# Canada Life > The Canada Life Assurance Company is one of Canada's largest life and health insurers, > formed from the 2020 amalgamation of Great-West Life, London Life and Canada Life under > Winnipeg-based parent Great-West Lifeco. It has **no public, self-serve developer portal > and no downloadable API specifications**. Its integration surface is entirely > partner-gated: a live OAuth2-protected gateway at api.canadalife.com that returns 403 on > every business path, advisor and customer login walls, and — the real machine-to-machine > channel in this market — ACORD XML for Life exchanged with distributors through Canada > Life's carrier membership in CLIEDIS. Generated by the API Evangelist enrichment pipeline on 2026-07-25. Canada Life publishes no llms.txt of its own (https://www.canadalife.com/llms.txt returns 404), so this file is generated from the artifacts in this repository. Every status code below was observed live. ## What an agent can and cannot do here - There is **no OpenAPI, Swagger, AsyncAPI, GraphQL SDL or .proto** published anywhere on a Canada Life host. Do not look for one; every spec path on the gateway returns 403. - There is **no self-serve signup**. Gateway credentials are issued through a partner, distributor or MGA relationship. There is no application form on any public page. - The **only** anonymously readable machine-readable documents are two OpenID Connect discovery documents and one JWKS. They describe the auth model and nothing else. - Quote, bind, issue and claims all run through advisor tooling or the CLIEDIS ACORD feeds. None of them is exposed as a callable public API. ## Identity and auth (the only live machine-readable surface) - [Gateway OIDC discovery](https://api.canadalife.com/.well-known/openid-configuration): 200. Issuer https://api.canadalife.com. Token endpoint /oauth2/v1/generate. Authorization endpoint published as "authorize-NOT-SUPPORTED" — interactive flow is off by design. scopes_supported is an empty array. - [Gateway JWKS](https://api.canadalife.com/oauth2/v1/jwks): 200. One RSA key, kid api-gateway-1, RS256. - [Customer portal OIDC discovery](https://my.canadalife.com/.well-known/openid-configuration): 200. Salesforce Experience Cloud defaults on a Canada Life host — 36 platform scopes, 24 claims, dynamic client registration. These are Salesforce platform scopes, not Canada Life business scopes. ## Repository artifacts - [Authentication profile](authentication/canada-life-authentication.yml): both OIDC surfaces, flows, endpoints, signing algorithms. - [OAuth scopes](scopes/canada-life-scopes.yml): the 36 published scopes plus the caveat that they are platform, not business, scopes. - [Well-known index](well-known/canada-life-well-known.yml): every /.well-known/ path probed on every host, with status codes. - [Conformance](conformance/canada-life-conformance.yml): what this provider does and does not conform to, including ACORD XML for Life via CLIEDIS. - [Lifecycle](lifecycle/canada-life-lifecycle.yml): the retired Apigee developer portal, and the absence of versioning, deprecation, SLA and status-page policy. - [Domain security](security/canada-life-domain-security.yml): TLS, HSTS, DNSSEC, CAA, SPF, DMARC probes. - [Vulnerability disclosure](security/canada-life-vulnerability-disclosure.yml): no researcher VDP or bug bounty; the real fraud/security reporting channel; the 2026 breach notices. - [Packages](packages/canada-life-packages.yml): every registry searched, zero first-party SDKs. - [Review](review.yml): the full probe log behind all of the above. ## Human surfaces - [Canada Life](https://www.canadalife.com/): corporate site. Life, health and dental, disability, critical illness, group retirement, savings and investments. - [Sign in](https://www.canadalife.com/sign-in.html): entry point for customer, employer and advisor logins. - [Advisor logins](https://www.canadalife.com/sign-in/advisor-logins.html): the human entry point to the partner surface. - [Advisor portal](https://advisor.canadalife.com/login): Liferay "Digital Agent" login wall. Not a developer portal. - [Customer portal](https://my.canadalife.com/): Salesforce-hosted retail portal. Login wall. - [Support](https://www.canadalife.com/support.html) - [Contact us](https://www.canadalife.com/contact-us.html) - [Blog](https://www.canadalife.com/blog.html) - [Newsroom](https://www.canadalife.com/about-us/news-highlights/news.html) - [Internet security](https://www.canadalife.com/internet-security.html): published security practices and the reporting channel. - [Privacy](https://www.canadalife.com/privacy.html) - [Terms of use](https://www.canadalife.com/terms-of-use.html) ## Standards channel - [CLIEDIS](https://www.cliedis.ca/): Canadian Life Insurance EDI Standards. Distributes ACORD XML for Life through the CAIR tool; defines the e-application, pending-policy and Book of Business feeds. - [CLIEDIS members](https://www.cliedis.ca/who-we-are/members): confirms Canada Life as a Carrier member. This is the ACORD evidence — canadalife.com itself has zero ACORD references across 1,236 sitemap URLs.