---
title: "probe"
url: "https://oapi-poc.hdbank.work/en-getting-started"
image: "https://oapi-poc.hdbank.work/_og/d/c_Ocean.takumi,title_probe,props_eyJ0aGVtZSI6eyJtb2RlIjoibGlnaHQiLCJjb2xvcnMiOnsicHJpbWFyeSI6IiMwMDAwRjUifX19,p_Ii9lbi1nZXR0aW5nLXN0YXJ0ZWQi,s__DC3qoVH-fkuzNNl.png"
---

☀☾

Sovico Open API · Developer Portal

# Get started with Sovico Open API

Sign up, get your credentials and make your first API call in the sandbox. All data is 100% simulated and never touches real systems.

[Create an account](https://oapi-poc.hdbank.work/register)[Browse the API catalog](https://oapi-poc.hdbank.work/en-apis)

## [Get going in just 3 steps](#get-going-in-just-3-steps)

1

### [Create an account and an application](#create-an-account-and-an-application)

Sign in with SSO, open **Applications** and create a new application. Sandbox apps are approved automatically; INS-02 is open to all developers, while IDN-01 and PAY-03 are only for authorized teams.

2

### [Get a sandbox API key](#get-a-sandbox-api-key)

The API key appears right after you create the application and is sent in the `apikey` header. Store it safely; never put it in a code repository or a shared channel.

3

### [Make your first call](#make-your-first-call)

Use curl or Postman to call `POST /quotes`. Add an `X-Mock-Scenario` header with 400, 403, 409, 429 or 503 to simulate error codes.

## [Keep going](#keep-going)

Quotas

### [Plans and quotas](#plans-and-quotas)

Four tiers (Public, Partner, Premium, Strategic) with rate, daily quota and how to handle 429.

[See the plans](https://oapi-poc.hdbank.work/en-plans)

OAuth2

### [Simulated Production](#simulated-production)

Register an app, wait for approval, get a token with client credentials and call the simulated production API.

[Read the guide](#production-simulation)

Support

### [Terms and support](#terms-and-support)

Usage rules, key expiry and how to report incidents with `X-Correlation-ID`.

[Contact support](https://oapi-poc.hdbank.work/en-support)

## [Try it with curl](#try-it-with-curl)

```bash
export SANDBOX=https://apis-dev.hdbank.work
curl -s -H "apikey: $KEY" -H "X-Correlation-ID: $(uuidgen)" \
  -X POST $SANDBOX/quotes -d '{"product":"motor","sum_insured":500000000}'
```

**Standard headers:** `X-Correlation-ID` (generated if missing), `X-Tenant-ID`, `Idempotency-Key` (required for PAY-03), `X-Consent-ID` (required for IDN-01). Errors are returned as `application/problem+json` (RFC 9457).

## [Limits and versions](#limits-and-versions)

New applications start on the Public tier: 2 requests/second, 100 requests/day. Exceeding it returns `429` with `Retry-After` and `RateLimit-*`. INS-02 v1 is deprecated (responses carry `Deprecation: true`, `Sunset: 31/12/2026`); use v2 at `/v2/quotes`.

## [Simulated Production (OAuth2, approval required)](#production-simulation)

For applications that need OAuth2 instead of an API key (API **INS-02 Insurance Quotes (production simulation)**).

1.  Create an application and pick the simulated production API. The request waits for the API owner to **approve manually**.
2.  Once approved, the portal issues a `client_id` and `client_secret` (Keycloak realm `devportal-demo`).
3.  Fetch a token. **Send `client_secret` via HTTP Basic**; sending it in the form body fails with `unauthorized_client`.

```bash
TOKEN=$(curl -s -u "$CLIENT_ID:$CLIENT_SECRET" -d grant_type=client_credentials -d scope=scope-ins \
  https://sso.hdbank.work/realms/devportal-demo/protocol/openid-connect/token | jq -r .access_token)
curl -s -H "Authorization: Bearer $TOKEN" $PROD/prod/quotes/qt-1
```

Sandbox keys and tokens do **not** work in simulated production (401).