Suncorp Group · Authentication Profile
Suncorp Group Authentication
Authentication
Suncorp Group declares 0 security scheme(s) across its OpenAPI definitions.
InsuranceAustraliaProperty and CasualtyGeneral InsuranceCarrierPersonal LinesCommercial LinesClaimsUnderwritingBrokersPartner GatedNew Zealand
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-07-25'
method: searched
source: >-
https://www.vero.com.au/terms-sid.html, https://www.vero.com.au/broker/tools.html,
https://www.vero.com.au/secure/veroedge.html and live 2026-07-25 probes of
online.verocentral.com.au. No OpenAPI exists to derive from —
derive-authentication.py has no spec input for this provider.
public_api: false
summary:
types: []
api_key_in: []
oauth2_flows: []
machine_to_machine_auth_documented: false
reading: >-
There is no public API and therefore no public API authentication scheme. No
API keys, no client-credentials flow, no mTLS onboarding and no scope model
are documented anywhere on Suncorp Group or brand properties. The only access
model Suncorp publishes is a human, browser-based federated single sign-on to
gated broker portals, granted person-by-person by a Vero representative.
schemes: []
gated_access_model:
- name: Access Single ID (SID)
kind: browser-federated-sso
audience: brokers and intermediaries
entry_point: https://www.vero.com.au/secure/veroedge.html
identity_provider: https://online.verocentral.com.au/idp/channel/vero-portal
identity_provider_status: 200
presentation: HTML login form titled "Vero Intermediary Portal"
terms: https://www.vero.com.au/terms-sid.html
provisioning: >-
Granted by a dedicated Vero Representative per the Vero broker tools page —
a human onboarding path, not self-serve registration.
discovery_documents:
openid_configuration: 404
oauth_authorization_server: 404
capabilities_behind_the_wall:
- SME Package and Commercial Motor quoting with real-time response
- New business bind and full policy lifecycle transactions
- Renewals including Workers Compensation
- Electronic document access (schedules, new business, renewals)
- name: Engineers PI & Strata Portal (Uniwriter)
kind: third-party-underwriting-application
audience: brokers
entry_point: https://EngineersPIandStrataPortal.vero.com.au/
entry_point_status: 200
presentation: Angular single-page application
discovery_documents:
openid_configuration: >-
200 but serves the SPA HTML shell, not a discovery document — does not parse
as JSON
machine_channels:
note: >-
The primary machine-to-machine path is a Broker Management System connection
over Australia's commercial broker trading networks (Steadfast SCTP, Sunrise
Exchange). Credentials and message formats for those channels are commercial
and are not published by Suncorp — see
conformance/suncorp-group-conformance.yml.
publicly_documented: false
pointer_note: >-
Deliberately NOT wired as `type: Authentication` in apis.yml. That scoring check
reads "API authentication is documented," and Suncorp Group documents no API
authentication — only a human portal login. Wiring the pointer would award
points for something that does not exist.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/suncorp-group-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.