# Great-West Lifeco > Great-West Lifeco Inc. is a Winnipeg-headquartered international financial services holding company in the Power Corporation group and one of the largest life insurers in North America, operating through Canada Life (Canada, UK, Isle of Man, Germany), Irish Life (Ireland) and Empower (United States). No /llms.txt is published on any host in the group; this file is generated by API Evangelist from the artifacts in this repository. Every fact below was read off a public page or a live probe on 2026-07-25. The group has no unified API program. There is no group-level developer portal, no downloadable specification, and no self-serve access anywhere. Two independent production API surfaces exist, both partner-gated: - **Empower** (U.S. retirement recordkeeping) runs a real, publicly readable developer portal whose reference documentation is behind login and whose credentials are issued only after a reviewed access request. - **Canada Life** (Canadian operating brand) runs an Apigee gateway at `api.canadalife.com` that serves an anonymous OpenID Connect discovery document but publishes no documentation; its error envelopes point to a digitalML-hosted API marketplace that does not resolve publicly. ## Company - [Great-West Lifeco](https://www.greatwestlifeco.com/): Holding company. No developer or API content. - [About Great-West Lifeco](https://www.greatwestlifeco.com/who-we-are/about-us.html) - [News](https://www.greatwestlifeco.com/news-and-events/news.html) - [Privacy policy](https://www.greatwestlifeco.com/privacy-policy.html) - [Legal](https://www.greatwestlifeco.com/legal.html) - [Internet Security Statement](https://www.greatwestlifeco.com/internet-security.html): Consumer security statement. No vulnerability-reporting address. - [Canada Life](https://www.canadalife.com/): Canadian insurance and wealth brand. No developer navigation of any kind. ## Developer surface (Empower, U.S. retirement subsidiary) - [Empower Retirement Developer Portal](https://developer.empower.com/): Drupal/Pronovix portal. Publicly readable, not self-serve. - [API Catalog](https://developer.empower.com/api-catalog): Exactly two entries readable anonymously, both marked production. - [Balance API](https://developer.empower.com/api-catalog/balance-api): Participant-level balance data (total, investment, loan and vesting balances) in JSON. Reference documentation behind login. - [OAuth 2.0 API](https://developer.empower.com/api-catalog/oauth2-api): Issues bearer access tokens for the API suite. Carries the group's only public release notes. - [Get started](https://developer.empower.com/docs/get-started): Registration, access request, x-api-key header, client_credentials token exchange, sandbox and stage environments. - [Go to production](https://developer.empower.com/docs/go-production) - [Status and maintenance](https://developer.empower.com/docs/status-and-maintenance): Sunday 00:00-12:00 MST maintenance window; deployments the second weekend of every month. - [PKI / additional security protocols](https://developer.empower.com/docs/additional-security-protocols-publicprivate-key-infrastructure-pki): private_key_jwt required since Q4 2024 in support of FAPI. - [Support](https://developer.empower.com/support) - [Developer Terms of Use](https://developer.empower.com/DevTerms) - [Sandbox developer portal](https://developer-sandbox.empower.com/): Publicly reachable mirror with an extra "test only" catalog category. - [Empower APIs (product page)](https://www.empower.com/financial-professionals/experience/apis): Names eight API products and three coming soon - the group's de facto roadmap. - [Empower Cybersecurity](https://www.empower.com/financial-professionals/about-empower/cybersecurity): SOC 2 Type 2, ISO 27001 / NIST 800-53 / NIST CSF alignment, OWASP-aligned SAST/DAST. ## API products named by Empower Live: DC payroll bundle (DC Census/Indicative + DC Deferrals + DC Loans), DC census/indicative, Financial data exchange, DC participant balances, DC deferrals, DC loans, DC participant YTD contributions, DC participant eligibility. Coming soon: DC participant personal rate of return, DC plan provisions, DC investments. Only "DC participant balances" (as Balance API) and the OAuth 2.0 API appear in the anonymously readable catalog. ## Machine-readable artifacts - [OpenID Connect discovery, Canada Life gateway](https://api.canadalife.com/.well-known/openid-configuration): HTTP 200. The only machine-readable contract published anywhere in the group. - No OpenAPI, Swagger, AsyncAPI, GraphQL SDL, gRPC/protobuf, MCP server, Postman collection or SDK exists on any public surface. Every spec probe against developer.empower.com, api.empower.com, api.canadalife.com, developer-sandbox.empower.com and the corporate sites returned 404 or 403. ## API Evangelist artifacts in this repository - authentication/great-west-lifeco-authentication.yml - both auth surfaces, x-api-key + OAuth 2.0 client_credentials + private_key_jwt, and the live Canada Life OIDC metadata. - scopes/great-west-lifeco-scopes.yml - authorization-server metadata; both surfaces publish an empty scope vocabulary. - well-known/great-west-lifeco-well-known.yml - every /.well-known/ probe across eight hosts, with the verbatim OIDC document. - conventions/great-west-lifeco-conventions.yml - transport, error envelopes, tracing, versioning, rate-limit posture. No idempotency contract is published. - errors/great-west-lifeco-problem-types.yml - the two proprietary gateway error envelopes and the observed/documented failure modes. - lifecycle/great-west-lifeco-lifecycle.yml - versioning, maturity labels, maintenance window, roadmap. No deprecation policy, no SLA. - changelog/great-west-lifeco-changelog.yml - Empower OAuth 2.0 API release notes v2.3.0 and v1.3.1. - sandbox/great-west-lifeco-sandbox.yml - the api-sandbox mock-data environment and the stage environment. No published test values. - conformance/great-west-lifeco-conformance.yml - OAuth2, OIDC, FAPI, FDX, OWASP, SOC 2 / ISO 27001 / NIST posture; ACORD and RFC 9457 absent. - security/great-west-lifeco-trust-center.yml - named certifications and governance controls. - security/great-west-lifeco-domain-security.yml - TLS, HSTS, DNSSEC, CAA, SPF and DMARC probes. ## Notes for agents - Nothing in this group can be called anonymously. Empower requires an approved access request before any endpoint, base URL or specification is disclosed; Canada Life requires an Apigee consumer key entitled to a specific API product. - The Canada Life gateway explicitly disables the interactive authorization endpoint - it is published as `/oauth2/v1/authorize-NOT-SUPPORTED`. Machine-to-machine grants only. - Scope names are never advertised. Empower rejects an unconfigured scope with HTTP 400 `invalid_grant`; scopes are attached to a client profile during approval. - No idempotency key, pagination convention, rate-limit header or webhook surface is documented anywhere. Treat write operations (DC deferrals, DC loans) as having no published retry-safety contract.