APIs
Each service has an interactive OpenAPI reference with request builders, schemas, and example responses.
Quoting
Medicare Supplement
Medigap quotes, plan names, plan details, and underwriting filters.
View referenceMedicare Advantage
Legacy Medicare Advantage quoting endpoints.
View referenceMedicare Advantage & PDP
Medicare Advantage and Part D plan, benefit, and pricing data.
View referenceHospital Indemnity
Hospital Indemnity quote search and open company lookup.
View referenceDental Vision and Hearing
Dental, vision, and hearing quote search.
View referenceFinal Expense Life
Final Expense Life quote search, carrier plan management, underwriting reference data, prescription drug lookup, and product analysis reports.
View referenceEnrollment
Platform
CSG Authentication
Access tokens, OAuth/JWT flows, and service-account authentication.
View referenceClient User Authorization
OAuth-like authorization-code flow for signing a client application's own users into CSG, plus the client/user management API backing it.
View referencePortal Authorization
Agent/consumer portal login, session management, and account settings -- the CSG session your browser or a client app gets after signing in.
View referenceGetting started
Every request requires a session token, except endpoints under open/.
Service-account integrations can use the OAuth/JWT flow in the
CSG Authentication docs instead.
Authenticate
POST /v1/auth.json with an email and password, or an api_key. Portal accounts also pass portal_name.
Receive a token
The response includes a token and its expires_date. Tokens stay active for eight hours.
Call any API
Send the token as the X-API-TOKEN header on requests to every service listed above.
# Content-Type: application/json
{
"api_key": "<your-api-key>",
"portal_name": "csg_individual"
}
# Content-Type: application/x-www-form-urlencoded
api_key=<your-api-key>&portal_name=csg_individual
# Or sign in as a user instead of with an API key:
# send "email" and "password" in place of "api_key".
{
"token": "<8-hour-session-token>",
"expires_date": "2026-09-24T22:42:39.861010",
"created_date": "2026-09-24T14:42:39.860960",
"user": {
"email": "you@example.com",
"products": [
{ "plan_code": "admin", "state": "active" }
]
}
}
Token expiration
An expired token returns 403 with Session Expired Error. Request a new token when that happens, or refresh on a schedule. Every seven hours stays safely inside the eight-hour window.
Sharing tokens
A token isn't tied to one client. Any number of clients can share it and make simultaneous requests while it's active.