Connecting to our application programming interfaces
Registered providers, plan managers and software developers (aggregators) can access our systems through our application programming interfaces (APIs).
Our APIs allow controlled and secure access to specific NDIA data for approved applicants to support the delivery of services to NDIS participants.
Everyone’s responsible for protecting the confidentiality, integrity and availability of NDIA data when they gain access to the APIs.
You can connect to our APIs in 2 ways:
- direct integration
- indirect integration.
Option 1: Direct integration
Direct integration is the process where registered providers, plan managers and aggregators connect directly with our APIs.
Step 1: Download and fill out the digital providers questionnaire
The digital providers questionnaire is a form registered providers, plan managers and aggregators fill out to become a digital partner.
Download the digital provider questionnaire:
- NDIA digital providers questionnaire (PDF 222KB)
- NDIA digital providers questionnaire (DOCX 110KB)
Tip: Aggregators need to partner with a registered provider.
Aggregators need to partner with a registered provider if they want to access our APIs. They'll also need to complete additional cyber security activities.
Step 2: Complete an ASIC company extract
Complete a current Australian Securities and Investments Commission (ASIC) company extract. You can buy this on the ASIC website .
The date on the current company extract should be within 4 weeks of the date you provide these documents to us.
Step 3: Sign the terms and conditions
Read and understand the terms and conditions. You’ll need to fill out and sign page 6 for us to assess your application.
Download the NDIA API terms and conditions:
- NDIA API terms and conditions (DOCX 43KB)
You need to include a copy of supporting evidence if an authorised representative, such as a power of attorney, signs the terms and conditions.
We use the company extract to confirm the signing authorities (registered secretary/director) on the terms and conditions.
Step 4: Provide evidence
Provide evidence to support your application. You can use the cyber clearance requirements document to find out what evidence we need.
Download the cyber clearance requirements:
- Cyber clearance requirements (PDF 196KB)
- Cyber clearance requirements (DOCX 64KB)
You’ll need to provide a copy of your planned architecture to connect to our APIs.
Standards you need to meet to connect to our systems
You need to meet the following standards to connect to our APIs:
- agree to the Australian Government API Design Standards
- have a suitable ICT certification and auditor report for your ICT systems as specified in the cyber clearance framework, for example ISO 27001:2022
- have an appropriate level of cyber security maturity
- display secure coding practices, where appropriate
- complete penetration testing, where appropriate.
Step 5: Send us your completed documents
After you have all your documents ready:
- email them to [email protected]
- mail them to:
Attention: Digital Partnership Office
NDIA
GPO Box 700
Canberra ACT 2601.
Step 6: We’ll assess your application
We’ll start assessing your application when we receive all required documents. We may ask you for further information to support your application, if needed.
We’ll work with you to finalise the architectural review and cyber clearance process.
Step 7: We’ll send you a technical pack
We’ll send you a technical pack if your application is approved, which includes information for:
- onboarding
- development
- NDIA testing standards.
Option 2: Indirect integration
Indirect integration is the process where registered providers connect with our APIs through an aggregator.
Step 1: A registered provider or plan manager connects with an aggregator
Registered providers and plan managers can access our APIs by connecting via an aggregator who is an existing NDIA digital partner.
Step 2: The aggregator applies to our Digital Partnership Office
The aggregator submits an application to our Digital Partnership Office (DPO) on behalf of a registered provider or plan manager.
Step 3: We assess the application
We’ll complete a technical review of the application. We’ll then let the aggregator know the outcome of the application.