# American International Group (AIG) > AIG is one of the world's largest international insurance organizations, operating in more than > 200 countries and jurisdictions, providing property casualty, cyber, professional liability, > management liability, marine, aviation, energy, trade credit and private client insurance. > AIG runs a live production API gateway but publishes NO public API contract, reference, SDK or > self-service signup. This file is generated by API Evangelist from independently probed public > surfaces; it is not published by AIG. ## API surface — read this first AIG has an API, and you cannot call it. - A production API gateway is live at `https://commercial.api.aig.com`. Every anonymous request is rejected by an Okta-backed "Protect Proxy" service policy. The host root returns HTTP 403 with the plain-text body `You are not authorized, Forbidden, Contact AIG HD`; a real route (`/pmp-gateway/c2a/pmp-ext-gtw-api`) returns HTTP 400 with `{"error":"Protect Proxy via okta Service Policy: The message does not contain the Authorization header"}`. - There is **no OpenAPI, Swagger, GraphQL SDL, AsyncAPI, WSDL or Protobuf** on any AIG host. - There is **no public API reference**. AIG's former developer portal, `developers.aig.com`, is still indexed by search engines (Direct Quote API, Product Configuration API, API Catalog pages) but the host refuses TCP connections. `developer.aig.com` is an empty Amazon S3 bucket. - There is **no self-service signup, no API key page, no sandbox, no SDK and no CLI.** Credentials are provisioned to appointed brokers, producers and clients through AIG's portals under distribution agreements. ## What IS machine-readable AIG's Okta identity host serves standard discovery metadata anonymously: - OpenID Connect discovery: https://auth1.customerpltfm.aig.com/.well-known/openid-configuration - OAuth 2.0 authorization-server metadata (RFC 8414): https://auth1.customerpltfm.aig.com/.well-known/oauth-authorization-server - The customer-platform authorization server that fronts the commercial gateway: https://auth1.customerpltfm.aig.com/oauth2/aus1aaqj1zvwVDL2n5d7/.well-known/oauth-authorization-server — authorization_code, client_credentials and refresh_token grants; PKCE S256; DPoP supported; 13 scopes, of which exactly one (`emeasme`) is an AIG business scope rather than a stock OIDC/Okta scope. ## Human entry points - Website: https://www.aig.com - Business insurance: https://www.aig.com/business - Individual insurance: https://www.aig.com/individual - myAIG broker portal: https://www.myaig.com - Producer Management Portal: https://www.producermanagementportal.aig.com - IntelliRisk claims platform: https://www.aig.com/home/claims/intellirisk - Contact: https://www.aig.com/home/contact - Newsroom: https://www.aig.com/home/newsroom/stories ## Security - Vulnerability Disclosure Program: https://www.aig.com/home/about/cyber-and-information-security/vulnerability-disclosure - Reports are submitted through HackerOne: https://hackerone.com/aig - No RFC 9116 `security.txt` — `www.aig.com` denies the entire `/.well-known/` path prefix with HTTP 403. ## Legal - Privacy policy: https://www.aig.com/privacy-policy - Terms of use: https://www.aig.com/terms-of-use ## Notes for agents - Do not attempt to call `commercial.api.aig.com` without provisioned credentials; it is a production gateway for AIG's broker and producer applications. - No rate limits are documented and no `RateLimit-*` or `Retry-After` headers are emitted, so there is no runtime pacing signal. - No status page exists; `status.aig.com` does not resolve. - This profile is an independent third-party assessment by API Evangelist and is not endorsed by AIG. Corrections: info@apievangelist.com