T Admin · Published APIs
Overview Users Reports

Internal API (web + mobile, same contract)

Versioned at /api/v1/… · JWT (15-min) or scoped API key via X-API-Key header · Idempotency-Key on POST /visits and POST /medications.

Interactive Swagger (/docs) ReDoc (/redoc) Raw OpenAPI JSON

AreaEndpoints
AuthPOST /api/v1/auth/login · GET /api/v1/permissions/me
ClinicalGET /api/v1/patients/{id}/dashboard · POST /api/v1/visits · POST /api/v1/visits/{id}/images · POST /api/v1/medications · POST /api/v1/medicine-reference · GET/POST /api/v1/appointments · POST /api/v1/notes
AI flagsGET /api/v1/flags?status=open · GET /api/v1/flags/{id} · GET /api/v1/visits/{id}/flags · POST /api/v1/flags/{id}/review
ReportsGET /api/v1/reports/mine · POST /api/v1/reports/{id}/run?fmt=json|csv|html|xlsx|pdf · admin CRUD at /api/v1/admin/reports
AdminGET /api/v1/admin/overview · GET/PUT /api/v1/admin/users · POST /api/v1/admin/api-keys

Partner/B2B note

Per blueprint §4: external partners get a narrower hand-curated spec + self-service read-only keys, manual approval for PHI writes. Nothing identifiable is published beyond a patient's own session until VAPT + one quarter of proven rate-limiting. 🔒 Human gate.

Service

/metrics /healthz