# Honey Insurance > Australian direct-to-consumer insurtech selling smart home, contents, renters and landlord > insurance. Honey Insurance Pty Ltd (ABN 52 643 672 628, AFSL 528244) distributes and > administers the policies; they are underwritten by RACQ Insurance Limited (ABN 50 009 704 152, > AFSL 233082), an APRA-authorised general insurer. Honey publishes **no public API**: no > developer portal, no API reference, no OpenAPI/Swagger definition, no GraphQL schema, no > webhook or event catalogue, no Postman collection and no SDKs. Quote, bind, issue and FNOL > exist only as consumer web and telephone journeys. Generated by API Evangelist from apis.yml and the artifacts in this repository. Method: generated (no /llms.txt is published at honeyinsurance.com — HTTP 404 on 2026-07-25). ## Integration posture - **There is no public API.** Do not attempt to construct requests against Honey Insurance. - `https://api.honeyinsurance.com` resolves and is real, but it is a private AWS API Gateway serving Honey's own quote funnel and account app. Every anonymous path returns `HTTP 403 {"message":"Forbidden"}` — including `/`, `/openapi.json`, `/openapi.yaml`, `/swagger.json`, `/v1/openapi.json`, `/api-docs`, `/docs`, `/redoc`, `/graphql`, `/mcp` and `/.well-known/*`. It is not documented for third parties and must not be treated as an API. - `developer.honeyinsurance.com`, `developers.honeyinsurance.com`, `docs.honeyinsurance.com`, `partners.honeyinsurance.com`, `portal.honeyinsurance.com`, `broker(s).honeyinsurance.com`, `agent(s).honeyinsurance.com`, `sandbox.honeyinsurance.com` and `status.honeyinsurance.com` do not resolve (NXDOMAIN). `/developers`, `/developer`, `/api`, `/partners` and `/integrations` return HTTP 404 on the website. - The published sitemap (80 URLs) contains no developer, API or partner-portal page. - No ACORD, AL3, ACORD XML or NGDS footprint. Australia's Consumer Data Right was designated to extend to general insurance and then deferred, so there is no open-insurance obligation. ## Identity (the only standards-based surface) - [OpenID Connect discovery](https://auth.honeyinsurance.com/.well-known/openid-configuration): Auth0 custom-domain tenant, issuer `https://auth.honeyinsurance.com/`. - [OAuth 2.0 authorization server metadata](https://auth.honeyinsurance.com/.well-known/oauth-authorization-server) (RFC 8414) - [JWKS](https://auth.honeyinsurance.com/.well-known/jwks.json) (RFC 7517) - Audience is **consumer "My account" sign-in only**. The advertised scopes are the stock Auth0 OIDC profile claims (openid, profile, offline_access, name, given_name, family_name, nickname, email, email_verified, picture, created_at, identities, phone, address). There are no insurance-domain scopes, no published API audience and no developer credential path. ## Insurance verbs (all human-channel, none API) - Quote and bind: https://www.honeyinsurance.com/get-a-quote/start (homeowners, landlord, renters) - Issue and policy documents: https://www.honeyinsurance.com/my-account - FNOL / claims: https://www.honeyinsurance.com/claims/, https://www.honeyinsurance.com/my-account/claims, phone 137 138 (24/7), contact@honeyinsurance.com ## Consumer surfaces - [Website](https://www.honeyinsurance.com/) - [Homeowners](https://www.honeyinsurance.com/homeowners/) - [Landlords](https://www.honeyinsurance.com/landlords/) - [Renters](https://www.honeyinsurance.com/renters/) - [Smarter home (sensor program)](https://www.honeyinsurance.com/smarter-home/) - [Honey Help](https://www.honeyinsurance.com/honey-help/) - [FAQ](https://www.honeyinsurance.com/faq/) - [Glossary](https://www.honeyinsurance.com/glossary/) - [Documents](https://www.honeyinsurance.com/documents/) - [Emergency contacts](https://www.honeyinsurance.com/emergency-contacts/) - [Complaints and feedback](https://www.honeyinsurance.com/complaints-and-feedback/) — escalates to AFCA - [Blog](https://www.honeyinsurance.com/blog/) - [Newsroom](https://www.honeyinsurance.com/media-centre/newsroom/) - [Brand assets](https://www.honeyinsurance.com/media-centre/brand-assets/) - [Careers](https://www.honeyinsurance.com/join-the-team/) - [Terms](https://www.honeyinsurance.com/terms/) - [Privacy](https://www.honeyinsurance.com/privacy/) - [Whistleblower policy](https://www.honeyinsurance.com/whistleblower-policy/) ## API Evangelist artifacts in this repository - apis.yml — APIs.json 0.19 provider record - review.yml — full 2026-07-25 probe log and findings - well-known/honey-insurance-well-known.yml — /.well-known/ index (+ the three verbatim Auth0 documents) - authentication/honey-insurance-authentication.yml — the OIDC/OAuth profile and its gaps - scopes/honey-insurance-scopes.yml — the advertised scopes (no insurance-domain scope exists) - conformance/honey-insurance-conformance.yml — standards conformance, asserted with evidence - lifecycle/honey-insurance-lifecycle.yml — versioning, deprecation, SLA and status page (all absent) - packages/honey-insurance-packages.yml — registry sweep, no first-party client library - security/honey-insurance-domain-security.yml — TLS/HSTS/DNSSEC/CAA/SPF/DMARC probe ## Not published No OpenAPI. No AsyncAPI. No GraphQL SDL. No gRPC/protobuf. No MCP server. No webhooks. No Postman collection. No SDKs or CLI. No sandbox or test credentials. No status page. No API changelog. No security.txt, vulnerability disclosure programme or trust center. No published certifications (SOC 2, ISO 27001, PCI DSS).