# Origami Risk > Origami Risk is a Chicago-headquartered risk, safety and insurance SaaS company (founded 2009) whose single-version cloud platform runs policy administration, digital underwriting, rating, billing, premium audit, claims administration, compliance and EHS/GRC for US property-and-casualty carriers, MGAs, program administrators, TPAs, risk pools, brokers, healthcare systems and large self-insureds. It publishes a genuinely public, self-serve developer portal at developers.origamirisk.com covering roughly 180 REST operations across quoting, rating, binding, policy issue/endorse/cancel, billing and payments, claims-from-incident (FNOL), domain metadata, files, reports and inbound webhooks. Generated by API Evangelist from the public Origami Risk developer portal and the repository artifacts in api-evangelist/origami-risk. No llms.txt is published by Origami Risk (probed 2026-07-25, 404). ## Key facts - Base URL is per-tenant and per-environment: `https://{environment}.origamirisk.com/OrigamiApi` (and `/OrigamiApi-v2`). There is no shared public API host; `api.origamirisk.com` does not resolve. - Environments: `preprod`, `staging`, `live` (US); `staging-gov`, `live-gov` (US Government); `staging`, `live` on `origamiriskeu.com` (EU). - Authentication: request a token (`POST /Authentication/Authenticate` simple format, or `POST /Authentication/AuthenticateOAuth` client_credentials format), then send it in a `Token` header. Optional HMAC-SHA1 per-call signing via `x-api-key` / `x-api-date` / `x-api-signature`. No OAuth scopes, no OIDC discovery. - Documentation is open; credentials are not — a provisioned Origami account, client and API user are required. - Limits: 100 records per query page, 25 records per bulk insert/upsert, 10 MB max request body, 10,000 character max URL. Read them at runtime from `GET /AccountInformation/Limits`. - A 200 response can carry validation or rating errors. Always inspect the body. - No idempotency-key contract; no ACORD/AL3/NGDS/IVANS conformance claim; no AsyncAPI; no first-party SDK or CLI. ## Developer surfaces - [Developer portal](https://developers.origamirisk.com/): ReadMe-hosted, publicly readable, currently in Beta. - [Guides](https://developers.origamirisk.com/docs): getting started, setting the {environment} value, max URL limits, max request payload size, beta notification. - [API reference](https://developers.origamirisk.com/reference): full operation-by-operation reference. - [Getting started](https://developers.origamirisk.com/docs/getting-started) - [Authentication methods](https://developers.origamirisk.com/reference/authentication-methods) - [HMAC authorization](https://developers.origamirisk.com/reference/hmac-authorization) - [Limits](https://developers.origamirisk.com/reference/limits) - [Product releases](https://www.origamirisk.com/platform/product-updates/): seasonal release train (Summer 2026, Spring 2026, Winter 2025). - [Service Level Agreement](https://www.origamirisk.com/serviceterms/sla/): 99.9% availability, service credits, backup regime. - [Status page](https://status.origamirisk.com/): client-authenticated. - [Trust center](https://trust.origamirisk.com/): Vanta-hosted. ## APIs - [Authentication API](https://developers.origamirisk.com/reference/authentication-methods): token issuance, token-expiry check, availability ping, HMAC signing. - [Public / core platform API](https://developers.origamirisk.com/reference/domains-entities): generic domain CRUD, upsert, bulk insert/upsert, metadata and data dictionary, screen configuration, notes, emails, files, links, mail merge, filter validation. - [Quotes and Proposals API](https://developers.origamirisk.com/reference/quotes-and-proposals): create/patch proposals, policy lines, coverages, schedules, validations, rating (run/queue/status), billing options, bind (sync/queue/status). - [Policies API](https://developers.origamirisk.com/reference/policies): accept, reject, undo-accept/reject/binding, endorse, cancel, reinstate, change billing frequency, take payment. - [Billing and Payments API](https://developers.origamirisk.com/reference/billing-accounts): log and reverse billing payments; online policy payment with the One Inc gateway. - [Actions API](https://developers.origamirisk.com/reference/actions): realtime CreateClaimFromIncident plus ~27 queued actions (FirstReport, Reserve, Review, RootCause, EDIReport, AuditResponse, Email, Fax, SMS, MailMerge, Note, Report, Task, User and more). - [Reports API](https://developers.origamirisk.com/reference/reports): report options, configuration, run-and-email, filter validation, filter string ↔ JSON tree conversion. - [Webhooks API](https://developers.origamirisk.com/reference/webhooks): list handlers, get a handler's request/response sample, post a payload to a named handler. Inbound only. - [Standard Rating API](https://developers.origamirisk.com/reference): standalone rating service — sync/async request submission, retrieval and cancellation. ## Specs - openapi/origami-risk-standard-rating-api-openapi.json — the only substantive published definition (sync/async rating, full DTO + ProblemDetails schemas). - openapi/origami-risk-public-api-openapi.json — scaffold (4 paths, ReadMe designer placeholders). - openapi/origami-risk-authentication-openapi.json — scaffold (3 paths). - openapi/origami-risk-rating-api-openapi.json — scaffold (1 placeholder path). ## API Evangelist artifacts - authentication/origami-risk-authentication.yml — token formats, HMAC signing contract, credential provisioning. - conventions/origami-risk-conventions.yml — versioning, pagination, bulk caps, async patterns, error semantics. - rate-limits/origami-risk-rate-limits.yml — published size/result-set limits and the runtime limits endpoint. - errors/origami-risk-problem-types.yml — ProblemDetails responses plus the 200-with-errors pattern. - lifecycle/origami-risk-lifecycle.yml — versioning, deprecations, SLA, status page, release train. - changelog/origami-risk-changelog.yml — seasonal product releases. - sandbox/origami-risk-sandbox.yml — the environment matrix and its EU caveat. - asyncapi/origami-risk-webhooks.yml — the inbound webhook surface and One Inc callbacks. - conformance/origami-risk-conformance.yml — standards conformance, including the ACORD negative. - data-model/origami-risk-data-model.yml — entity graph and runtime metadata discovery. - mcp/origami-risk-mcp.yml — candidate MCP tool list (no official server exists). - skills/ — packaged agent skills for the quote-to-issue, FNOL and reporting flows. - security/origami-risk-domain-security.yml, security/origami-risk-trust-center.yml. - packages/origami-risk-packages.yml — records that no first-party SDK exists.