This is not our API. This repository is an independent, third-party profile of a company's publicly available API surface, maintained by API Evangelist. API Evangelist does not operate, host, resell, or support this company's APIs, and is not affiliated with or endorsed by the company unless stated on the profile.
Where the information came from. Everything here is assembled from material a member of the public can reach with a browser and no credentials — the company's own website, developer portal and documentation, the specifications it publishes for public use (OpenAPI, AsyncAPI, JSON Schema,
apis.json,llms.txtand similar), its public repositories, and its public status, pricing and changelog pages. Nothing here is obtained by breaching a system, defeating an access control, or using credentials of any kind.The rating is an independent assessment. The Kin Score and Agent Readiness rating are independently calculated scores of a company's public API artifacts, produced by API Evangelist against a published rubric. They are not certifications, endorsements, security assessments, or audits, and they score published artifacts — not the quality, safety, or security of the software.
Corrections, re-scores, and removal are free. No partnership, contract, or purchase is required, and you do not need to justify the request.
- Something wrong? Open an issue on this repository, or email info@apievangelist.com.
- Published something new? Ask for a re-score and we will re-run the rating.
- Want the listing taken down? Say so and we will honor it. The profile is reduced to your company name, a factual description, and a link to your own site, and the company is recorded as unrated — never scored zero for having asked.
Response times. Acknowledgement within one business day; removal or restriction within two business days; corrections and re-scores within five business days.
On a security or compliance team? Email info@apievangelist.com with security in the subject line and you will get a person, not a form. We will tell you exactly which public URLs this profile was built from so your team can see the same surface we did, and we will take the listing down on request while you work through it.
Full detail: Where this data comes from
The National Association of Insurance Commissioners (NAIC) is the U.S. standard-setting and regulatory support organization created and governed by the chief insurance regulators of the 50 states, the District of Columbia and five territories. It is not a carrier and not a federal regulator — under the McCarran-Ferguson settlement the United States has no national insurance supervisor, so the NAIC is the coordinating body through which state-based regulation is made uniform. It writes the model laws, accounting practices and Annual Statement Blanks that every admitted insurer files against, operates the Financial Data Repository behind those filings, and runs the market infrastructure the industry actually transacts on: SERFF for electronic rate and form filing, State Based Systems (SBS) for producer and company licensing in roughly thirty jurisdictions, iSite+ and myNAIC for regulator analytics, OPTins for premium tax, and consumer-facing lookups such as the Consumer Information Source and the Life Insurance Policy Locator. Its lines of business span property and casualty, life and annuity, health, title and fraternal across the United States.
APIs.json: https://raw.githubusercontent.com/api-evangelist/naic/refs/heads/main/apis.yml
- Insurance
- United States
- Regulator
- Market Infrastructure
- Insurance Regulation
- Property and Casualty
- Life Insurance
- Health Insurance
- Producer Licensing
- Rate and Form Filing
- Regulatory Reporting
- Standards Body
- Created: 2026-07-25
- Modified: 2026-07-25
The NAIC publishes no public developer portal and no documented self-serve API. Probed on 2026-07-25:
developer.naic.org,developers.naic.org,docs.naic.org— all NXDOMAINapi.naic.org— resolves and answers over HTTP/2, but returns a baretext/plainNot Foundon/,/openapi.json,/swagger.json,/api-docs,/v1,/docs,/health,/swagger-ui.htmland/actuator. An internal gateway, not a portal.content.naic.org/developers,/api,/apis,/developer,/web-services,/data— all HTTP 404
Zero OpenAPI, Swagger, WSDL or AsyncAPI documents were found. The NAIC publishes no specification of any kind.
The only API-shaped surface the NAIC names in public is SERFF Web Services, and it is partner-gated. Everything else — myNAIC, iSite+, SBS, OPTins, SERFF Login — is an Okta-fronted web application. Bulk regulatory data from the Financial Data Repository is licensed by contract (idp@naic.org) and delivered as CSV; InsData sells statutory financial statements as PDFs. Neither is an API.
The 2026-07-25 enrichment round probed content.naic.org itself rather than only the developer-hostname candidates, and found a live, anonymously readable JSON:API v1.1 at https://content.naic.org/jsonapi, served by Drupal 11. Its entry point returns a machine-readable resource index enumerating 284 resource types, and anonymous GET returns HTTP 200 application/vnd.api+json across every content family. It carries the NAIC's model law corpus (with MDL model numbers), the state insurance department regulator directory, committees and task forces, insurance topics, publications, CIPR research, the newsroom, and the published PDFs behind them.
The NAIC has never advertised it. There is no documentation, no changelog, no deprecation policy, no status page and no support channel scoped to it — and the underlying Drupal content model is unversioned. Treat it as a real but unsupported public read surface.
The NAIC also publishes a first-party llms.txt declaring AI usage preferences (allow_model_training: false, require_attribution: true), crawl guidance (crawl_delay: 10, max_requests_per_day: 100) and path scoping — so its stated contract with automated consumers is more explicit than its contract with API developers. Honor it; nothing enforces it server-side.
The openapi/ document in this repo is derived by API Evangelist from that live resource index (x-publisher-provided: false), not published by the NAIC.
No ACORD reference found. A full-text scan of the official NAIC Technology Products and Services Catalog (57,226 characters extracted) returned zero occurrences of ACORD, XML, web service, REST, SOAP or developer. The NAIC runs its own statutory idiom — Annual Statement Blanks, the Market Conduct Annual Statement (MCAS), risk-based capital reporting, and the SERFF filing schema — which sits parallel to ACORD rather than mapping onto it. No AL3, NGDS, IVANS or agency-download reference exists in the NAIC estate.
The NAIC-operated SERFF (System for Electronic Rates & Forms Filing) platform exposes machine integration services to filers, state regulators and filing vendors. The SERFF Technical Support Checklist published at serff.com names three services by name — Legacy SPI (two-way PUSH/PULL), Legacy SIS (one-way PULL), and a Modernized Data API (one-way PULL) — each available in PROD and BETA environments. There is no public reference documentation, no OpenAPI or WSDL, and no self-serve signup: access is provisioned by request to wsrequest@naic.org and the service hosts are credential-gated (services.serff.com returned HTTP 403 anonymously; services-beta.serff.com returned HTTP 200 but serves only an NAIC/NIPR landing page). Recorded here as a real but partner-gated surface, not a public API.
- Human URL: https://www.serff.com/
- Insurance
- Rate and Form Filing
- Regulatory Reporting
- Partner Gated
- Documentation
- Documentation — SERFF Technical Support Checklist
- Documentation — SERFF Modernization
A live, anonymously readable JSON:API v1.1 surface over the NAIC's public regulatory content estate, served by Drupal 11 and undocumented by the publisher. Supports the full JSON:API query grammar — sparse fieldsets, filtering, sorting, relationship inclusion, offset pagination capped at 50 — and returns JSON:API error objects rather than RFC 9457 problem details. Writes are closed (POST → HTTP 401 "No authentication credentials provided.", DELETE → 405). It carries the content estate only: not SERFF filings, the Financial Data Repository, SBS licensing or OPTins.
- Base URL:
https://content.naic.org/jsonapi - Human URL: https://content.naic.org/
- Auth: none — anonymous read
- OpenAPI — derived, 569 operations
- Examples — five verbatim live payloads
- Documentation — the JSON:API specification the surface implements
| Artifact | File | Method |
|---|---|---|
| OpenAPI | openapi/naic-content-jsonapi-openapi.yml |
derived from the live resource index |
| llms.txt | llms/naic-llms.txt |
searched — publisher-authored, verbatim |
| Examples | examples/ |
searched — five verbatim live responses |
| Conventions | conventions/naic-conventions.yml |
derived from live probes |
| Error catalog | errors/naic-problem-types.yml |
derived from provoked live errors |
| Data model | data-model/naic-data-model.yml |
derived |
| Authentication | authentication/naic-authentication.yml |
searched |
| Conformance | conformance/naic-conformance.yml |
derived |
| Lifecycle | lifecycle/naic-lifecycle.yml |
searched |
| Well-known | well-known/naic-well-known.yml |
searched — audited negative record |
| Domain security | security/naic-domain-security.yml |
probed |
| MCP server | mcp/naic-mcp.yml |
derived — candidate, nothing deployed |
| Agent skills | skills/ |
generated — 3 skills, grounded operationIds |
| Agentic access | agentic-access/naic-agentic-access.yml |
generated — 569 read-only contracts |
Not present, because they genuinely do not exist: SDKs/packages, CLI, sandbox, changelog, status page, deprecation policy, webhooks/AsyncAPI, GraphQL, gRPC, OAuth scopes, Postman collection, security.txt, vulnerability-disclosure program, trust center, GitHub organization.
- Website
- About
- Newsroom
- Insurance Topics
- Publications
- SERFF
- State Based Systems (SBS)
- iSite+
- InsData
- Financial Data Repository
- Consumer Information Source
- Technology Products and Services Catalog
- Contact / Support
- Help
- Terms & Conditions
- Privacy Statement
NIPR (the National Insurance Producer Registry, nipr.com) is a separate legal entity from the NAIC even though the two share systems and branding. Any producer-licensing API activity belongs on the NIPR record, not this one.
- Kin Lane — kin@apievangelist.com