generated: '2026-07-25' method: searched source: >- Live probes of Bupa's market-unit developer surfaces (portal.api.bupa.com.au, apidoc.bupa.cl) plus the Entra ID OIDC discovery document captured in well-known/bupa-cl-entra-openid-configuration.json docs: null derived_from_openapi: false note: >- Bupa publishes no OpenAPI or Swagger definition anywhere on its public web estate, so this profile cannot be derived from securitySchemes. It is assembled instead from the platforms Bupa's two live market-unit developer surfaces actually run on and from the one identity document that is anonymously readable. Bupa does not publish an authentication reference page for API consumers; access to the real scheme documentation is released only after contacting the Bupa Integration Fabric Team. Everything below is evidenced; nothing is inferred beyond what the evidence field states. public_documentation: published: false reason: >- Neither market unit publishes an authentication guide. The Bupa Australia portal's entire public onboarding text is three steps that all route through a human team, and the Bupa Chile portal renders nothing before sign-in. summary: types: [oauth2, openIdConnect, apiKey] api_key_in: [header] oauth2_flows: [authorizationCode] identity_providers: [Microsoft Entra ID] confirmed: 2 inferred: 1 schemes: - name: Microsoft Entra ID (OpenID Connect / OAuth 2.0 authorization code) type: openIdConnect status: confirmed applies_to: Bupa Chile API portal (apidoc.bupa.cl) openid_configuration: well-known/bupa-cl-entra-openid-configuration.json discovery_url: https://login.microsoftonline.com/6faad805-0755-4412-981c-e2d4e4021ee7/v2.0/.well-known/openid-configuration discovery_http_status: 200 issuer: https://login.microsoftonline.com/6faad805-0755-4412-981c-e2d4e4021ee7/v2.0 authorization_endpoint: https://login.microsoftonline.com/6faad805-0755-4412-981c-e2d4e4021ee7/oauth2/v2.0/authorize token_endpoint: https://login.microsoftonline.com/6faad805-0755-4412-981c-e2d4e4021ee7/oauth2/v2.0/token end_session_endpoint: https://login.microsoftonline.com/6faad805-0755-4412-981c-e2d4e4021ee7/oauth2/v2.0/logout userinfo_endpoint: https://graph.microsoft.com/oidc/userinfo jwks_uri: https://login.microsoftonline.com/6faad805-0755-4412-981c-e2d4e4021ee7/discovery/v2.0/keys tenant: 6faad805-0755-4412-981c-e2d4e4021ee7 tenant_region_scope: SA client_id: 744efffa-f93d-4137-b874-cef142712fa6 redirect_uri: https://apidoc.bupa.cl/public/login response_types_supported: [code, id_token, code id_token, id_token token] scopes_supported: [openid, profile, email, offline_access] subject_types_supported: [pairwise] id_token_signing_alg_values_supported: [RS256] token_endpoint_auth_methods_supported: - client_secret_post - private_key_jwt - client_secret_basic - self_signed_tls_client_auth evidence: >- The MSAL configuration is declared in the portal's shipped Angular bundles (main-D6DO74WN.js and chunks), which also declare baseUrl https://api.bupa.cl/portal/ms-controller. The tenant's v2.0 OIDC discovery document returns HTTP 200 and was saved verbatim. scope: >- This authenticates access to the Chile developer portal itself. It is not published as the security scheme of any individual Bupa API — no such scheme document is public. - name: Bupa Chile portal backend session type: http scheme: bearer status: confirmed applies_to: https://api.bupa.cl/portal/ms-controller evidence: >- The portal bundle stores an Entra id_token in localStorage under "user" and calls the controller with it; every anonymous request to https://api.bupa.cl/, /portal/ms-controller, /portal/ms-controller/apis, /openapi.json and /swagger.json returns HTTP 401. - name: Azure API Management subscription key type: apiKey in: header parameter_name: Ocp-Apim-Subscription-Key status: inferred applies_to: Bupa Australia APIs (api.bupa.com.au) evidence: >- portal.api.bupa.com.au is an Azure API Management managed developer portal (config.json declares APIM service banzprodapim01, managementApiVersion 2022-04-01-preview) and its public copy reads "Start with simple registration and get the keys to manage, build and test." Subscription-key header auth is the Azure APIM default. caveat: >- INFERRED FROM THE PLATFORM, NOT FROM A PUBLISHED REFERENCE. Bupa documents no header name, no key issuance flow and no token endpoint publicly. The parameter name above is the Azure APIM default and has not been confirmed against a Bupa document. Do not treat it as an authoritative Bupa claim. related: well_known: well-known/bupa-well-known.yml conformance: conformance/bupa-conformance.yml domain_security: security/bupa-domain-security.yml