aid: cbre-australia name: CBRE Australia review: question: >- Does CBRE Australia expose a public, documented, machine-readable API surface — and separately, does it carry any RESO posture? answer: false date: '2026-07-26' reviewer: API Evangelist homeMarket: Australia tier: commercial-cre primaryDomain: cbre.com.au legalEntity: CBRE (Gwsla) Pty Ltd AU09949 (per cbre.com.au footer, fetched 2026-07-26) sectorBlock: resoPosture: summary: No RESO reference found — RESO is absent from CBRE Australia entirely. certified: false certificationType: none dataDictionaryVersion: null webApiCertification: none upiUsage: none observed directoryEvidence: >- https://www.reso.org/certificates/ (RESO Certification Status, the public certified-organizations listing) was fetched 2026-07-26, HTTP 200, 416,233 bytes of HTML / 98,179 characters of extracted text. A case-insensitive scan of the extracted text found NO occurrence of "CBRE" and NO occurrence of "Australia". https://www.reso.org/certification/ returned HTTP 200 and confirms RESO certification is scoped to MLS systems (489 in the United States, 30+ in Canada, "a small but increasing number in Central America, South America, Europe and West Asia") — Australia is not named. https://certification.reso.org/ (the RESO Analytics live certification directory app) returned HTTP 400 to anonymous requests and could not be queried. whyAbsent: >- Australia has no MLS. RESO Web API and RESO Data Dictionary certification are artifacts of the North American MLS system, mandated by NAR (an industry body, not a government) and only meaningful where an MLS exists. Australian residential listing distribution runs through a portal duopoly (REA Group's realestate.com.au and Domain); commercial listings run through realcommercial.com.au and agency sites. The closest thing Australia has to a REQUIRED, national, machine-readable property rail is PEXA, the electronic conveyancing network that is effectively mandated in most states — a settlement rail, not a listing standard, and not something CBRE Australia publishes an interface to. metadataProbe: >- https://www.cbre.com.au/$metadata was probed 2026-07-26 and returned HTTP 404 (the Sitecore "Error: Page Not Found (404)" page). No OData service document, no $metadata document, no Reso/OData path exists on any CBRE host reachable anonymously. accessGate: classification: none-published whatADeveloperMustSignOrJoin: >- Nothing is published, because there is nothing published to sign up for. There is no developer registration form, no API application, no key request, no partner API programme page, and no data licence offered to developers anywhere on cbre.com.au. CBRE does operate API infrastructure, but every reachable piece of it is either WAF-blocked (api.cbre.com, Imperva/Incapsula 403 on all paths) or authenticated (eipportal.cbre.com, an "Integration Platform - CBRE" React SPA that renders a login shell). Obtaining CBRE Australia data is a commercial client or partner engagement negotiated offline — an advisory or property-management contract — not a developer onboarding flow. It is correct to call this "none-published" rather than "partner-only", because CBRE does not publish a partner API programme either. scrapingProhibited: true scrapingClauseVerbatim: >- From CBRE's Terms of Use (https://www.cbre.com/about-us/disclaimer-terms-of-use, fetched 2026-07-26, HTTP 200): users may not "engage in spamming, flooding, harvesting of e-mail addresses or other personal information, spidering, screen scraping, database scraping, or any other activity with the purpose of obtaining lists of users or any other information, including specifically, property listings available through the site". The phrase "application programming interface" does not appear anywhere in the Terms of Use (0 occurrences). robotsEvidence: >- https://www.cbre.com.au/robots.txt (HTTP 200, 2,143 bytes, fetched 2026-07-26) contains "Disallow: /api" and "Disallow: /sitecore/", confirming an internal Sitecore-backed /api path that is explicitly closed to crawlers and is not a published developer interface. openData: exists: false note: >- CBRE Australia publishes no open dataset. It is a private commercial firm; its research and market outlooks are published as PDFs and web articles, not as licensed-free machine-readable data. The Australian open-data counterweight in this sector sits with government (state land registries, several of which have been progressively privatised, plus data.gov.au) and not with CBRE. No genuinely open, unlicensed, publicly callable CBRE dataset was found. authModel: publishedScheme: none oidcDiscovery: >- https://api.cbre.com/.well-known/openid-configuration returned HTTP 403 (Imperva/Incapsula block page, 888 bytes) to an anonymous request on 2026-07-26. No OIDC discovery document is served anonymously. https://api-dev.cbre.com/.well-known/openid-configuration returned HTTP 404 with a WSO2 JSON error body. observedInfrastructure: >- api-dev.cbre.com serves the stock WSO2 API Manager landing page (

Welcome to APIM

...), which identifies the gateway product but publishes no APIs. eipportal.cbre.com is a Vite/React SPA titled "Integration Platform - CBRE" whose manifest.json is still the unmodified Create React App sample. Neither exposes an anonymous API catalogue, token endpoint, or documented auth flow. conclusion: >- No auth model can be recorded because no public API exists to authenticate against. Any real scheme in use is internal to CBRE and its contracted partners. webhooksEventsSdksPostman: webhooks: none found events: none found sdks: >- None. github.com/CBRE exists (org id 8472144, created 2014-08-17) with 0 public repositories. Related orgs checked 2026-07-26: cbreenterprise (0), CBRE-Shared-Code (0), cbre360 (0), cbreapac (0 — this is the Asia-Pacific org that would cover Australia), CBRE-DevOps (0), CBREDigitalSpain (0). cbreemea has 2 public repos, both forks of the third-party oauth2_proxy project, not CBRE APIs or SDKs. postman: none found note: Absence of all four is itself the finding for this provider. productApiFamily: note: >- CBRE Australia's service segmentation is taken verbatim from the live cbre.com.au navigation (fetched 2026-07-26). NONE of these are exposed as APIs; they are recorded so the sector study can see what a machine-readable surface would have covered if one existed. needs: - Invest, Finance & Value (https://www.cbre.com.au/services/invest-finance-and-value) - Plan, Lease & Occupy (https://www.cbre.com.au/services/plan-lease-and-occupy) - Design & Build (https://www.cbre.com.au/services/design-and-build) - Manage Properties & Portfolios (https://www.cbre.com.au/services/manage-properties-and-portfolios) - Transform Business Outcomes (https://www.cbre.com.au/services/transform-business-outcomes) propertyTypes: - Office - Retail - Industrial & Logistics - Build to Rent - Alternatives listingSurface: >- https://www.cbre.com.au/properties — "Search CBRE's Commercial Property Listings", HTTP 200, an HTML search UI for Properties for Sale and Properties for Lease. No JSON feed, no documented query API, no download. findings: summary: | CBRE Australia has no public developer surface. Every candidate developer hostname is NXDOMAIN, the one production API hostname that does resolve is WAF-blocked to anonymous traffic, and the two reachable API-adjacent hosts are a default vendor gateway page and a login-gated integration portal. No OpenAPI, no Swagger, no OData $metadata, no WSDL of CBRE's own authorship, no Postman collection, no SDK, no webhooks, no OIDC discovery, no security.txt. RESO does not appear anywhere in CBRE's estate and does not appear in the public RESO certification listing — which is the expected and honest result for an Australian organization, since Australia has no MLS and therefore no RESO ecosystem. This is a "built-stub": identity captured, API posture captured, zero APIs listed because zero real APIs are published. criticalDistinction: >- Certification is not reachability, and in this case neither is present. CBRE Australia is NOT a certified-but-closed provider (the RESO trap this study is designed to catch) — it is simply closed, with no standards posture at all. The distinction matters: a RESO-certified US brokerage at least speaks an open standards language behind its licence gate. CBRE Australia speaks no published standard and offers no gate to pass through. crossCheckAgainstExistingRepo: >- The pre-existing api-evangelist/cbre (global) profile claims a developer portal at https://developer.cbre.com/ and a baseURL of https://api.cbre.com, and lists a "CBRE Real Estate API". That claim does not hold up on probe: developer.cbre.com returns NXDOMAIN (no A record, no CNAME) and api.cbre.com returns an Imperva 403 to every path. This Australia profile deliberately does NOT repeat that claim and lists zero APIs. probes: fetchDate: '2026-07-26' method: >- Anonymous curl with a desktop browser user-agent, plus a text-extraction reader proxy for hosts behind the Cloudflare interactive challenge. Every status code below was observed directly. hosts: - url: https://www.cbre.com.au/ status: 403 note: Cloudflare "Just a moment..." interactive challenge to direct curl; content retrieved via reader proxy (HTTP 200, 19,939 bytes) and confirmed as the live CBRE Australia homepage. - url: https://cbre.com.au/ status: 403 note: Same Cloudflare challenge. - url: https://developer.cbre.com.au/ status: 000 note: DNS does not resolve (NXDOMAIN). No developer portal. - url: https://developers.cbre.com.au/ status: 000 note: DNS does not resolve (NXDOMAIN). - url: https://api.cbre.com.au/ status: 000 note: DNS does not resolve (NXDOMAIN). Australia has no CBRE API host. - url: https://docs.cbre.com.au/ status: 000 note: DNS does not resolve (NXDOMAIN). - url: https://www.cbre.com.au/developers status: 403 note: Cloudflare challenge; no such path is linked anywhere in site navigation. - url: https://www.cbre.com.au/api status: 403 note: Cloudflare challenge. robots.txt explicitly disallows /api — internal Sitecore path, not a published API. - url: https://www.cbre.com.au/docs status: 403 note: Cloudflare challenge. - url: https://developer.cbre.com/ status: 000 note: NXDOMAIN — no A record, no CNAME. The global developer portal claimed by third-party sources does not exist. - url: https://developers.cbre.com/ status: 000 note: NXDOMAIN. - url: https://api.cbre.com/ status: 403 note: Resolves to sqduhqb.ng.impervadns.net / 45.60.196.249. Imperva/Incapsula block page (888 bytes) with incident ID. A real API host exists; it is not anonymously reachable and publishes nothing. - url: https://api.cbre.com/openapi.json status: 403 note: Imperva block. - url: https://api.cbre.com/swagger.json status: 403 note: Imperva block. - url: https://api.cbre.com/swagger status: 403 note: Imperva block. - url: https://api.cbre.com/api-docs status: 403 note: Imperva block. - url: https://api.cbre.com/$metadata status: 403 note: Imperva block. No OData metadata document obtainable. - url: https://api.cbre.com/.well-known/openid-configuration status: 403 note: Imperva block. No anonymous OIDC discovery. - url: https://api-prod.cbre.com/ status: 403 note: Imperva block. - url: https://api-uat.cbre.com/ status: 000 note: Does not resolve. - url: https://apim.cbre.com/ status: 000 note: Does not resolve. - url: https://apis.cbre.com/ status: 000 note: Does not resolve. - url: https://docs.cbre.com/ status: 000 note: Does not resolve. - url: https://api-dev.cbre.com/ status: 200 note: 'Default WSO2 API Manager landing page, 142 bytes verbatim:

Welcome to APIM

service. A development-tier gateway, not a developer portal.' - url: https://api-dev.cbre.com/devportal status: 404 note: WSO2 JSON 404. No developer portal deployed. - url: https://api-dev.cbre.com/store status: 404 note: WSO2 JSON 404. No API store deployed. - url: https://api-dev.cbre.com/publisher status: 404 note: WSO2 JSON 404. - url: https://api-dev.cbre.com/swagger status: 404 note: WSO2 JSON 404. No spec served. - url: https://api-dev.cbre.com/api status: 404 note: WSO2 JSON 404. - url: https://api-dev.cbre.com/services status: 200 note: 'Axis2 deployed-services page, 197 bytes: exactly one service, "Version", with one operation getVersion.' - url: https://api-dev.cbre.com/services/Version?wsdl status: 200 note: >- A real WSDL, 5,536 bytes, parses as XML. NOT SAVED to openapi/ and NOT listed as a CBRE API, deliberately: its targetNamespace is http://version.services.core.carbon.wso2.org, i.e. it is the stock WSO2 Carbon platform Version service present on every default WSO2 install. It is vendor scaffolding, not a CBRE contract, and saving it would falsely imply CBRE publishes a machine-readable interface. - url: https://eipportal.cbre.com/ status: 200 note: React/Vite SPA, 973 bytes of shell, Integration Platform - CBRE. Renders nothing without JavaScript and no anonymous API catalogue. manifest.json (HTTP 200, 305 bytes) is the unmodified Create React App sample. - url: https://eipportal.cbre.com/login status: 200 note: Same SPA shell — client-side routed login. Authenticated, internal/partner surface. - url: https://mytrade-api-dev.cbre.ca/ status: 404 note: Redirects to /api then 404. Canadian development host, out of scope for the Australian profile and serving nothing. - url: https://www.cbre.com.au/robots.txt status: 200 note: >- Retrieved via reader proxy, 2,143 bytes. Contains the directives "Disallow: /api" and "Disallow: /sitecore/". Points sitemaps at cbre.com/sitemap.xml and cbre.com.au/sitemap.xml. - url: https://www.cbre.com.au/.well-known/security.txt status: 404 note: No security.txt, no vulnerability disclosure contact published on the Australian domain. - url: https://www.cbre.com.au/openapi.json status: 404 note: Sitecore 404. No OpenAPI. - url: https://www.cbre.com.au/swagger.json status: 404 note: Sitecore 404. No Swagger. - url: https://www.cbre.com.au/api-docs status: 404 note: Sitecore soft-404 page. - url: https://www.cbre.com.au/$metadata status: 404 note: 'Sitecore "Error: Page Not Found (404)" page. No OData metadata document.' - url: https://www.cbre.com.au/properties status: 200 note: "\"Search CBRE's Commercial Property Listings\" — HTML search UI only, no\ \ feed, no documented query interface." - url: https://www.cbre.com.au/about-us status: 200 note: Retrieved via reader proxy, 17,111 bytes. Zero occurrences of "developer", "/api", "api key", or "integration". - url: https://www.cbre.com.au/services status: 200 note: Retrieved via reader proxy, 19,017 bytes. The single occurrence of "developer" is the real-estate sense ("real estate investors, developers and occupiers"), not software. - url: https://www.cbre.com/about-us/disclaimer-terms-of-use status: 200 note: Terms of Use. Prohibits spidering / screen scraping / database scraping of property listings. No mention of an API. - url: https://www.reso.org/certification/ status: 200 note: RESO Certification and MLS Map. Confirms certification scope is MLS systems in the US, Canada, and a small number elsewhere. Australia not mentioned. - url: https://www.reso.org/certificates/ status: 200 note: RESO Certification Status listing, 416,233 bytes. No "CBRE", no "Australia" in extracted text. - url: https://certification.reso.org/ status: 400 note: RESO Analytics certification directory app rejects anonymous requests; could not be queried directly. - url: https://api.github.com/orgs/CBRE status: 200 note: 0 public repositories. Checked alongside cbreapac (0), cbreenterprise (0), CBRE-Shared-Code (0), cbre360 (0), CBRE-DevOps (0), CBREDigitalSpain (0), cbreemea (2, both third-party oauth2_proxy forks). artifacts: openapi: [] asyncapi: [] odataMetadata: [] postman: [] wsdl: [] count: 0 note: >- openapi/ directory intentionally omitted — nothing real of CBRE's authorship was found to put in it. The one machine-readable document retrieved (api-dev.cbre.com WSO2 Version WSDL) is vendor default scaffolding and is documented in probes[] rather than stored as a CBRE artifact. marketSeamContext: note: >- Recorded as sector background only. No CBRE integration with any of these is claimed or evidenced. observations: - >- Australian residential listing distribution is a portal duopoly — REA Group's realestate.com.au and Domain — sitting over state-by-state land registries that have been progressively privatised. Commercial listings, CBRE's segment, flow through realcommercial.com.au (REA Group) and agency websites. - >- PEXA, the electronic conveyancing network, is effectively mandated in most Australian states and settles the overwhelming majority of property transactions. https://www.pexa.com.au/ (HTTP 200) and https://developer.pexa.com.au/ (HTTP 200) were probed on 2026-07-26 and a PEXA developer host does resolve and respond — the strongest evidence in the Australian market that a required, national, machine-readable property rail exists. It sits at the settlement layer, not the listing layer, and it is not CBRE's. - >- Valuation data in Australia concentrates in PropTrack (REA-owned) and CoreLogic. CBRE Australia performs valuation and advisory as a service engagement; it does not publish an AVM API. conclusion: status: built-stub apisListed: 0 portalConfirmed: false openApiHarvested: false specsCount: 0 resoCertified: false accessGate: none-published openData: false gated: true reason: >- Identity captured from live sources; API posture captured honestly as absent. No public developer portal exists, no machine-readable contract of CBRE's authorship was retrievable, and RESO is entirely absent — the correct answer for an Australian commercial real estate services firm operating in a market that has no MLS.