# Guidewire > Guidewire is the core-systems platform for property & casualty insurance: PolicyCenter (policy > administration), ClaimCenter (claims), BillingCenter (billing), plus PricingCenter, > UnderwritingCenter, InsuranceNow, and the HazardHub/Cyence/Predict analytics line. Its machine > interface is the InsuranceSuite Cloud API — a set of RESTful system APIs served by the CUSTOMER'S > OWN Guidewire Cloud deployment, not by a Guidewire-operated public host. Generated by API Evangelist on 2026-09-12 from Guidewire's public documentation. Guidewire does not publish an llms.txt of its own: https://docs.guidewire.com/llms.txt returns HTTP 200 with a 1,736-byte HTML single-page-app shell, not a text document (probed 2026-08-17 and again 2026-09-12). ## How to reach the API There is no public Guidewire API host. `api.guidewire.com` does not resolve (NXDOMAIN, checked 2026-09-12) and has never been a Guidewire endpoint. Request URLs take the documented form: /rest// e.g. https:///cc/rest/common/v1/activities?fields=assignedGroup `` is the customer's own InsuranceSuite instance on Guidewire Cloud. Every API also serves its own definition at `/rest//openapi.json` (OpenAPI 3.0) and `/swagger.json` (Swagger 2.0); in the base configuration those two endpoints are readable by any caller, including unauthenticated ones — but only against a running instance. ## The APIs in Cloud API - Account API — `/account/v1` — accounts and account-specific objects (PolicyCenter) - Admin API — `/admin/v1` — users, groups and administration objects - API List — `/apis` — lists the REST APIs available on the instance - Async API — `/async/v1` — retrieve responses to asynchronously processed calls - Billing API — `/billing/v1` — accounts and billing objects (BillingCenter) - Claim API — `/claim/v1` — claims and claim-specific objects (ClaimCenter) - Common API — `/common/v1` — platform objects shared across applications (activities, notes, contacts) - Composite API — `/composite/v1` — composite requests - Graph API — `/graph/v1` — operate on whole object graphs (PolicyCenter) - Job API — `/job/v1` — jobs (submission, policy change, renewal, cancellation) (PolicyCenter) - Policy API — `/policy/v1` — policies and policy-specific objects (PolicyCenter) - Product Definition API — `/productdefinition/v1` — PolicyCenter product metadata - System Tools API — `/systemtools/v1` — batch processes and database consistency checks - Test Util API — `/test-util/v1` — testing; available only when enabled - Contact API — `/contact/v1` — contacts (ContactManager deployments) Line-of-business endpoints are GENERATED per customer from Advanced Product Designer flows, so two Guidewire tenants do not expose the same contract. Plan for a per-tenant spec, not a shared one. ## Public API references (no login) - ClaimCenter — https://docs.guidewire.com/cloud/cc/202607/apiref/ (1,265 published operation pages) - PolicyCenter — https://docs.guidewire.com/cloud/pc/202607/apiref/ (963 published operation pages) - BillingCenter — https://docs.guidewire.com/cloud/bc/202607/apiref/ (1,208 published operation pages) - InsuranceNow — https://docs.guidewire.com/cloud/in/20262/apiref/ - Advanced Product Designer API — https://docs.guidewire.com/apd/api/latest/ - All references — https://docs.guidewire.com/apiReferences/ These references are rendered per platform release; the current release is Qusar (2026.07). They render the endpoints and sample responses but do not offer the underlying OpenAPI file for download. ## Authentication - Bearer token (JWT) — every caller type. The JWT carries both authentication and authorization claims. - HTTP Basic — internal users only, and NOT supported in production; development environments only. - Authorization is expressed as named API roles (role.yaml) bound to endpoints and fields, plus resource access and proxy-user access. There is no OAuth scope catalog for Cloud API. - Docs: https://docs.guidewire.com/cloud/is/202607/cloudapica/cloudAPI/AuthChoose/overview-authentication/c_authentication-methods.html ## Conventions an agent needs - Idempotency: `GW-DBTransaction-ID` request header, up to 128 characters, globally unique. A replayed value is rejected with HTTP 400 and `gw.api.webservice.exception.AlreadyExecutedException`. This is duplicate SUPPRESSION, not replay-with-identical-response — treat the 400 as "already applied". - Lost updates: `GW-Checksum` request header gates commits on a matching server-side checksum. - No-commit execution: `GW-DoNotCommit: true` runs the request without committing (documented as endpoint warm-up). - Pagination: `pageSize` (default 25, max 100), `pageOffset` (zero-indexed, root resources only), `includeTotal=true` adds a `total`. Follow the returned `first`/`prev`/`next`/`self` links. - Other query parameters: `fields`, `filter`, `sort`, `asOfDate`, `include`, `includeLocalizations`. - Strictness: unknown payload properties and unknown query parameters are REJECTED by default (`GW-UnknownPropertyHandling` / `GW-UnknownQueryParamHandling` = log | reject | ignore). - Async: `Prefer: respond-async`, optionally `respond-async, wait=T` or `wait-ms=T`; collect from `/async/v1`. - Tracing: `X-Correlation-ID`. - Errors: HTTP status plus a fully-qualified Guidewire exception class name. NOT RFC 9457 problem+json. - Versioning: major version in the path (`/claim/v1`); minor releases are additive; a new major version is published alongside the old one. The definition of a breaking change lives in Guidewire's Schema Backwards Compatibility Contract, which is customer-only. - Rate limits: not published. Throttling is set per tenant by the Guidewire Cloud subscription. ## Reversibility - `POST /claim/v1/claims/{claimId}/cancel` cancels a DRAFT claim and removes it from the database. Once a claim is submitted it can be closed but no longer cancelled. - `DELETE /claim/v1/claims/{claimId}/checks/{checkId}` deletes a claim check, but not once the check has been escalated. There is no check-set-level delete. - There is no documented undo for a committed PATCH. ## Developer surface - Developer hub: https://www.guidewire.com/developers - APIs overview: https://www.guidewire.com/developers/apis - Cloud APIs: https://www.guidewire.com/developers/apis/cloud-apis - InsuranceNow API: https://www.guidewire.com/developers/apis/insurancenow-apis - REST API Client (outbound HTTP from InsuranceSuite): https://www.guidewire.com/developers/apis/rest-api-client - Documentation: https://docs.guidewire.com/ - Marketplace: https://marketplace.guidewire.com/ - Community and support: https://community.guidewire.com/ - Status: https://status.guidewire.com/ - Blog: https://www.guidewire.com/resources/blog - Open source: https://github.com/guidewire-oss and https://github.com/Guidewire ## Security and compliance - Vulnerability disclosure: https://www.guidewire.com/contact-us/vulnerability-disclosure-policy/ — report to psirt@guidewire.com with a CVSS 3.0 score and proof of concept. No bug bounty is offered. - Trust profile: https://trust.guidewire.com/ - Security documentation: https://docs.guidewire.com/security/ - Named certifications: SOC 1 Type 2, SOC 2 Type 2, ISO/IEC 27001, ISO/IEC 27701, PCI DSS. The reports themselves require a Guidewire Community login. - No RFC 9116 security.txt is served on any Guidewire host. (status.guidewire.com serves one, but it is Atlassian's — the host is an Atlassian Statuspage instance.) ## Commercial Access is enterprise-only: Cloud API ships as part of a Guidewire Cloud / InsuranceSuite subscription. There is no public pricing page, no self-serve API key and no public sandbox. Contact: https://www.guidewire.com/about/get-in-touch/contact-us ## Release train Every four months, named per release: Qusar 2026.07, Palisades 2026.03, Olos 2025.11, Niseko 2025.07, Mammoth 2025.03, Las Leñas 2024.11. https://www.guidewire.com/products/technology/guidewire-cloud-platform-releases