# Hiscox > Hiscox Ltd is a diversified international specialist insurance and reinsurance group with roots in the Lloyd's of London market dating to 1901, domiciled in Bermuda and listed on the London Stock Exchange (LSE:HSX), employing over 3,000 people across 14 countries. It underwrites through Hiscox Retail (small business, professional and specialty personal lines in the UK, Europe, Asia and the USA), Hiscox London Market (larger specialty risks written out of Lloyd's Syndicate 33), and Hiscox Re & ILS. Hiscox's API posture is partner-gated: a real first-party developer portal exists at developer.hiscox.com, but every reference document, sandbox credential and OpenAPI/Swagger file sits behind a login that is issued only after a Hiscox Partnership Manager approves a commercial partnership. Generated by API Evangelist (https://apievangelist.com) on 2026-07-25 from the public Hiscox developer portal, Hiscox Group press releases and live host probes. Nothing here is fabricated; where Hiscox publishes nothing, that absence is stated. ## How access works - There is no self-serve signup. Approval by a Hiscox Partnership Manager comes first; an account granting immediate access to the SDBX sandbox is created after approval. - Contact for partner onboarding: hiscox.partneroperations@hiscox.com (developer portal Support page) and partnercontact@hiscox.com (API Terms of Use). - Authentication is OAuth 2.0 plus a partner-issued API key. TLS 1.2 is required and is the only TLS version supported for both SDBX and Production. - All Hiscox APIs are REST. Both XML and JSON request/response formats are supported. - Standing maintenance window: every Monday and Thursday, 15:00-18:00 ET. ## APIs - [Hiscox Eligibility API](https://developer.hiscox.com/apis): Returns the list of US states and the Hiscox products offered by profession, used to establish whether a risk can be quoted. Status Active. Partner-gated. - [Hiscox Quote API v4](https://developer.hiscox.com/apis): Returns a competitive general liability, professional liability, business owner's policy (BOP) and/or cyber quote for purchase via partner portals or APIs. Status Active. Partner-gated. - [Hiscox Setup Payment API](https://developer.hiscox.com/apis): Initiates the Hiscox policy payment process, completing the quote-to-buy flow for partner-distributed small business policies. Status Active. Partner-gated. - [Hiscox Cargo API](https://www.hiscoxgroup.com/news/press-releases/2025/30-06-25): Hiscox London Market solution for small cargo and stock throughput risks, launched 30 June 2025. Near-instant quote and bind within underwriting appetite, US$5m limit, 100% Hiscox Syndicate 33 security, risk models and software coded in-house. Distributed through broker partners (Price Forbes first); not listed on the developer portal and no public documentation exists. ## Docs - [Hiscox Developer Portal](https://developer.hiscox.com/) - [API catalog](https://developer.hiscox.com/apis) - public listing of names, one-line descriptions and status only - [Documentation](https://developer.hiscox.com/documentation) - login wall - [FAQ](https://developer.hiscox.com/frequently-asked-questions) - the only public source for authentication, TLS, sandbox and format policy - [Support / Partner With Us](https://developer.hiscox.com/support) - [API Terms of Use](https://developer.hiscox.com/terms-use) - [Privacy policy](https://www.hiscox.com/privacy-policy) ## Specs No OpenAPI, Swagger, AsyncAPI, GraphQL SDL or Protobuf definition is publicly retrievable. Hiscox confirms the specifications exist - the FAQ lists "a complete listing of our APIs and access to the OpenAPI spec Swagger" as SDBX functionality - but they are issued only to approved partners. Every unauthenticated spec path probed on developer.hiscox.com and on the api.hiscox.com gateway returned HTTP 404. ## Artifacts in this repo - [apis.yml](https://raw.githubusercontent.com/api-evangelist/hiscox/refs/heads/main/apis.yml) - APIs.json 0.19 index - [authentication/hiscox-authentication.yml](https://raw.githubusercontent.com/api-evangelist/hiscox/refs/heads/main/authentication/hiscox-authentication.yml) - OAuth 2.0 + API key profile, searched from the FAQ and Terms - [conventions/hiscox-conventions.yml](https://raw.githubusercontent.com/api-evangelist/hiscox/refs/heads/main/conventions/hiscox-conventions.yml) - REST, XML/JSON, TLS floor, Apigee gateway, and what is not published - [sandbox/hiscox-sandbox.yml](https://raw.githubusercontent.com/api-evangelist/hiscox/refs/heads/main/sandbox/hiscox-sandbox.yml) - the SDBX environment, access path and maintenance window - [lifecycle/hiscox-lifecycle.yml](https://raw.githubusercontent.com/api-evangelist/hiscox/refs/heads/main/lifecycle/hiscox-lifecycle.yml) - versioning, the no-notice change clause, warranty disclaimers and dated API milestones - [conformance/hiscox-conformance.yml](https://raw.githubusercontent.com/api-evangelist/hiscox/refs/heads/main/conformance/hiscox-conformance.yml) - web-standards conformance plus the ACORD and Cyber Essentials Plus footprint - [security/hiscox-domain-security.yml](https://raw.githubusercontent.com/api-evangelist/hiscox/refs/heads/main/security/hiscox-domain-security.yml) - TLS/HSTS/DNS posture across five hosts and three domains - [packages/hiscox-packages.yml](https://raw.githubusercontent.com/api-evangelist/hiscox/refs/heads/main/packages/hiscox-packages.yml) - zero first-party SDKs, with the registries probed - [well-known/hiscox-well-known.yml](https://raw.githubusercontent.com/api-evangelist/hiscox/refs/heads/main/well-known/hiscox-well-known.yml) - the empty /.well-known/ surface, recorded with statuses - [review.yml](https://raw.githubusercontent.com/api-evangelist/hiscox/refs/heads/main/review.yml) - the full API Evangelist review with every probe and status code ## Standards footprint Hiscox's most concrete open-standards footprint is ACORD rather than REST. On 3 July 2025 ACORD and Howden announced that ACORD Standards for digital accounting and invoicing went live in the UK retail insurance market, with Hiscox as the receiving insurer responding in real time to Howden's digital invoices through the ACORD Solutions Group ADEPT (ACORD Data Exchange Platform & Translator) receiver portal, which supports both XML and JSON messaging. The Hiscox UK broker extranet (launched March 2023) integrates into brokers' Acturis back office. Neither surface is developer-accessible. ## Not published No public base URL. No OAuth scope reference. No error/problem-details catalog. No rate limits. No idempotency contract. No status page. No changelog or release notes. No deprecation policy or SLA. No webhooks, events or AsyncAPI. No GraphQL. No MCP server. No SDKs, CLI or embedded components. No first-party Postman workspace. No security.txt, bug bounty or coordinated vulnerability disclosure programme. No /.well-known/ documents of any kind.