# First Digital Trust > First Digital Trust Limited (trading as First Digital) is a Hong Kong-headquartered trust and > custody institution serving the digital asset industry. It markets "Open Trust APIs", a RESTful > API suite for client onboarding, KYC/AML data, account information, instruction initiation, > reporting, webhooks and SSO — but publishes no public developer portal, API reference, or > machine-readable specification. API access is reached through a client relationship. Generated by API Evangelist from this repository's apis.yml and harvested artifacts on 2026-08-12. This file was NOT published by First Digital; the provider serves no llms.txt (probed https://1stdigital.com/llms.txt → 403, https://helpdesk.1stdigital.com/llms.txt → 404). ## What is machine-readable here There is no OpenAPI, AsyncAPI, GraphQL SDL, MCP server, agent card or Postman collection. Contract discovery was run against every First Digital host (1stdigital.com, www.1stdigital.com, portal.1stdigital.com, helpdesk.1stdigital.com, cdn.1stdigital.com) across /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs and the /.well-known/ surface. The only real document served anywhere is an RFC 9116 security.txt. ## APIs - [Open Trust APIs](https://1stdigital.com/open-trust-apis/): RESTful API suite covering client onboarding, KYC & assured identity (AML/CTF data and documents), account information (real-time client and account data), instruction initiation, reporting (real-time balances plus historical transaction retrieval), webhooks, and an SSO authentication service. No public reference, no base URL published, no specification. ## Specs - None published by the provider. ## Artifacts in this profile - [Webhook surface](asyncapi/first-digital-trust-webhooks.yml): the advertised webhook capability, recorded with an explicitly empty event list because the provider publishes none. - [Well-known probe](well-known/first-digital-trust-well-known.yml): 30 paths across 4 hosts; one real document. Note portal.1stdigital.com answers 200 with an Angular SPA shell on every /.well-known/* path — those are not documents. - [security.txt](well-known/first-digital-trust-security.txt): verbatim RFC 9116 document. - [Vulnerability disclosure](security/first-digital-trust-vulnerability-disclosure.yml): security contact infosec@1stdigital.com; no bug bounty, no Policy field. - [Trust center](security/first-digital-trust-trust-center.yml): SOC 1 Type 2, SOC 2 Type 2, ISO 27001, CSA STAR Level 1, plus the licensed entities and their registrations. - [Domain security](security/first-digital-trust-domain-security.yml): TLS 1.3, DNSSEC enabled, CAA set, SPF and DMARC present (policy: quarantine), no HSTS. - [Conformance](conformance/first-digital-trust-conformance.yml): 15 confirmed organisational and regulatory standards; protocol conformance is not determinable without a spec. - [Packages](packages/first-digital-trust-packages.yml): zero first-party SDKs found. - [Plans](plans/first-digital-trust-plans-pricing.yml): zero published plans; contact-sales model. - [Rate limits](rate-limits/first-digital-trust-rate-limits.yml): zero published limits. ## Docs - [Company site](https://1stdigital.com/) - [Open Trust APIs](https://1stdigital.com/open-trust-apis/) - [Support center](https://helpdesk.1stdigital.com/) — end-user Client Portal articles only - [Client portal](https://portal.1stdigital.com/) — Microsoft Entra ID sign-in - [Security Center](https://1stdigital.com/security/) - [Legal & Regulatory](https://1stdigital.com/legal-and-regulatory/) - [Privacy Policy](https://1stdigital.com/legal-and-regulatory/privacy-policy/) - [Acceptable Use Policy](https://1stdigital.com/legal-and-regulatory/acceptable-use-policy/) - [News & Insights](https://1stdigital.com/news-and-insights/) ## Access note for agents 1stdigital.com sits behind a Cloudflare bot challenge that returns HTTP 403 to automated clients on most paths, although robots.txt is `Allow: /`. The exempt paths are /robots.txt and /.well-known/security.txt. There is no public API endpoint an agent can call.