# Whitespace > Whitespace Software Limited is a London-based digital placing platform for the Lloyd's and London (re)insurance market, and one of only two electronic placing systems given fully recognised status by Lloyd's. Part of Verisk (via Sequel). Brokers and underwriters create, negotiate, quote, firm-order, line, sign and endorse fully digital subscription-market contracts in place of the traditional slip. The reference documentation is public and unauthenticated; credentials are not — sandbox and production service tokens are issued by Whitespace Support to contracted broker, carrier and vendor organisations, are IP-allowlisted, and expire within a year. Whitespace authored the JSON Market Reform Contract (JMRC) and donated it to ACORD for the Global Reinsurance and Large Commercial data standards. Generated by API Evangelist on 2026-07-25. Whitespace publishes no llms.txt of its own; this file is generated from apis.yml and the artifacts in this repository. Source of record: https://apidocs.whitespace.co.uk/ ## APIs - [Whitespace Platform API](https://apidocs.whitespace.co.uk/): REST/JSON API over the full London-market subscription placing lifecycle — 113 paths, 121 operations across Risks, Data (Defined Data), Attachments, Documents, Activities, Comments, Labels, Lookup, Endorsements, Lines, Questionnaire, Summary, Shared, User and MI Report. Sandbox base URL https://sandbox.whitespace.co.uk/, production https://www.whitespaceplatform.com. ## Specs - [OpenAPI 3.0.0 (harvested verbatim)](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/openapi/whitespace-london-platform-openapi.yml): the platform specification, served inline by Whitespace at https://swagger.whitespace.co.uk/index.spec.js - [OpenAPI Overlay](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/overlays/whitespace-london-platform-overlay.yaml): API Evangelist enhancements — an operationId for each of the 121 operations (the published spec declares none), the production server, and deprecation flags for the four superseded operations - [AsyncAPI 3.0.0 for the activity queues](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/asyncapi/whitespace-london-queues-asyncapi.yml): generated description of the per-client Azure Service Bus event surface, including the complete published activity-string enumeration ## Docs - [Developer documentation index](https://apidocs.whitespace.co.uk/) - [API reference (Swagger UI)](https://swagger.whitespace.co.uk/) - [Getting Started with the Whitespace API](https://apidocs.whitespace.co.uk/Getting_Started_with_the_Whitespace_API.pdf) - [Obtaining and Using a Service Token for the API](https://apidocs.whitespace.co.uk/Obtaining_and_Using_a_Service_Token_for_the_API.pdf) - [Refresh Token Guide v1.0](https://apidocs.whitespace.co.uk/Refresh_Token_Guide_v1.0.pdf) - [How does API versioning work?](https://apidocs.whitespace.co.uk/How_does_API_versioning_work.pdf) - [Whitespace Channels v1.0](https://apidocs.whitespace.co.uk/Whitespace_Channels_v1.0.pdf) - [Queues and the Whitespace Platform v1.2.2](https://apidocs.whitespace.co.uk/Queues_and_the_Whitespace_Platform_v1.2.2.pdf) - [Integrating with Whitespace via Queues 3.1](https://apidocs.whitespace.co.uk/Integrating_with_Whitespace_via_Queues_3.1.pdf) - [An Introduction to Defined Data](https://apidocs.whitespace.co.uk/An_Introduction_to_Defined_Data.pdf) - [The Defined Data API and JSON Notes](https://apidocs.whitespace.co.uk/Defined%20Data%20API%20and%20JSON%20Notes.pdf) - [JMRC ACORD Specification v0.5 — Defined Data](https://apidocs.whitespace.co.uk/JMRC%20ACORD%20Specification%20V0.5%20-%20Defined%20Data.pdf) - [Whitespace Data Dictionary (xlsx)](https://apidocs.whitespace.co.uk/Whitespace_Data_Dictionary.xlsx) - [Release notes and user guides](https://www.whitespace.co.uk/release-notes) ## Artifacts - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/authentication/whitespace-london-authentication.yml): HTTP bearer JWT service tokens plus the renewable/refresh token flow and the SUMO UserID header - [API conventions](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/conventions/whitespace-london-conventions.yml): GET/POST only, compound IC/MU document IDs, `_rev` optimistic concurrency (no idempotency key), channel-based authorisation, date-stamped optional URI versioning - [Error catalogue](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/errors/whitespace-london-problem-types.yml): the `{"error": true, "reason": "..."}` envelope, deliberately opaque 400s, and `Invalid WSAUTH` - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/lifecycle/whitespace-london-lifecycle.yml): versioning and the never-retire policy, deprecated operations, environments - [Changelog](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/changelog/whitespace-london-changelog.yml): platform releases back to 3.2, current 3.7 (10 July 2026) - [Sandbox](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/sandbox/whitespace-london-sandbox.yml): the Sandbox environment, dummy counterparty organisations and the token request path - [Data model](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/data-model/whitespace-london-data-model.yml): the RW* document graph and the `IC…::…` identifier grammar - [Conformance](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/conformance/whitespace-london-conformance.yml): JMRC, ACORD GRLC/ACORDGPM, MRC, Lloyd's recognition — and what it does not do (no OAuth2, no OIDC, no RFC 9457, no security.txt) - [Packages](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/packages/whitespace-london-packages.yml) and [CLI](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/cli/whitespace-london-cli.yml): the first-party MIT-licensed C# client and command-line utilities at github.com/whitespace-software/CSharpUtils - [Agent skills](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/skills/_index.yml): broker placing, underwriter quoting and line writing, Defined Data/ACORD, queue-driven integration, endorsements - [Candidate MCP tool projection](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/mcp/whitespace-london-mcp.yml): Whitespace publishes no MCP server; this is a design grounded in the real spec - [Agentic access](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/agentic-access/whitespace-london-agentic-access.yml): recommended execution contracts per operation - [Domain security probe](https://raw.githubusercontent.com/api-evangelist/whitespace-london/refs/heads/main/security/whitespace-london-domain-security.yml) ## Onboarding There is no self-serve signup. Integration follows a three-step process, all of it by email to support@whitespace.co.uk: (1) request Sandbox user accounts and an API service account, (2) request Sandbox Azure Service Bus queue(s), (3) request Production service account(s) and queue(s). Production service tokens require the calling IP address(es) as a contractual second authentication factor and expire within one year. Commercial terms are governed by the Whitespace Interchange Agreement at https://www.whitespace.co.uk/interchange-agreement ## Notes for agents - Reads are GET, every state change is POST. There is no PUT or PATCH. - There is NO idempotency key. Writes carry a document revision `_rev` which must be current; a retried write against a stale revision is rejected. Re-GET before any retry. - Most write operations are legally consequential acts in a subscription insurance market — showing a contract, offering a firm order, writing a line and signing are market acts, not sandbox-safe calls. Test on Sandbox. - Errors are usually a bare 400 with no explanation, by design. 401 returns `{"error": true, "reason": "Invalid WSAUTH"}`. - Events arrive on an Azure Service Bus queue, not by webhook. Integrations should be queue-driven.