API reference

The core FHIR REST surface this platform exposes. The authoritative, machine-readable contract is documented in OpenAPI, as scoped in the SOW — this page is a human-readable summary of that spec for reviewers, not the spec itself.

Every call above carries the requesting actor's identity and is checked against RBAC (what the role may do) and the patient's consent + treatment relationship (whether this organisation may see this record right now) before data returns. That two-layer check is shown in context, live, on Cross-organisation access.