# H&R Block > H&R Block (NYSE: HRB) is a US tax-preparation company and Fortune 1000 constituent, > operating retail offices, consumer and small-business tax software, and the MyBlock > digital platform. It has no public developer program. The only machine-readable contract > it serves on the open internet is the OAuth 2.0 / OpenID Connect discovery metadata for > its customer identity platform. This file was generated by API Evangelist on 2026-09-14 from probed evidence, not authored or endorsed by H&R Block. Every link below was fetched or probed on that date and carries the status it returned. ## What is actually callable - [OpenID Connect discovery](https://login.hrblock.com/.well-known/openid-configuration): 200, application/json. PingFederate authorization server, issuer `https://login.hrblock.com`. - [OAuth 2.0 authorization server metadata (RFC 8414)](https://login.hrblock.com/.well-known/oauth-authorization-server): 200, application/json. - [JWKS](https://login.hrblock.com/pf/JWKS): 200, 24 signing keys (RSA + EC). - Scopes advertised: `openid`, `profile`, `email`, `address`, `phone`, `hrbGuaid`, `hrbUcid`. - Grants advertised: authorization_code, implicit, refresh_token, password, client_credentials, device_code, token-exchange, jwt-bearer, saml2-bearer, CIBA. PKCE S256, PAR, DPoP and mutual-TLS client authentication are all advertised. ## What does not exist publicly - No OpenAPI, AsyncAPI, GraphQL SDL, WSDL, .proto or Postman collection is published anywhere. - `api.hrblock.com`, the base URL on record, does not resolve (NXDOMAIN). - `developer.hrblock.com`, `apiportal.hrblock.com` (an Apigee developer portal search engines have indexed), `apigw.hrblock.com`, `mcp.hrblock.com`, `edge.hrblock.com`, `services.hrblock.com` and `connect.hrblock.com` all resolve in public DNS but refuse or drop TCP on 80/443. H&R Block's API estate is internal/partner-network only. - No MCP server, no A2A agent card, no llms.txt of the company's own, no security.txt. - No first-party SDK on npm, PyPI or any other registry. - No API pricing, no published rate limits, no changelog, no SLA. The Statuspage.io tenant at hrblock.statuspage.io answers "Page Inactive". ## Security and disclosure - [Responsible Disclosure Policy](https://www.hrblock.com/responsible-disclosure-policy/): effective 2022-04-01, scope is all internet-accessible public-facing H&R Block systems, anonymous reports accepted, 90-day disclosure embargo requested. - [HackerOne program](https://hackerone.com/hrblock-bbp): handle `hrblock-bbp`, team "H&R Block Tax Group, Inc. BBP". Whether it pays bounties is not observable anonymously. ## Integration, for humans - [Tax import partners](https://www.hrblock.com/partners/tax-import-partners/) — the partner program through which financial institutions and payroll providers feed tax data into H&R Block products. This is the front door; access is by bilateral agreement, not self-serve. - [Support](https://www.hrblock.com/support/) - [Newsroom](https://www.hrblock.com/tax-center/newsroom/) Note: every `www.hrblock.com` URL above returns HTTP 403 from the Akamai edge to our crawler, for every path and every User-Agent. The pages demonstrably exist; our network is turned away. ## API Evangelist artifacts - [apis.yml](https://raw.githubusercontent.com/api-evangelist/hanr-block/refs/heads/main/apis.yml) - authentication/hanr-block-authentication.yml - scopes/hanr-block-scopes.yml - conformance/hanr-block-conformance.yml - well-known/hanr-block-well-known.yml - security/hanr-block-vulnerability-disclosure.yml - security/hanr-block-domain-security.yml - lifecycle/hanr-block-lifecycle.yml - packages/hanr-block-packages.yml