# Lloyd's of London > The world's specialist insurance and reinsurance market, operating as a regulated marketplace rather than a carrier. Lloyd's is a standards and market-infrastructure publisher first: its technical surface is aimed at brokers, syndicates, coverholders and market vendors, not at outside developers. There is no public self-serve API, no public sandbox and no downloadable specification reachable today. Everything below is either a live probe result or a verbatim capture of documentation Lloyd's published on the retired developer.lloyds.com portal. Generated by the API Evangelist enrichment pipeline on 2026-07-25. Method: generated from apis.yml plus the artifacts in this repository (https://www.lloyds.com/llms.txt returns 200 with an empty body - Lloyd's publishes no llms.txt). ## What is actually live - [Lloyd's Catastrophe Codes API v1 - health](https://api.londonmarketgroup.co.uk/Lloyds/CatastropheCodes/v1/health): 200 anonymously, on Production and Sandbox. The only Lloyd's API surface an unonboarded developer can call. - [Catastrophe Codes data resource](https://api.londonmarketgroup.co.uk/Lloyds/CatastropheCodes/v1/CatastropheCodes): 401 `{"Code":401,"Message":"Client certificate is missing."}` - the mutual-TLS gate is live and enforcing. - [OIDC discovery, Production](https://api.londonmarketgroup.co.uk/discovery/.well-known/openid-configuration): 200. Mandated by section 5.12.2 of the Lloyd's Base API Standard. Also live on preprod-api and sand-api. - [JWKS, Production](https://api.londonmarketgroup.co.uk/discovery/keys): 200 RSA key set. - [security.txt](https://www.lloyds.com/.well-known/security.txt): 200, RFC 9116, Contact securityreporting@lloyds.com. - [Responsible Disclosure hall of fame](https://www.lloyds.com/security-reports): 200. ## What is retired - The Lloyd's API Development Portal (developer.lloyds.com), launched BETA on 2020-06-08 under the "API Factory" programme. HTTPS times out; HTTP 301s to www.lloyds.com. Last archived 200: 2022-01-25. - The Placing API endpoints. Both the documented base path `/PPL/Lloyds/Placing/V1` and the example path `/Lloyds/Placing/v1` return 404 on the Production and Sandbox gateways. - The published Swagger/OpenAPI 3.0 file for Placing v1.10. Its host no longer resolves and it was never captured by the Internet Archive. Nothing was reconstructed. ## APIs - [Lloyd's Placing API - Submission and Quote v1](https://web.archive.org/web/20210128061829/https://developer.lloyds.com/placingsubmissionandquote-v1/Key-Details-On-API): electronic placement for the London subscription market - submissions, MRC/quote documents, carriers and underwriters, requests for quote and underwriter responses. Endpoint version 1.10, base `https://api.londonmarketgroup.co.uk/PPL/Lloyds/Placing/V1`. Partner-gated; endpoints no longer routed. - [Lloyd's Placing API - Firm Order](https://web.archive.org/web/20200610082013/https://developer.lloyds.com/Explore-Innovate): "Finalise Placings, Bind Risks, Sign Transactions" - the BIND verb. Catalogue entry only. - [Lloyd's RPAC API](https://web.archive.org/web/20200610082013/https://developer.lloyds.com/Explore-Innovate): risk, premium and claims reporting for delegated authority placements. Catalogue entry only. - Lloyd's Catastrophe Codes API v1: catastrophe event reference data, base `https://api.londonmarketgroup.co.uk/Lloyds/CatastropheCodes/v1`, sandbox `https://sand-api.londonmarketgroup.co.uk/Lloyds/CatastropheCodes/v1`. Live. ## Standards Lloyd's publishes - [Requirements and Standards](https://www.lloyds.com/market-resources/requirements-and-standards): the primary technical corpus Lloyd's publishes to its market. - [Core Data Record (CDR v3.2)](https://www.lloyds.com/market-resources/requirements-and-standards/core-data-record): the market's standard transactional data set for premium validation and settlement, claims matching at first notification of loss, tax and regulatory reporting. Aligned to ACORD technical standards and to MRC v3. - [Coverholder and Delegated Claims Reporting Standards](https://www.lloyds.com/market-resources/delegated-authorities/market-knowledge/reporting-standards): mandated core reporting data set for binding authority and coverholder agreements. - [ACORD membership for all coverholders](https://www.lloyds.com/insights/news/lloyds-provides-acord-membership-for-all-coverholders): Lloyd's funds free custom ACORD membership, giving coverholders the ACORD Delegated Authority Data Standards. - [Lloyd's Base API Standard](https://web.archive.org/web/20200930095802/https://developer.lloyds.com/Get-Started/Base-API-Standard): the normative RFC 2119 standard every API published to the market by a Lloyd's system must obey. Captured as `conventions/lloyds-of-london-conventions.yml`. ## Artifacts in this repository - [apis.yml](apis.yml): the APIs.json 0.19 index for this provider. - [conventions/lloyds-of-london-conventions.yml](conventions/lloyds-of-london-conventions.yml): the Base API Standard as structured data - resource model, `_pageSize`/`_pageNum` paging (max 200), `_order`/`_last_modified` ordering, `_select` field culling, `_expand` expansion, filter grammar with `!` negation, `{items,total,_links}` collection envelope, `{Message,Code}` error envelope, If-Match / If-Unmodified-Since concurrency, Major.Minor versioning, `/health` and `/version` meta resources. No idempotency mechanism exists. - [authentication/lloyds-of-london-authentication.yml](authentication/lloyds-of-london-authentication.yml): dual credential model - client X.509 certificate on mutual TLS plus an Azure AD on-behalf-of JWT carrying `scp=user_impersonation`. - [scopes/lloyds-of-london-scopes.yml](scopes/lloyds-of-london-scopes.yml): the single scope, `user_impersonation`, and the JWT claims authorisation is actually done from. - [errors/lloyds-of-london-error-codes.yml](errors/lloyds-of-london-error-codes.yml): 107 named Placing API error codes plus the HTTP status mapping rules from the Base API Standard. - [examples/_index.yml](examples/_index.yml): 22 request/response payload examples published verbatim by Lloyd's. - [data-model/lloyds-of-london-data-model.yml](data-model/lloyds-of-london-data-model.yml): the entity graph - BrokerDepartment, Submission, SubmissionDocument, SubmissionUnderwriter, SubmissionDialogue, UnderwriterOrganisation, CatastropheCode - and the composite business-key identity convention. - [lifecycle/lloyds-of-london-lifecycle.yml](lifecycle/lloyds-of-london-lifecycle.yml): Major.Minor compatibility policy with the itemised allowed/disallowed change table, release channels, and what has been retired. - [changelog/lloyds-of-london-changelog.yml](changelog/lloyds-of-london-changelog.yml): the Placing v1.10 release notes. - [sandbox/lloyds-of-london-sandbox.yml](sandbox/lloyds-of-london-sandbox.yml): the three-environment estate and the LIMOSS onboarding path to reach it. - [conformance/lloyds-of-london-conformance.yml](conformance/lloyds-of-london-conformance.yml): standards conformance, including the deliberate absences (no AsyncAPI, no webhooks, no SOAP - all explicitly out of scope of the Base API Standard). - [well-known/lloyds-of-london-well-known.yml](well-known/lloyds-of-london-well-known.yml): the harvested discovery surface across five hosts. - [security/lloyds-of-london-vulnerability-disclosure.yml](security/lloyds-of-london-vulnerability-disclosure.yml), [security/lloyds-of-london-domain-security.yml](security/lloyds-of-london-domain-security.yml): the disclosure programme and the probed TLS/DNS posture. - [review.yml](review.yml): the full API Evangelist provider review. ## How to get access Access is never self-serve. An organisation must (1) onboard to LIMOSS Common Services / the LIMOSS API Gateway, (2) be guested into each environment separately - Sandbox, PreProd and Production are isolated, (3) register its application in the Common Services Azure Active Directory, and (4) register a different X.509 certificate per environment. Test broker and underwriter organisations are provisioned on request by the Lloyd's API Factory. - API Factory (licences, test harnesses, API standards, design issues): developer@lloyds.com - Placing API adoption on the PPL platform: PPLEnquiries@lloyds.com - LIMOSS onboarding and service SLA: https://limoss.london/ ## Notes for agents - There is no MCP server, no GraphQL endpoint, no gRPC surface, no webhook catalogue and no AsyncAPI document. Publish-subscribe and message-originated interfaces are explicitly out of scope of the Lloyd's Base API Standard; events are modelled as pollable resource collections. The absence is by design. - There is no rate-limit contract and no idempotency-key mechanism. - Errors are NOT RFC 9457 problem+json. The envelope is `{"Message": "...", "Code": }` and gateway errors embed a `Ref: ` correlation token in the message. - No OpenAPI is reachable for any Lloyd's API. Do not assume one exists behind the gate.