formflow.Product status

DELIVERY API & INTEGRATIONS

Keep your portals.
Connect the right release.

Integrate through your insurer backend or backend-for-frontend. Each environment delivers its current authorized form package.

V2 investor-demo baseline available · Production qualification remains in progress. See product status

Five focused retrieval operations

The customer-facing Delivery API is separated from management and administration.

List forms

Retrieve a bounded page of released forms and continue through the catalog.

Query forms

Use structured filters, grouping, sorting, and field selection under the same authorization rules.

Retrieve form metadata

Resolve the current released package for the requested form and permitted scope.

Retrieve the PDF

Fetch the PDF belonging to that exact environment release.

Retrieve the active schema

Read metadata definitions for the selected company and environment.

Respect the delivery boundary

Delivery access does not expose management actions, draft packages, approvals, support data, or private audit history.

Make integration easier to maintain

V2 documentation is scoped to the company and environment, with artifacts generated from the contract.

OpenAPI and metadata schemas

Download machine-readable definitions aligned with the selected environment.

Postman and cURL examples

Use starter requests and environment templates without embedding live credentials in shared artifacts.

QA request builder

Explore allowlisted read operations in a QA-only tool. It is not a Production execution console.

Predictable client behavior

Documentation covers pagination, cache validators, safe errors, rate-limit responses, and bounded retries.

Manage machine access deliberately

Credential lifecycle core is implemented; managed-key, distributed invalidation, and deployment validation remain production gates.

Scoped integration identities

Separate company, environment, audience, and permitted Delivery operations.

Credential lifecycle

The design supports one-time secret display, expiry, bounded rotation overlap, revocation, and integration disablement.

Backend-only secrets

Shared credentials belong on the server, never in browser code, query strings, or public examples.

Provider evolution

The architecture allows future authentication adapters. OAuth client credentials and mTLS are not presented as released V2 options.

Explore operations and access controls