# Express Scripts Holding > Express Scripts is a pharmacy benefit management (PBM) company, now part of Cigna's > Evernorth Health Services, that processes prescription claims and provides home > delivery and specialty pharmacy services for health plans, employers and government > programs. Express Scripts runs a real API estate — a production gateway, a separate > sandbox gateway and its own OAuth 2.0 / OpenID Connect authorization server — but > publishes no API contract publicly. The developer portal renders client-side and its > content backend refuses anonymous requests. This file is GENERATED by API Evangelist from an independent third-party profile of Express Scripts' public API surface. It is not published by Express Scripts. The company's own developer portal advertises an llms.txt at https://developer.express-scripts.com/llms.txt, but that URL returns HTTP 200 serving the portal's HTML shell rather than a text llms.txt — a soft 404. ## What an agent can actually reach - Production API gateway: https://api.express-scripts.io — HTTP 401 to every anonymous request, including /.well-known/* paths. Authenticates before routing. - Sandbox API gateway: https://api-sandbox.express-scripts.io — HTTP 401, same behavior. - Authorization server (OpenID Connect discovery, HTTP 200, anonymous): https://p.login.developer.express-scripts.com/oauth2/default/.well-known/openid-configuration - Authorization server metadata (RFC 8414, HTTP 200, anonymous): https://p.login.developer.express-scripts.com/.well-known/oauth-authorization-server ## What is NOT available - No OpenAPI, Swagger, GraphQL SDL, AsyncAPI, Protobuf or WSDL at any public URL. - No MCP server and no A2A agent card. The developer host answers HTTP 200 with an identical 1,245-byte SPA shell for every /.well-known/* path, including /.well-known/agent-card.json; none of those 200s is a document. - No SDK or client library in any public package registry. - No published pricing, rate limits, status page, changelog or deprecation policy. - No /.well-known/oauth-protected-resource (RFC 9728), so an agent cannot discover the authorization server from the resource. ## Authentication - Protocol: OAuth 2.0 + OpenID Connect, on Express Scripts' own Okta tenant. - Issuer: https://p1-express-scripts.okta.com/oauth2/default (branded as https://p.login.developer.express-scripts.com/oauth2/default) - PKCE: required in practice, S256 only. - Sender-constrained tokens: DPoP (RFC 9449) supported. mTLS is not. - Also advertised: Pushed Authorization Requests (RFC 9126), Device Authorization Grant (RFC 8628), CIBA, token introspection (RFC 7662), revocation (RFC 7009) and Dynamic Client Registration (RFC 7591). - Application scope: `esrx.default`, alongside the standard OIDC scopes. - Machine-to-machine: client_credentials is advertised on the org-level authorization server. ## How access is obtained Access is not self-serve. Credentials require an Express Scripts client or partner relationship plus an approved account on https://developer.express-scripts.com/. The portal ships `register-authorization: true` and `can-register-apps: false`, so Express Scripts issues application credentials rather than letting a developer create them, and `public-specs: false`, which is why no specification is visible without signing in. ## Not Express Scripts The Express Scripts developer portal shares one codebase with the Cigna and Evernorth portals, and its bundle names two FHIR base URLs: https://p-hi2.digitaledge.cigna.com/PatientAccess/v1/ and .../ProviderDirectory/v1/. Both CapabilityStatements declare publisher "Cigna, Inc." Those are Cigna's CMS Interoperability APIs, not Express Scripts', and must not be attributed to this company. ## Profile - API Evangelist profile: https://github.com/api-evangelist/express-scripts-holding - apis.yml: https://raw.githubusercontent.com/api-evangelist/express-scripts-holding/refs/heads/main/apis.yml - Developer portal: https://developer.express-scripts.com/ - Website: https://www.express-scripts.com - Parent company: https://www.evernorth.com/ - Trust center: https://trust.express-scripts.com/ (SOC 2, PCI DSS, HIPAA) - Vulnerability disclosure: https://www.cigna.com/legal/members/responsible-vulnerability-disclosure Generated 2026-09-07 by the API Evangelist enrichment pipeline.