REST APIs for Core Objects
Quoting, policy, claims, producer, and document endpoints follow consistent, versioned REST conventions — one API surface for every workflow the exchange runs.
Mon–Fri, 9 AM–6 PM
Carrier Solution
A modern REST API surface connects the exchange to your rating engines, policy admin, document management, and CRM. Webhooks push events the moment they happen, and dedicated sandbox environments make integration testing safe — before a single live policy moves.
The API Surface
Quoting, policy, claims, producer, and document endpoints follow consistent, versioned REST conventions — one API surface for every workflow the exchange runs.
Purpose-built connectors link your rating engine, policy admin, and CRM so quotes rate in real time and bound business lands in your system of record automatically.
Quote requested, policy bound, endorsement issued, claim filed — webhooks push events to your systems the moment they happen, with signed payloads and automatic retries.
Every carrier gets a dedicated sandbox with test producers, products, and policies. Build and validate integrations against realistic data with zero production risk.
Scoped API keys and OAuth 2.0 client-credentials flows control exactly what each integration can read and write, with per-key rate limits and rotation support.
Encryption in transit and at rest, full audit logging on every API call, and SOC 2-aligned controls keep policyholder data protected end to end.
How It Works
Receive dedicated sandbox credentials, interactive API reference docs, and sample payloads for every endpoint the day your integration project starts.
Wire quoting, policy, and claims flows against sandbox producers, products, and policies — with webhook test events you can replay on demand.
Run the certification suite that validates request handling, error recovery, and webhook acknowledgment before any production credentials are issued.
Switch to production keys with rate limits sized to your volume. API dashboards track call health, latency, and webhook delivery from day one.
Developer Experience
Most carrier integrations stall on undocumented endpoints, silent breaking changes, and webhooks that vanish without a trace. The exchange API is built the other way: versioned contracts, complete documentation, idempotent writes, and delivery guarantees your team can verify. Once connected, the same pipes feed every dashboard and report your portfolio runs on.
Explore Data & AnalyticsFAQ
No. Most carriers start with a single flow — usually real-time rating or bound-policy delivery — and add policy, claims, and producer endpoints as later phases. Each API area stands alone, so a partial integration is fully functional from day one.
The API is transport-agnostic: if your system can make outbound HTTPS calls or receive them through your network edge, it can integrate. For batch-oriented legacy cores, scheduled file-based delivery (SFTP with the same data contracts) is available as a bridge while you modernize.
Endpoints are versioned, and existing versions keep working when new ones ship. Deprecations are announced with a published timeline — never silently — and your integration dashboard flags any calls still hitting endpoints scheduled for retirement.
Failed deliveries retry automatically with exponential backoff, and every event is stored so you can replay it from the dashboard. Signed payloads let your systems verify authenticity, and delivery reporting shows exactly which events succeeded, retried, or need attention.
Security documentation covering SOC 2-aligned controls, encryption standards, data retention, and audit logging is available for your review. Scoped API keys mean each integration only accesses the data it needs, and full call-level audit logs support your own compliance reporting.
Join Insurance Exchange and get sandbox access, documented APIs, and a certification path that takes your integration to production with confidence.