Participation and correction

Add, correct, or remove an endpoint

If we got something wrong about your organization, we would rather be corrected than counted right.

01

We are missing your endpoint

Payer FHIR base URLs are not predictable from company names, so this registry is built one developer portal at a time and is certainly incomplete. Absence from this list means no public base URL was found, not that no API exists.

We need the base URL and a link to where it is published, because confirming the publisher is who the entry claims is what verification means here. Nothing is added on an unverified submission.

Tell us about an endpoint

02

Something here is wrong

This has happened. A live payer endpoint was recorded as dead because a middlebox on the probing network intercepted TLS and the error surfaced as one uninformative word. That is why every published grade reconciles probes from more than one vantage, and why reaching an endpoint from any of them settles that it is up.

What those vantages are, exactly: three GitHub-hosted runner images (Ubuntu, macOS, Windows). They are three hosts on one provider's network, not three independent networks. They catch a fault local to one host, which is the failure above; they cannot catch a source-address rule, bot filter, geo rule, or rate limit your edge applies to that provider's address space, because that hits all three at once. So when all three fail, the page says the endpoint was not reached from that network on that day. It does not say the endpoint is down.

You do not need to prove anything before asking us to look again.

Dispute or remove an entry

Our probe contract

What we do to your servers

At most two unauthenticated GET requests per endpoint per probing run: /metadata and /.well-known/smart-configuration. Three probing runs a day, one per runner image, so a scheduled day is at most six requests to any one endpoint. The run that publishes this site adds none: it grades the documents those runs already retrieved.

Requests carry an identifying User-Agent with a contact address. We never authenticate, never register for API access, never request patient data, and never probe beyond those two paths. Publishing is triggered on a schedule and by hand, not by commits, because a commit says nothing about your endpoint and a commit-triggered rebuild once turned an ordinary working day into dozens of requests to every endpoint here.

Grades describe observable properties of public documents. They are not audits, not compliance determinations, and not statements about care quality.