# Marshmallow > Marshmallow is a London-headquartered UK insurtech (founded 2017) that prices motor, van and home > insurance for people who have recently moved to the United Kingdom, using global rather than only > national driving history. It owns the whole value chain: distribution via Marshmallow Financial > Services Limited (FCA FRN 797672), car finance via Marshmallow Credit Services Limited (FCA FRN > 1024606), and underwriting via Marshmallow Insurance Limited, an authorised insurance undertaking > regulated by the Gibraltar Financial Services Commission. Marshmallow publishes NO public, > self-serve API: there is no developer portal, no OpenAPI, no SDK, no sandbox and no webhook > catalogue. Its APIs are real but entirely internal and partner-gated. Generated by API Evangelist from the apis.yml catalog entry and the artifacts harvested in this repository. Provenance: generated (no provider-published llms.txt exists — https://www.marshmallow.com/llms.txt returns 404). ## API posture - [Review findings](https://raw.githubusercontent.com/api-evangelist/marshmallow/refs/heads/main/review.yml): full probe log — every developer entry point tested on 2026-07-25. - No public API. `api.marshmallow.com` (403) and `docs.marshmallow.com` (403) exist but block anonymous callers; `developer.`/`developers.`/`sandbox.`/`partners.`/`status.`/`trust.` do not resolve. - No OpenAPI, Swagger, GraphQL SDL, AsyncAPI, Protobuf, Postman workspace, MCP server or webhook catalogue was found on any host. - None of the four insurance verbs — quote, bind, issue, FNOL — is exposed to third parties; all four are consumer web and app journeys served by Marshmallow's private API. - No ACORD, AL3, ACORD XML or NGDS reference appears on any public Marshmallow property. ## Authentication (the one machine-readable surface) - [OpenID Connect discovery](https://auth.marshmallow.com/.well-known/openid-configuration): the only anonymously reachable machine-readable document Marshmallow serves. - [Harvested copy](https://raw.githubusercontent.com/api-evangelist/marshmallow/refs/heads/main/well-known/marshmallow-openid-configuration.json) - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/marshmallow/refs/heads/main/authentication/marshmallow-authentication.yml): grants (authorization_code, client_credentials, refresh_token, token-exchange), PKCE S256, mTLS client auth, certificate-bound access tokens, DPoP. - [OAuth scopes](https://raw.githubusercontent.com/api-evangelist/marshmallow/refs/heads/main/scopes/marshmallow-scopes.yml): only `openid` is published; no product scopes, no dynamic client registration. ## Artifacts in this repository - [apis.yml](https://raw.githubusercontent.com/api-evangelist/marshmallow/refs/heads/main/apis.yml) - [Well-known index](https://raw.githubusercontent.com/api-evangelist/marshmallow/refs/heads/main/well-known/marshmallow-well-known.yml) - [Conformance](https://raw.githubusercontent.com/api-evangelist/marshmallow/refs/heads/main/conformance/marshmallow-conformance.yml) - [Domain security](https://raw.githubusercontent.com/api-evangelist/marshmallow/refs/heads/main/security/marshmallow-domain-security.yml) - [Packages](https://raw.githubusercontent.com/api-evangelist/marshmallow/refs/heads/main/packages/marshmallow-packages.yml) - [Components](https://raw.githubusercontent.com/api-evangelist/marshmallow/refs/heads/main/components/marshmallow-components.yml) ## Open source - [marshmallow-insurance on GitHub](https://github.com/marshmallow-insurance): four public repositories, all front-end. - [@mrshmllw/smores-react](https://www.npmjs.com/package/@mrshmllw/smores-react): React design system. - [@mrshmllw/smores-foundations](https://www.npmjs.com/package/@mrshmllw/smores-foundations): design tokens. - [@mrshmllw/campfire](https://www.npmjs.com/package/@mrshmllw/campfire): shared front-end utilities. ## Company - [Website](https://www.marshmallow.com/) - [Our story](https://www.marshmallow.com/our-story) - [Blog](https://www.marshmallow.com/blog) - [Help centre](https://www.marshmallow.com/help) - [Claims](https://www.marshmallow.com/claims) - [Customer account](https://account.marshmallow.com/) - [Terms and conditions](https://www.marshmallow.com/terms-and-conditions) - [Privacy policy](https://www.marshmallow.com/privacy-policy) - [Complaints policy](https://www.marshmallow.com/complaints-policy) - [Solvency and Financial Condition Report](https://www.marshmallow.com/solvency-and-financial-condition-report) ## Disambiguation The Python `marshmallow` object serialization/validation library (github.com/marshmallow-code) is a different project entirely and has no relationship to Marshmallow the UK insurer.