# Aviva plc > Aviva plc is the United Kingdom's largest insurer and one of the ten biggest insurance groups in Europe, a composite carrier covering UK and Ireland general insurance, the UK's largest life book, health, workplace pensions and wealth, plus Aviva Investors and Aviva Canada. Its API programme is real but partner-gated: a Kong Konnect developer portal at developer.aviva.co.uk fronts a family of Aviva Health (Private Medical Insurance) APIs, with sandbox access granted on application and production consumption granted on approval through the Aviva API Gateway. There is no self-serve signup, no public API reference, no downloadable OpenAPI, no public Postman workspace, no GraphQL surface and no published event catalogue. Generated by the API Evangelist enrichment pipeline on 2026-07-25 from https://github.com/api-evangelist/aviva-plc — Aviva does not publish an llms.txt of its own (developer.aviva.co.uk/llms.txt returns 403; www.aviva.com/llms.txt and www.aviva.co.uk/llms.txt return 404). ## What an agent can and cannot do here - Every human content path on developer.aviva.co.uk returns HTTP 403 unauthenticated, including a deliberately bogus path — the 403 is blanket, so path existence cannot be inferred from it. - The portal's own metadata endpoint (GET /api/v2/portal) returns HTTP 200 and reports is_public false, rbac_enabled true, oidc_auth_enabled true, basic_auth_enabled false, saml_auth_enabled false, dcr_provider_ids []. - Both public sitemaps (/__sitemap__/pages.xml and /__sitemap__/apis.xml) are empty urlsets: Aviva publishes zero pages and zero APIs to public indexing. - api.aviva.co.uk and api.aviva.ie resolve behind Akamai and return a blanket "Access Denied" 403 on every path. - No OpenAPI, Swagger, AsyncAPI, GraphQL SDL or .proto artifact is retrievable anywhere. - There is no first-party SDK on npm, PyPI, NuGet or any other registry, and no Aviva GitHub organisation. ## APIs (partner-gated) - [Aviva Private Medical Insurance Consumer Pricing API](https://developer.aviva.co.uk/api-details/details-pricing): Calculates premiums for Aviva consumer Private Medical Insurance policies and returns product-related detail — the quote/rating verb of the Aviva Health API family. HTTP 403 unauthenticated. - [Aviva Private Medical Insurance Consumer Purchase API](https://developer.aviva.co.uk/api-details/details-purchase): Submits applications for PMI policy enrolment into Aviva systems, automating the journey from quote to buy — the bind/issue verbs. HTTP 403 unauthenticated. - Aviva also describes SME (Small Medium Enterprise) PMI pricing APIs that calculate premiums and fetch the No Claim Discount (NCD) level, but no stable public URL was confirmed for them, so they are not catalogued as separate entries. ## Developer surface - [Developer portal](https://developer.aviva.co.uk/): Kong Konnect portal under an Extended Validation certificate issued to "Aviva PLC". Partner login wall, not a self-serve portal. - [Service catalogue / documentation](https://developer.aviva.co.uk/documentation) - [Developer guide](https://developer.aviva.co.uk/developer-guide) - [Get started](https://developer.aviva.co.uk/get-started) - [Guides](https://developer.aviva.co.uk/guides) - [About the portal](https://developer.aviva.co.uk/about) - [Contact / request access](https://developer.aviva.co.uk/contact) — enquiries and consumption requests go to aservices@aviva.com ## Access model Three steps, all gated: Discover (browse the catalogue and documentation), Access (test in the sandbox with mock data once authenticated), Consume (make a formal request to consume through the Aviva API Gateway). Portal login is OAuth 2.0 authorization_code with PKCE (S256), OIDC-backed and RBAC-enforced. For API consumption, an authenticated partner creates an OAuth 2.0 client (Name, Client_id, Client_secret) in the portal and passes the generated token as `Authorization: Bearer `. No scopes, token endpoint or base URL for the business APIs is published. ## The larger integration channel is not the portal - [Polaris UK imarket](https://www.polaris.co.uk/products/imarket/): Aviva is a named participating insurer on Polaris's commercial-lines platform, trading over Polaris code lists and PL EDI messages into broker systems Acturis, Applied Systems, Bravo Digital Trader, Open GI and SSP. The UK carrier-to-broker standards seam is Polaris, not ACORD — no ACORD/AL3/NGDS reference exists on any Aviva surface. - [Aviva + Acturis claims API](https://www.acturis.com/blog/2024/12/13/aviva-and-acturis-launch-ground-breaking-broker-api-to-simplify-claims-process/) (December 2024): a one-way push of new and updated motor, property and liability claim records from Aviva into a broker's Acturis system. It does not accept a loss notification in, and it is delivered through the software house rather than through the developer portal. ## Artifacts in this repo - [apis.yml](https://raw.githubusercontent.com/api-evangelist/aviva-plc/refs/heads/main/apis.yml): APIs.json 0.19 index for the provider. - [review.yml](https://raw.githubusercontent.com/api-evangelist/aviva-plc/refs/heads/main/review.yml): full probe log and the standards-posture review. - [authentication/aviva-plc-authentication.yml](https://raw.githubusercontent.com/api-evangelist/aviva-plc/refs/heads/main/authentication/aviva-plc-authentication.yml): both auth surfaces (portal login vs API consumption). - [well-known/aviva-plc-well-known.yml](https://raw.githubusercontent.com/api-evangelist/aviva-plc/refs/heads/main/well-known/aviva-plc-well-known.yml): discovery-path index, with the SPA-shell false positives marked. - [well-known/aviva-plc-oauth-authorization-server.json](https://raw.githubusercontent.com/api-evangelist/aviva-plc/refs/heads/main/well-known/aviva-plc-oauth-authorization-server.json): the one real RFC 8414 document Aviva publishes. - [conventions/aviva-plc-conventions.yml](https://raw.githubusercontent.com/api-evangelist/aviva-plc/refs/heads/main/conventions/aviva-plc-conventions.yml): cross-cutting semantics, with honest absences. - [conformance/aviva-plc-conformance.yml](https://raw.githubusercontent.com/api-evangelist/aviva-plc/refs/heads/main/conformance/aviva-plc-conformance.yml): standards posture including the ACORD/Polaris finding. - [lifecycle/aviva-plc-lifecycle.yml](https://raw.githubusercontent.com/api-evangelist/aviva-plc/refs/heads/main/lifecycle/aviva-plc-lifecycle.yml): versioning, deprecation, SLA, status-page probes and programme milestones. - [sandbox/aviva-plc-sandbox.yml](https://raw.githubusercontent.com/api-evangelist/aviva-plc/refs/heads/main/sandbox/aviva-plc-sandbox.yml): the gated sandbox and mock-testing journey. - [rate-limits/aviva-plc-rate-limits.yml](https://raw.githubusercontent.com/api-evangelist/aviva-plc/refs/heads/main/rate-limits/aviva-plc-rate-limits.yml): rate-limit headers observed on the portal API. - [security/aviva-plc-domain-security.yml](https://raw.githubusercontent.com/api-evangelist/aviva-plc/refs/heads/main/security/aviva-plc-domain-security.yml): TLS, HSTS, DNSSEC, SPF and DMARC probe results. ## Company - [Aviva plc corporate site](https://www.aviva.com/) - [Aviva UK customer site](https://www.aviva.co.uk/) - [Aviva broker hub](https://connect.avivab2b.co.uk/) - [Newsroom](https://www.aviva.com/newsroom/) - [Investors](https://www.aviva.com/investors/) - [Legal / terms of use](https://www.aviva.com/legal/) - [Privacy policy](https://www.aviva.com/privacy-policy/)