openapi: 3.2.0 info: title: Ki Broker Trading Platform API (observed) Facilities API version: '2026-07-25' summary: Observed HTTP surface of Ki's partner-gated broker trading platform. description: '**This is an API Evangelist DERIVED specification, not a Ki-published document.** Ki (Lloyd''s Syndicate 1618) publishes no developer portal, no API reference and no OpenAPI. This document was derived on 2026-07-25 from the endpoint registry that Ki''s own broker platform ships in its public JavaScript bundle at `https://app.ki-insurance.com/assets/index-DgeF7w2c.js`. Every path and every HTTP method below was observed verbatim in that bundle, together with the request helpers (`GET`/`POST`/`PUT`/`DELETE`) that call them. What is REAL here: path templates, HTTP methods, query-parameter names, the `Authorization: Bearer` scheme, the `application/json` content negotiation, and the 401/403/503 handling the client implements. What is NOT specified: request and response schemas. Ki does not publish them and they are left empty rather than invented. Path-parameter NAMES are assigned by API Evangelist because the minified bundle does not retain them. The API is partner-gated: access requires an Auth0 authorization-code login at `https://login.ki-insurance.com/` against audience `https://api.ki.com`. There is no self-serve signup.' contact: name: Ki Insurance url: https://ki-insurance.com/ x-apievangelist-derivation: method: derived source: https://app.ki-insurance.com/assets/index-DgeF7w2c.js observed: '2026-07-25' note: Not a provider-published specification. Do not treat as a Ki contract. x-observed-endpoints-unmapped: - path: /api/user/current/logout registry_key: user.logout note: endpoint observed in the client registry; HTTP method not determinable from the minified bundle - path: /api/quote/{p1}/sov registry_key: quote.uploadSov note: endpoint observed in the client registry; HTTP method not determinable from the minified bundle - path: /api/quote/{p1}/pdf/subjectivities registry_key: subjectivities note: endpoint observed in the client registry; HTTP method not determinable from the minified bundle - path: /api/umr/master-line-slip registry_key: uniqueMarketReference.masterLineSlip note: endpoint observed in the client registry; HTTP method not determinable from the minified bundle - path: /api/indications/consents registry_key: indicationsConsent.list note: endpoint observed in the client registry; HTTP method not determinable from the minified bundle - path: /api/indications/affirm registry_key: indicationsConsent.consent note: endpoint observed in the client registry; HTTP method not determinable from the minified bundle servers: - url: https://app.ki-insurance.com description: Ki broker trading platform (same-origin API; partner-gated) security: - auth0Bearer: [] tags: - name: Facilities paths: /api/facilities/attestations: get: operationId: getFacilityAttestations summary: Retrieve facility attestations description: Observed in the Ki broker platform client bundle as `facilityAttestations` -> `GET /api/facilities/attestations?facilityId=${e}&cobId=${t}`. Request and response schemas are not published by Ki and are deliberately left unspecified rather than invented. tags: - Facilities x-observed-registry-key: facilityAttestations x-observed-method-evidence: call-site proximity in the client bundle x-observed-confidence: medium responses: '200': description: Successful response. Ki does not publish the response schema. content: application/json: schema: {} '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '503': $ref: '#/components/responses/Maintenance' parameters: - name: facilityId in: query required: false schema: type: string description: Query parameter observed verbatim in the published client bundle. - name: cobId in: query required: false schema: type: string description: Query parameter observed verbatim in the published client bundle. /api/facilities/exclusion-clauses: get: operationId: getExclusionClausesList summary: List exclusion clauses for a class of business and facility description: Observed in the Ki broker platform client bundle as `exclusionClauses.list` -> `GET /api/facilities/exclusion-clauses?cobId=${e}&facilityId=${t}`. Request and response schemas are not published by Ki and are deliberately left unspecified rather than invented. tags: - Facilities x-observed-registry-key: exclusionClauses.list x-observed-method-evidence: call-site proximity in the client bundle x-observed-confidence: medium responses: '200': description: Successful response. Ki does not publish the response schema. content: application/json: schema: {} '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '503': $ref: '#/components/responses/Maintenance' parameters: - name: cobId in: query required: false schema: type: string description: Query parameter observed verbatim in the published client bundle. - name: facilityId in: query required: false schema: type: string description: Query parameter observed verbatim in the published client bundle. /api/facilities/lineslip-mappings: get: operationId: getFacilitiesLineslipMappings summary: List facility line-slip mappings description: Observed in the Ki broker platform client bundle as `facilities.lineslipMappings` -> `GET /api/facilities/lineslip-mappings`. Request and response schemas are not published by Ki and are deliberately left unspecified rather than invented. tags: - Facilities x-observed-registry-key: facilities.lineslipMappings x-observed-method-evidence: explicit GET helper call site x-observed-confidence: high responses: '200': description: Successful response. Ki does not publish the response schema. content: application/json: schema: {} '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '503': $ref: '#/components/responses/Maintenance' /api/facilities/triggerMarkets/{classOfBusinessId}: get: operationId: getSyndicateTrackerSyndicates summary: List tracker/trigger markets for a class of business description: Observed in the Ki broker platform client bundle as `syndicate.trackerSyndicates` -> `GET /api/facilities/triggerMarkets/${e}`. Request and response schemas are not published by Ki and are deliberately left unspecified rather than invented. tags: - Facilities x-observed-registry-key: syndicate.trackerSyndicates x-observed-method-evidence: explicit GET helper call site x-observed-confidence: high responses: '200': description: Successful response. Ki does not publish the response schema. content: application/json: schema: {} '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '503': $ref: '#/components/responses/Maintenance' parameters: - name: classOfBusinessId in: path required: true schema: type: string components: responses: Maintenance: description: Service unavailable. The client routes the user to the maintenance page. Forbidden: description: Forbidden. The client routes the user to the forbidden page. Unauthorized: description: Unauthorized. The client clears the session and returns the user to login. securitySchemes: auth0Bearer: type: http scheme: bearer bearerFormat: JWT description: 'Auth0-issued access token. The client attaches `Authorization: Bearer ` to every call. Issuer `https://login.ki-insurance.com/`, audience `https://api.ki.com`.' auth0OpenId: type: openIdConnect openIdConnectUrl: https://login.ki-insurance.com/.well-known/openid-configuration description: Auth0 OIDC discovery for the partner login (authorization code + PKCE).