# AccessFintech > AccessFintech operates Synergy, a post-trade data and workflow network for capital markets. > It connects buy-side firms, broker-dealers, custodians, hedge funds, order management systems > and vendors onto a shared view of trade, settlement and collateral data, normalizes fragmented > data across securities, derivatives and alternatives, detects breaks across counterparties, and > lets the parties to a trade resolve exceptions on one record rather than by email and > reconciliation files. ## Status of this file This llms.txt was generated by API Evangelist from public probes, not published by AccessFintech. AccessFintech serves no /llms.txt (404 at https://www.accessfintech.com/llms.txt on 2026-08-06). ## What an agent can and cannot do here AccessFintech has **no public developer program**. There is no developer portal, no API reference, no OpenAPI or AsyncAPI specification, no SDK, no sandbox, and no self-serve sign-up. The Synergy API exists and is real, but it is reachable only by onboarded network members with credentials issued through a commercial onboarding engagement. An agent cannot integrate with AccessFintech from public information alone; the correct next step is https://www.accessfintech.com/request-a-meeting/. ## API surface (gated) - [Synergy Platform API](https://www.accessfintech.com/platform/): GraphQL at https://api.accessfintech.com/gql (the shipped client mirrors the operation name into the query string as `?operation=`), plus a REST surface on the same origin. Authenticated session required. Anonymous introspection is refused at the CDN edge (403). - Multi-party context: requests carry `x-context-org-id` to select the acting organization, `x-csrf-token` for anti-CSRF, and `x-correlation-id` for tracing. ## Identity - [OpenID Connect discovery](https://login.accessfintech.com/.well-known/openid-configuration): issuer `https://login.accessfintech.com` (Okta-hosted). Authorization code with PKCE (S256), refresh tokens, device code, DPoP, Pushed Authorization Requests, dynamic client registration, token introspection and revocation. - [OAuth 2.0 Authorization Server Metadata (RFC 8414)](https://login.accessfintech.com/.well-known/oauth-authorization-server) - Enterprise SSO/SAML is offered to customers. - [Sign in](https://login.accessfintech.com/) ## Artifacts in this profile - Authentication profile: authentication/accessfintech-authentication.yml - OAuth/OIDC scopes as advertised by the issuer: scopes/accessfintech-scopes.yml - Well-known discovery index: well-known/accessfintech-well-known.yml - Standards conformance: conformance/accessfintech-conformance.yml - API conventions observed in the shipped client: conventions/accessfintech-conventions.yml - Packages: packages/accessfintech-packages.yml - Domain security posture: security/accessfintech-domain-security.yml ## Company - [Home](https://www.accessfintech.com/) - [Platform](https://www.accessfintech.com/platform/) - [Solutions](https://www.accessfintech.com/solutions/) — broker-dealer, custodians, asset managers, hedge funds; securities, derivatives, alternatives - [About](https://www.accessfintech.com/about/) - [Blog](https://www.accessfintech.com/blog/) - [Contact](https://www.accessfintech.com/contact/) - [Request a meeting](https://www.accessfintech.com/request-a-meeting/) - [Privacy policy](https://www.accessfintech.com/privacy-policy/) - [GitHub](https://github.com/accessfintech) ## Not published No OpenAPI. No AsyncAPI or webhook catalog. No MCP server. No A2A agent card (/.well-known/agent-card.json and /.well-known/agent.json miss on every host). No security.txt. No trust center or named certifications. No status page. No changelog. No CLI. No sandbox. No API client SDK in any public registry.