# Goodlord > Goodlord (Oh Goodlord Limited, London) is a United Kingdom PropTech platform that digitises > the pre-tenancy and tenancy lifecycle for residential letting agents, landlords and tenants — > tenant referencing, e-signed tenancy contracts, rent and deposit payments, rent protection > insurance, guarantors, PEPs and sanctions checks, inventories, utility switching and end of > tenancy. It sits between the agency CRM (Reapit, Alto, Street, Qube) and the regulated deposit > schemes, insurers and utility suppliers — not on the listings side controlled by the > Rightmove/Zoopla portal duopoly. Generated by API Evangelist on 2026-07-26. Goodlord publishes no llms.txt of its own (https://www.goodlord.com/llms.txt returns 404; https://portal.goodlord.co/llms.txt returns the Tyk portal HTML shell, a soft 404). This file is generated from Goodlord's three published OpenAPI 3.1.0 documents and its public developer portal. ## How access actually works Goodlord's API posture is unusually open for the UK lettings sector, and honestly split in two. The documentation is genuinely public and the machine-readable contracts are downloadable without a login. Credentials are not. The developer portal's registration page returns "Registration is not allowed" and requires an invite code, and Goodlord's own getting-started guide instructs developers to obtain sandbox and production access through a Goodlord sales manager or account manager. **Public contract, partner-gated keys.** There is no self-serve signup, no free tier and no published pricing for API access. Note also that `*.goodlord.co` answers a wildcard DNS record — `developer`, `docs`, `status`, `help`, `webhooks`, `sandbox` and a control probe of a nonsense name all return HTTP 200 with the identical Goodlord Core SPA. Do not treat a 200 on a goodlord.co subdomain as evidence that anything is there. ## APIs - [Goodlord Referencing API](https://portal.goodlord.co/portal/catalogue-products/referencing-product-1): Create rental applications, add and assess applicants and guarantors (plus employer, accountant and landlord referees), patch outcome conditions, read touchpoints and emails, retrieve generated documents. 15 operations, 10 paths. Live host `https://api.goodoverlord.com`. OAuth 2.0 client_credentials plus a mandatory issued `Company-ID` header. - [Goodlord Referencing API (Sandbox)](https://portal.goodlord.co/portal/catalogue-products/referencing-product-1): Identical operation surface on `https://api-sandbox.goodlord.co`, published as its own catalogue entry with its own specification and token endpoint. Access arranged by a Goodlord account manager. - [Goodlord Insurance App API](https://insurance-app.goodlord.co/api/v1/docs): Rent protection insurance claims — claims and claim submission, evidence file upload, insurer payments, arrears rent schedules and rows, plus agents, companies, roles and role groups. 35 operations, 21 paths. Its OpenAPI is served publicly and unauthenticated, but it is not listed in the developer portal catalogue and has no published onboarding path. Every data operation returns 401 without a token. ## Specs - [Referencing API OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/openapi/goodlord-referencing-api-openapi.json) - [Referencing API Sandbox OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/openapi/goodlord-referencing-api-sandbox-openapi.json) - [Insurance App API OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/openapi/goodlord-insurance-app-api-openapi.json) - [OpenID Connect discovery (end-user platform login, Microsoft Entra External ID)](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/well-known/goodlord-openid-configuration.json) ## Docs - [Goodlord Developer Portal](https://portal.goodlord.co/) — a real, public, anonymously readable Tyk developer portal. It is linked from nowhere on the marketing site; the www.goodlord.com sitemap has 385 URLs and not one /api, /developers or /docs entry. - [Product catalogue](https://portal.goodlord.co/portal/catalogue-products) - [Referencing Product — authentication, webhooks, glossary and domain guides](https://portal.goodlord.co/portal/catalogue-products/referencing-product-1) - [Getting started with Goodlord's Referencing API](https://portal.goodlord.co/blog/2024/8/22/getting-started-with-goodlords-referencing-api) - [Understanding Goodlord's Referencing API](https://portal.goodlord.co/blog/2024/8/20/getting-started-with-goodlord-referencing-api) - [Referencing API reference](https://portal.goodlord.co/portal/catalogue-products/referencing-product-1/dHlrL3Byb2QtcmVmZXJlbmNpbmctYXBp/docs) - [Insurance App API reference](https://insurance-app.goodlord.co/api/v1/docs) ## Authentication - Referencing API: OAuth 2.0 `client_credentials`. `POST /auth/token` with `client_id`, `client_secret` and `grant_type`; returns a Bearer JWT valid 3600 seconds with scope `free_plan referencing_product`. Every call additionally carries `Company-ID: ` — mandatory, documented only in the portal, not declared in the OpenAPI. - Insurance App API: JWT bearer in the `Authorization` header (declared in the spec as `apiKey`). - End-user platform login (letting agents and tenants, not developers): Microsoft Entra External ID / Azure AD B2C, policy `B2C_1A_2_SIGNUPORSIGNIN`, with a real OIDC discovery document. - Full profile: [authentication](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/authentication/goodlord-authentication.yml) · [scopes](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/scopes/goodlord-scopes.yml) ## Events Three webhook events are published with exact names — `V2.subject.report.generated`, `V2.subject.reference.form.generated`, `V2.subject.outcome.updated` — with an example payload envelope carrying identifiers only. Subscriptions are configured by Goodlord on request; there is no subscription API, no published signature scheme and no AsyncAPI document. The Insurance App API has no event surface at all — it is poll-only. - [Webhook catalogue](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/asyncapi/goodlord-referencing-webhooks.yml) ## API Evangelist artifacts - [API conventions](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/conventions/goodlord-conventions.yml) - [Error catalogue](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/errors/goodlord-problem-types.yml) - [Data model](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/data-model/goodlord-data-model.yml) - [Lifecycle, status page and versioning](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/lifecycle/goodlord-lifecycle.yml) - [Sandbox and test access](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/sandbox/goodlord-sandbox.yml) - [Standards conformance](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/conformance/goodlord-conformance.yml) - [Domain security probe](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/security/goodlord-domain-security.yml) - [Trust center](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/security/goodlord-trust-center.yml) - [Well-known documents](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/well-known/goodlord-well-known.yml) - [Agentic access contracts](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/agentic-access/goodlord-agentic-access.yml) - [Candidate MCP tool surface](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/mcp/goodlord-mcp.yml) - [Agent skills](https://raw.githubusercontent.com/api-evangelist/goodlord/refs/heads/main/skills/_index.yml) ## Operations - Status page: https://goodlord.statuspal.io/ (StatusPal; components Web application, Referencing, Vouch). Reachable via https://www.goodlord.com/status. Not linked from the developer portal. `status.goodlord.co` is the wildcard SPA, not a status page. - Trust center: https://trust.goodlord.com/ (Sprinto) — ISO 27001 v2022 and GDPR claimed; certificate, 40+ policies and the subprocessor register are behind a "Request access" gate. - No changelog, no release notes, no deprecation or sunset policy, no published SLA, no published rate limits, no security.txt, no vulnerability disclosure programme. ## Not available No SDKs in any language, no CLI, no embeddable UI components, no Postman collection, no public GitHub organisation, no GraphQL, no gRPC, no AsyncAPI, no MCP server, no OData `$metadata`, no RESO Web API or Data Dictionary conformance (RESO is a US NAR/MLS construct with no United Kingdom counterpart), and no open data — every dataset is tenant-scoped, credential-gated personal data of the highest sensitivity. ## Company - [Website](https://www.goodlord.com/) - [Platform](https://www.goodlord.com/platform) - [Integrations](https://www.goodlord.com/platform/integrations) — Reapit, Street.co.uk, Alto, Qube (CRM); TDS, DPS, mydeposits, Reposit (deposits); Paymentshield (insurance); Home Telecom, OVO Energy, Sky UK, Perse (utilities); Kamma, The Depositary (compliance and end of tenancy). Described as commercial partnerships activated during onboarding, not developer integrations. - [Partners](https://www.goodlord.com/about/our-partners) - [NewsAGENT blog](https://www.goodlord.com/newsagent) - [Support](https://www.goodlord.com/support) — separate help centres for agents, landlords, tenants and guarantors - [Terms of Use](https://www.goodlord.com/terms) · [Privacy Policy](https://www.goodlord.com/privacy-policy) - Legal entity: Oh Goodlord Limited (company number 8933499), The Hickman, 2-4 Whitechapel Rd, London E1 1EW. Appointed Representative of Goodlord Protect Limited, authorised and regulated by the Financial Conduct Authority for insurance distribution, FRN 836727.