Build trusted healthcare connections into SALUVIORA.
A governed partner platform for provider networks, health-data sharing, booking, availability, FHIR R4 and signed events. Every connection is organisation-scoped, jurisdiction-aware and promoted through explicit certification gates.
Scoped credentials
One-time-issued secrets, hashed at rest, bounded by approved subscription scopes.
Member authority
Health-data APIs require an active member grant and external-subject link.
FHIR R4
Read-only canonical clinical-resource projection with verification provenance.
Signed events
HTTPS webhooks, per-endpoint signing, retry and dead-letter controls.
API catalogue
Versioned products, explicit runtime state
connect.directory.v1 · REST
Evidence-backed provider, location, service, capability and rating discovery.
Existing governed provider-search projection carried into Connect 1.0.
connect.shared-health.v1 · REST
Member-authorised organisation access to selected SALUVIORA health-resource scopes.
Existing consent/grant-bound shared-health interface carried into Connect 1.0.
connect.booking.v1 · REST
Provider booking-request submission and authoritative booking-status retrieval.
v1 adds governed partner booking-status read alongside the existing booking request API.
connect.availability.v1 · REST
Provider organisations publish bounded service availability with provider-attested provenance.
New in Connect 1.0.
connect.fhir-r4.v1 · FHIR
FHIR R4 Bundle projection of member-authorised ClinicalResource facts.
FHIR read is implemented; FHIR write remains blocked pending clinical-safety and provenance certification.
connect.events.v1 · WEBHOOK
Signed outbound event delivery with HTTPS destination validation, retries and dead-letter controls.
Existing signed webhook control plane formalised as a Connect product.
connect.diagnostics.v1 · REST
Future diagnostic order/status/result exchange using authoritative partner provenance.
Planned; not callable in Connect 1.0 initial release.
connect.insurance.v1 · REST
Future authoritative coverage and authorisation exchange.
Planned; Healthcode/direct insurer certification remains separate.
connect.referrals.v1 · FHIR
Future governed referral creation/status exchange.
Planned; not callable.
connect.prescriptions.v1 · FHIR
Future private/NHS prescribing state exchange through separately certified pharmacy integrations.
Planned; not callable.
Bearer API credential
Opaque one-time-issued secret; only SHA-256 hash is retained by SALUVIORA.
OAuth 2.0 Client Credentials
Requires governed token issuer/signing configuration before runtime enablement.
Mutual TLS
Requires deployment-gateway client-certificate termination and verified certificate binding.
Initial Connect 1.0 runtime uses opaque bearer credentials. OAuth 2.0 client credentials and mTLS remain planned until their issuer/certificate controls are runtime-certified.
Correlation: supply x-correlation-id or SALUVIORA generates one.
Idempotency: write endpoints require an Idempotency-Key when the catalogue marks the operation idempotent.
Jurisdiction: credentials are restricted to subscription-approved country codes and release gates.
Authority: a successful API call never upgrades an unverified source into a verified clinical or insurer decision.
Stage 1
Stage 2
Stage 3
Stage 4
Stage 5
Stage 6
Production is never self-service. Promotion requires current certification plus applicable security, contract, DPA, DPIA, clinical-safety, commercial and subscription approvals.