generated: '2026-09-07' method: probed source: >- https://fmsso.fanniemae.com/.well-known/openid-configuration (HTTP 200, application/json, fetched 2026-09-07) and https://fmsso.fanniemae.com/.well-known/oauth-authorization-server (HTTP 200), both saved verbatim under well-known/. Reached by following the Developer Portal's own 302 from https://developer.fanniemae.com/fv7ui-secured/web/fv7/api/auth/v1/userdetails. note: >- Derived from Fannie Mae's own published authorization-server metadata, not from an OpenAPI — Fannie Mae publishes no public API contract. This describes how a developer authenticates to the Fannie Mae Developer Portal and to the applications and APIs behind it; per-API security schemes are not public. provider: Fannie Mae authorization_servers: - issuer: https://fmsso.fanniemae.com product: PingFederate role: primary — external party / Developer Portal SSO discovery: openid_configuration: https://fmsso.fanniemae.com/.well-known/openid-configuration oauth_authorization_server: https://fmsso.fanniemae.com/.well-known/oauth-authorization-server jwks_uri: https://fmsso.fanniemae.com/pf/JWKS endpoints: authorization: https://fmsso.fanniemae.com/as/authorization.oauth2 token: https://fmsso.fanniemae.com/as/token.oauth2 userinfo: https://fmsso.fanniemae.com/idp/userinfo.openid introspection: https://fmsso.fanniemae.com/as/introspect.oauth2 revocation: https://fmsso.fanniemae.com/as/revoke_token.oauth2 end_session: https://fmsso.fanniemae.com/idp/init_logout.openid pushed_authorization_request: https://fmsso.fanniemae.com/as/par.oauth2 device_authorization: https://fmsso.fanniemae.com/as/device_authz.oauth2 backchannel_authentication: https://fmsso.fanniemae.com/as/bc-auth.ciba dynamic_client_registration: https://fmsso.fanniemae.com/as/clients.oauth2 grant_types_supported: - authorization_code - implicit - refresh_token - password - client_credentials - urn:ietf:params:oauth:grant-type:jwt-bearer - urn:ietf:params:oauth:grant-type:saml2-bearer - urn:ietf:params:oauth:grant-type:device_code - urn:ietf:params:oauth:grant-type:token-exchange - urn:openid:params:grant-type:ciba - urn:pingidentity.com:oauth2:grant_type:validate_bearer token_endpoint_auth_methods_supported: - client_secret_basic - client_secret_post - client_secret_jwt - private_key_jwt - tls_client_auth - none code_challenge_methods_supported: [plain, S256] require_pushed_authorization_requests: false subject_types_supported: [public, pairwise] claims_supported: [sub] dpop_supported: true mtls_client_auth_supported: true - issuer: https://auth.pingone.com/4c2b23f9-52b1-4f8f-aa1f-1d477590770c/as product: PingOne (Fannie Mae production tenant) role: >- Developer Portal self-service registration. The production portal's shipped runtime config names this environment as its registerUrl; the environment id was read from https://developer.fanniemae.com/main.9ce4eb977e10f81d.js. discovery: openid_configuration: https://auth.pingone.com/4c2b23f9-52b1-4f8f-aa1f-1d477590770c/as/.well-known/openid-configuration probed_status: 200 note: >- Served by Ping Identity's SaaS on a Fannie Mae tenant, not on a fanniemae.com host — recorded as evidence, not counted as a document Fannie Mae serves. schemes: - id: oauth2_authorization_code type: oauth2 flow: authorizationCode pkce: supported (S256) description: >- The Developer Portal front door. An unauthenticated request to the portal's own data API 302s to fmsso.fanniemae.com/as/authorization.oauth2 with client_id=sso-p2p-GED-p1-oidc-iDMZ-DeveloperPortal, response_type=code and scope="openid profile idmz". evidence: >- HTTP 302 observed 2026-09-07 on https://developer.fanniemae.com/fv7ui-secured/web/fv7/api/auth/v1/userdetails - id: oauth2_client_credentials type: oauth2 flow: clientCredentials description: >- Advertised in grant_types_supported. This is the machine-to-machine path a licensed integrator would use for API calls; issuance of a client is not self-service. evidence: https://fmsso.fanniemae.com/.well-known/oauth-authorization-server - id: mutual_tls type: mutualTLS description: tls_client_auth is advertised as a token-endpoint client authentication method. evidence: https://fmsso.fanniemae.com/.well-known/oauth-authorization-server - id: saml2_federation type: saml description: >- SAML 2.0 bearer grant and PingFederate IdP-initiated SSO/SLO (https://fmsso.fanniemae.com/idp/startSLO.ping) — the enterprise federation path used by licensed seller/servicer organizations. evidence: https://fmsso.fanniemae.com/.well-known/openid-configuration access: self_service_registration: true registration_url: https://auth.pingone.com/4c2b23f9-52b1-4f8f-aa1f-1d477590770c/saml20/idp/startsso?spEntityId=p1c-puma-GED-p1-saml-devportal-DirectRegistration registration_probed_status: 200 credentials_gate: >- A free Developer Portal account can be self-registered, but production API access is granted per application under the Software Subscription Agreement (the Consolidated Technology Guide) and is administered through Technology Manager — it is not self-service. contract_published: false api_reference_public: false docs: developer_portal: https://developer.fanniemae.com/ get_started: https://developer.fanniemae.com/#/get-started technology_guide: https://www.fanniemae.com/tech-guide technology_manager: https://technologymanager.fanniemae.com/