# Vitality (UK) > Vitality is a United Kingdom health and life insurer — VitalityHealth and > VitalityLife under the Vitality umbrella brand, owned by the South African > financial services group Discovery Limited. It is the UK's third-largest > private medical insurer with roughly 1.9 million members and a shared-value > model that prices cover against member health and activity engagement. > Its API programme is real but PARTNER-GATED: there is a live production API > gateway and a fully published OpenID Connect identity layer, but no public > developer portal, no API reference and no machine-readable API contract. Generated by the API Evangelist enrichment pipeline on 2026-07-25 from live probes. Method: generated. Nothing below is inferred — every URL was fetched. ## What exists - [API gateway](https://apis.vitality.co.uk/): WSO2 API Manager, HTTP 200 with the default "Welcome to APIM" landing page. Origin wso2-prd-apigw.tvc.vitality.co.uk:8243 behind an AWS load balancer in eu-west-1. No API catalogue, no docs. - [OpenID Connect discovery](https://apis.vitality.co.uk/oauth2/token/.well-known/openid-configuration): complete, anonymous, HTTP 200. Also served at /oauth2/oidcdiscovery/.well-known/openid-configuration. - [JWKS](https://apis.vitality.co.uk/oauth2/jwks): one RS256 signing key. - [Authorization endpoint](https://apis.vitality.co.uk/oauth2/authorize) and [token endpoint](https://apis.vitality.co.uk/oauth2/token): live; the token endpoint returns 401 invalid_client to anonymous callers. - Additional edges: m.apis.vitality.co.uk (member/mobile), ah-login.apis.vitality.co.uk (adviser hub), eh-login.apis.vitality.co.uk (employer hub), plus pre/test/uat environments — all sharing the issuer https://apis.vitality.co.uk/oauth2/token. ## What does not exist - No OpenAPI, Swagger, AsyncAPI or .proto on any reachable host. - No developer portal: /devportal, /publisher, /store and the WSO2 devportal REST APIs all return the WSO2 404 fault document. - No self-serve signup. The dynamic client registration endpoint advertised in discovery is not reachable through the public gateway (404). Credentials come from commercial partner onboarding. - No webhooks, no event catalogue, no status page, no deprecation policy, no public Postman workspace, no public GitHub repositories, no ACORD posture. - No public quote, bind, issue or FNOL API. ## Artifacts in this repo - [apis.yml](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/apis.yml): the APIs.json index - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/authentication/vitality-uk-authentication.yml) - [OAuth scopes](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/scopes/vitality-uk-scopes.yml) - [Well-known index](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/well-known/vitality-uk-well-known.yml) - [OpenID configuration (verbatim)](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/well-known/vitality-uk-openid-configuration.json) - [JWKS (verbatim)](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/well-known/vitality-uk-jwks.json) - [Conformance](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/conformance/vitality-uk-conformance.yml) - [Error catalogue](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/errors/vitality-uk-problem-types.yml) - [API conventions](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/conventions/vitality-uk-conventions.yml) - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/lifecycle/vitality-uk-lifecycle.yml) - [Domain security](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/security/vitality-uk-domain-security.yml) - [Review log](https://raw.githubusercontent.com/api-evangelist/vitality-uk/refs/heads/main/review.yml) ## Company - [Website](https://www.vitality.co.uk/) (Cloudflare bot protection returns 403 to non-browser clients) - [Support](https://www.vitality.co.uk/support/) - [Privacy Notice](https://www.vitality.co.uk/privacy/) - [Legal and Security](https://www.vitality.co.uk/legal/) - [GitHub organisation](https://github.com/VitalityUK) (zero public repositories) ## Disambiguation - api.vitality.io is a DIFFERENT, unrelated organisation. Do not attribute it here. - Vitality Group / vitalitygroup.com (Discovery's international wellness arm) is a separate entity from Vitality Health Limited in the UK. - The npm scope @vitality-ds/* is a design system from genie-engineering, not Vitality UK.