Sovico Open API · Developer Portal
Get started with Sovico Open API
Sign up, get your credentials and make your first API call in the sandbox. All data is 100% simulated and never touches real systems.
Get going in just 3 steps
Create an account and an application
Sign in with SSO, open Applications and create a new application. Sandbox apps are approved automatically; INS-02 is open to all developers, while IDN-01 and PAY-03 are only for authorized teams.
Get a sandbox API key
The API key appears right after you create the application and is sent in the apikey header. Store it safely; never put it in a code repository or a shared channel.
Make your first call
Use curl or Postman to call POST /quotes. Add an X-Mock-Scenario header with 400, 403, 409, 429 or 503 to simulate error codes.
Keep going
Plans and quotas
Four tiers (Public, Partner, Premium, Strategic) with rate, daily quota and how to handle 429.
See the plansSimulated Production
Register an app, wait for approval, get a token with client credentials and call the simulated production API.
Read the guideTerms and support
Usage rules, key expiry and how to report incidents with X-Correlation-ID.
Try it with curl
export SANDBOX=https://apis-dev.hdbank.work
curl -s -H "apikey: $KEY" -H "X-Correlation-ID: $(uuidgen)" \
-X POST $SANDBOX/quotes -d '{"product":"motor","sum_insured":500000000}'
X-Correlation-ID (generated if missing), X-Tenant-ID, Idempotency-Key (required for PAY-03), X-Consent-ID (required for IDN-01). Errors are returned as application/problem+json (RFC 9457).Limits and versions
New applications start on the Public tier: 2 requests/second, 100 requests/day. Exceeding it returns 429 with Retry-After and RateLimit-*. INS-02 v1 is deprecated (responses carry Deprecation: true, Sunset: 31/12/2026); use v2 at /v2/quotes.
Simulated Production (OAuth2, approval required)
For applications that need OAuth2 instead of an API key (API INS-02 Insurance Quotes (production simulation)).
- Create an application and pick the simulated production API. The request waits for the API owner to approve manually.
- Once approved, the portal issues a
client_idandclient_secret(Keycloak realmdevportal-demo). - Fetch a token. Send
client_secretvia HTTP Basic; sending it in the form body fails withunauthorized_client.
TOKEN=$(curl -s -u "$CLIENT_ID:$CLIENT_SECRET" -d grant_type=client_credentials -d scope=scope-ins \
https://sso.hdbank.work/realms/devportal-demo/protocol/openid-connect/token | jq -r .access_token)
curl -s -H "Authorization: Bearer $TOKEN" $PROD/prod/quotes/qt-1