Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
Aviva plc website screenshot

Aviva plc

Aviva plc is the United Kingdom's largest insurer and one of the ten biggest insurance groups in Europe, listed on the London Stock Exchange and serving roughly 20 million UK customers across the UK, Ireland and Canada following completion of its acquisition of Direct Line Insurance Group on 1 July 2025. Aviva is a composite carrier rather than a single-line one: UK and Ireland general insurance (personal and commercial motor, property and liability), the UK's largest life insurance book, a growing corporate and individual health business, workplace pensions and wealth, and Aviva Investors as the asset-management arm. Aviva Canada is that market's second-largest property and casualty insurer. Aviva's API posture is that of a carrier, not a platform. It operates a real, modern developer portal at developer.aviva.co.uk — a Kong Konnect portal fronted by Aviva's own EV certificate — but the portal reports is_public false with RBAC and OIDC authentication enabled, and every content path returns HTTP 403 to an unauthenticated request. It is explicitly a partner surface: the portal's own copy describes Partners discovering, accessing and consuming Aviva Health APIs, with sandbox access granted on application and production consumption granted on approval. There is no self-serve signup, no public API reference, no downloadable OpenAPI, no public Postman workspace, no GraphQL surface and no published event catalogue. The far larger integration channel is not the portal at all: in the UK, Aviva trades with brokers through Polaris UK's imarket and its PL EDI message and code-list standards, reaching broker systems such as Acturis, Applied Systems, Open GI, Bravo and SSP, and in December 2024 Aviva became the first insurer to launch a claims API integrated directly into Acturis, pushing new and updated motor, property and liability claim records into brokers' management systems. No ACORD reference was found on any Aviva surface; the UK's standards seam here is Polaris, not ACORD. This record is therefore an honest stub: a real but partner-gated API programme with no public self-serve surface to harvest.

agent aware

More than an index entry, but the surface is still mostly links rather than artifacts — the cohort most likely to move a full band from modest, well-targeted work.

Kin Score

API Evangelist profiles Aviva plc the way a machine reads it — 5 machine-readable artifacts across 2 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Aviva plc scores 27.4/100 (emerging), with a separate agent-readiness read of 20/100 (agent aware). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 27.4/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 10.4 / 20
Commercial Clarity 4.2 / 20
Operational Transparency 0.0 / 13
Governance 0.0 / 12
Discoverability 8.0 / 10
Regulatory · Securities & Market Data 8.1 / 15
Agent readiness — 20/100 · agent aware
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3

How we profile Aviva plc

Each block below is one kind of artifact we hold for Aviva plc. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 2

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

Aviva Private Medical Insurance Consumer Pricing API

Listed in the Aviva API Developer Portal service catalogue as an API that calculates premiums for Aviva consumer Private Medical Insurance policies — the quote/rating verb of th...

Aviva Private Medical Insurance Consumer Purchase API

Listed in the Aviva API Developer Portal service catalogue as the purchase counterpart to the pricing API, enabling partners to submit applications for PMI policy enrolment into...

Rate Limits 1

Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.

Documented rate limits and quota policies.

Aviva Plc Rate Limits

0 limits

RATE LIMITS

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Aviva Plc Authentication

oauth2 · 2 schemes

SECURITY

Aviva Plc Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Resources

Every other property we hold for Aviva plc — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Documentation 3

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Access & Security 2

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

← All providers · Data indexed from github.com/api-evangelist/aviva-plc · machine-readable index on apis.io