BenefitsEdge API — Developer Portal

Staging / sandbox only. Operators: use admin call logs for full history.

Getting started

Authentication: Authorization: key <API_KEY> (obtain from ops; never commit secrets).

Encryption: POST bodies use AES-GCM JSON: { "ciphertext", "iv" } wrapping inner JSON. Key: deployment API_AES_KEY (autopopulated below in staging).

SAML init: POST /v1/api/saml/init → browser opens GET /v1/hold/:token → auto-post SAML to vendor ACS.

Sample inner payloads: nyl-saml-init-inner.json, metlife-saml-init-inner.json

Architecture docs (repo): docs/api/README.md

Playground — SAML init

Prefer employee details (platform, accountKey, employee); legacy clientDetails still works. Key casing does not matter — the API lowercases keys on receive. This page encrypts your JSON as typed.

Payload:

Staging autopopulates the deployment key. Encryption runs in the browser; the key is not POSTed for encrypt.

Enter a valid AES key to preview the request body.
Skip SAML build; return placeholder redirect URL
Send a request to see the response.

Recent API calls (last 10)

TimeMethodRouteIntegration APIIntegrationms
2026-09-29T15:00:07Z POST /v1/api/saml/init newyorklife 200 200 4372
2026-09-28T18:05:42Z POST /v1/api/saml/init newyorklife 200 200 4178
2026-09-16T18:26:15Z POST /v1/api/saml/init newyorklife 200 200 35549
2026-08-24T18:16:10Z POST /v1/api/saml/init newyorklife 200 200 23590
2026-08-24T13:42:16Z POST /v1/api/saml/init newyorklife 200 200 4909
2026-08-24T13:21:37Z POST /v1/api/saml/init newyorklife 200 200 2699
2026-08-24T13:10:28Z POST /v1/api/saml/init newyorklife 200 200 2574
2026-08-24T13:08:31Z POST /v1/api/saml/init newyorklife 200 200 2627
2026-08-24T13:08:01Z POST /v1/api/saml/init newyorklife 200 200 19119
2026-08-21T18:42:57Z POST /v1/api/saml/init newyorklife 200 200 21693

Call log refreshes in the background every 30s (playground state is kept). API 2xx + integration 4xx/5xx highlighted.