API archive entry · source-reported

Health Repository Provider Specifications for HIU

The following are the specifications for the APIs to be implemented at the Health Repository end if an entity is only serving the role of a HIU. The specs are essentially duplicates from the Gateway and Bridge, but put together so as to make it clear to *HIUs* which set of APIs they should implement to participate in the network. 1. The APIs are organized by the flows - **identification**, **consent flow**, **data flow** and **monitoring**. They represent the APIs that are expected to be available at the HIU end by the Gateway. 2. For majority of the APIs, if Gateway has initiated a call, there are corresponding callback APIs on the Gateway. e.g for **/consents/hiu/notify** API on HIU end, its expected that a corresponding callback API **/consents/hiu/on-notify** on Gateway is called. Such APIs are organized under the **Gateway** label. 3. Gateway relevant APIs for HIUs are grouped under **Gateway** label. These include the APIs that HIPs are required to call on the Gateway. For example, to request a CM for consent, HIU would call **/consent-requests/init** API on gateway. 4. **NOTE**, in some of the API documentations below, **X-HIP-ID** is mentioned in header (for example in /aut

Provider / source website

Plan the first integration safely

The access fields below come from the connected directory. Their likely implementation impact is explained without assuming provider-specific behavior.

Authentication

OAuth is reported. Confirm flows, scopes, consent, token lifetime, and refresh rules.

Transport

HTTPS is not confirmed. Do not send credentials or production data until secure transport is verified.

Browser access

CORS is unknown. Treat direct browser access as unconfirmed and test before choosing a client-only architecture.

First-request sequence

  1. Identify the current base URL, version, and endpoint for the use case.
  2. Confirm how credentials are issued and where they may be stored.
  3. Test success, invalid input, throttling, unavailable data, and timeouts.
  4. Record response fields, pagination, caching, and error shapes.
  5. Add monitoring, retries with backoff, and an appropriate fallback.

Questions to resolve before production

Pricing and quotas

Confirm current plans, free-tier limits, overages, and request ceilings.

Endpoint coverage

Check that the operations and response fields match the intended workload.

Reliability

Look for uptime history, a status page, support routes, and service commitments.

Data and privacy

Review retention, licensing, regional processing, and compliance requirements.

Versioning

Confirm the active version, change policy, deprecation window, and migration guidance.

Developer experience

Validate SDKs, examples, error formats, pagination, and test environments.

Source reference

APIs.guru OpenAPI Directory

This page separates source-reported facts from questions that need live provider verification.