# Steadfast Group > Steadfast Group Limited (ASX:SDF) is the largest general insurance broker network and the largest group of insurance underwriting agencies in Australasia, headquartered in Sydney. It is a broker-intermediary, not a risk carrier: 414 independent brokerages placing roughly $12.7 billion in gross written premium, plus 31 underwriting agencies writing about 100 products. Its trading technology is the Steadfast Client Trading Platform (SCTP), being consolidated with the INSIGHT policy management platform into "Steadfast Apps". > API posture, recorded honestly: Steadfast Group publishes NO developer portal, NO API documentation and NO API specification. Exactly one public, anonymous API exists in the whole estate — the JSON API behind the consumer Flood Risk Tracker — and it is undocumented. Everything that matters commercially (quote, bind, issue, claims) sits behind a credentialed broker portal and a commercially arranged partner API host. The OpenAPI in this repository was DERIVED by API Evangelist from observed live traffic, not published by Steadfast. This file was generated by API Evangelist from the catalog record at https://github.com/api-evangelist/steadfast-group — Steadfast Group publishes no llms.txt (https://www.steadfast.com.au/llms.txt returns 404). ## APIs - [Steadfast Flood Risk Tracker API](https://floodrisktracker.steadfast.com.au/): Public, anonymous, read-only JSON API. Two GET operations: resolve an Australian address to a G-NAF identifier, then return Swiss Re river-flood and coastal storm-surge risk layers for it. No authentication, no documentation, no support commitment. - [Steadfast Identity (Okta OIDC)](https://idp.steadfast.com.au): OpenID Connect provider fronting the broker portal. Discovery is anonymously readable; credentials are issued commercially, not self-serve. - Steadfast Partner API host (https://api.steadfast.com.au): live but undocumented — HTTP 403 at the root, 404 on every documentation path, 503 on every /.well-known/ path. Not consumable. ## Specs - [Flood Risk Tracker OpenAPI 3.1 (derived)](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/openapi/steadfast-group-flood-risk-tracker-openapi.yml) - [OpenID Connect discovery document (verbatim)](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/well-known/steadfast-group-openid-configuration.json) - [OAuth 2.0 authorization server metadata (verbatim)](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/well-known/steadfast-group-oauth-authorization-server.json) - [OpenAPI Overlay of API Evangelist annotations](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/overlays/steadfast-group-flood-risk-tracker-overlay.yaml) ## Artifacts - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/authentication/steadfast-group-authentication.yml): anonymous for the public API; Okta OIDC with PKCE S256 and DPoP for everything else. - [OAuth scopes](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/scopes/steadfast-group-scopes.yml): the seven scopes advertised by the identity provider. - [API conventions](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/conventions/steadfast-group-conventions.yml): observed naming, identifiers, error envelope, versioning, CORS and data quirks. - [Error catalog](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/errors/steadfast-group-problem-types.yml): RFC 9457 problem details, plus the empty-array-not-404 convention. - [Data model](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/data-model/steadfast-group-data-model.yml): AddressCandidate and RiskLayer, joined by G-NAF identifier. - [Examples](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/examples/steadfast-group-flood-risk-tracker-examples.yml): verbatim live request/response pairs. - [Conformance](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/conformance/steadfast-group-conformance.yml): what the estate does and does not conform to, including the ACORD gap. - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/lifecycle/steadfast-group-lifecycle.yml): versioning, and the absence of a status page, changelog, roadmap, SLA and deprecation policy. - [Well-known index](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/well-known/steadfast-group-well-known.yml): every /.well-known/ probe across the estate with its HTTP status. - [Domain security](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/security/steadfast-group-domain-security.yml): TLS, HSTS, DNSSEC, CAA, SPF and DMARC posture. - [Candidate MCP tools](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/mcp/steadfast-group-mcp.yml) and [tool crosswalk](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/mcp/steadfast-group-tool-crosswalk.yml): no Steadfast MCP server exists; these describe what one would expose. - [Agent skill: flood risk lookup](https://raw.githubusercontent.com/api-evangelist/steadfast-group/refs/heads/main/skills/steadfast-group-flood-risk-lookup.md) ## Company - [Website](https://www.steadfast.com.au/) - [About Steadfast](https://www.steadfast.com.au/about-us/) - [Board and management](https://www.steadfast.com.au/about-us/board-and-management/) - [Investor centre](https://investor.steadfast.com.au/investor-centre/) - [Well Covered — news and media releases](https://www.steadfast.com.au/well-covered/) - [Find an insurance broker](https://www.steadfast.com.au/find-an-insurance-broker) - [Flood Risk Tracker](https://floodrisktracker.steadfast.com.au/) - [Steadfast Underwriting Agencies](https://steadfastagencies.com.au/) - [Steadfast Life](https://www.steadfastlife.com.au/) - [Steadfast New Zealand](https://www.steadfastnz.nz/) - [Steadfast Singapore](https://www.steadfast.com.sg/) - [Broker login (credentialed, not a developer portal)](https://broker.steadfast.com.au/) - [Privacy policy](https://www.steadfast.com.au/privacy-policy/) - [Legal](https://www.steadfast.com.au/legal/) - [Codes of practice](https://www.steadfast.com.au/codes-of-practice/) - [Contact](https://www.steadfast.com.au/contact-us/) ## Optional - No developer portal, no API documentation, no SDKs, no CLI, no Postman collection, no GitHub organisation, no status page, no changelog, no roadmap, no security.txt, no bug bounty and no trust centre exist for Steadfast Group. Every one of these was probed and confirmed absent on 2026-07-25. - Packages named "steadfast" on npm and PyPI belong to Steadfast Courier (Bangladesh) or unrelated projects — none is a Steadfast Group client library. - Governance signal without implementation: founder, Managing Director and CEO Robert B. Kelly AM chairs the ACORD Board in New York, yet no ACORD, AL3, ACORD XML or NGDS implementation detail appears anywhere on the public site. - Market context: Australia's Consumer Data Right was designated to extend to general insurance and then deferred, so no open-insurance mandate forces a broker network of this scale to publish an API.