SALUVIORA Connect 1.0

Build trusted healthcare connections into SALUVIORA.

A governed partner platform for provider networks, health-data sharing, booking, availability, FHIR R4 and signed events. Every connection is organisation-scoped, jurisdiction-aware and promoted through explicit certification gates.

Scoped credentials

One-time-issued secrets, hashed at rest, bounded by approved subscription scopes.

Member authority

Health-data APIs require an active member grant and external-subject link.

FHIR R4

Read-only canonical clinical-resource projection with verification provenance.

Signed events

HTTPS webhooks, per-endpoint signing, retry and dead-letter controls.

API catalogue

Versioned products, explicit runtime state

10 products
Provider Network API

connect.directory.v1 · REST

certification

Evidence-backed provider, location, service, capability and rating discovery.

provider.read

Existing governed provider-search projection carried into Connect 1.0.

Member Shared Health API

connect.shared-health.v1 · REST

certification

Member-authorised organisation access to selected SALUVIORA health-resource scopes.

health.shared.read

Existing consent/grant-bound shared-health interface carried into Connect 1.0.

Booking API

connect.booking.v1 · REST

certification

Provider booking-request submission and authoritative booking-status retrieval.

booking.write
bookings.read

v1 adds governed partner booking-status read alongside the existing booking request API.

Provider Availability API

connect.availability.v1 · REST

sandbox

Provider organisations publish bounded service availability with provider-attested provenance.

availability.write

New in Connect 1.0.

FHIR R4 Shared Clinical API

connect.fhir-r4.v1 · FHIR

sandbox

FHIR R4 Bundle projection of member-authorised ClinicalResource facts.

clinical.fhir.read
clinical.fhir.write

FHIR read is implemented; FHIR write remains blocked pending clinical-safety and provenance certification.

Events & Webhooks API

connect.events.v1 · WEBHOOK

certification

Signed outbound event delivery with HTTPS destination validation, retries and dead-letter controls.

webhooks.manage

Existing signed webhook control plane formalised as a Connect product.

Diagnostics Partner API

connect.diagnostics.v1 · REST

design

Future diagnostic order/status/result exchange using authoritative partner provenance.

diagnostics.orders.read
diagnostics.results.write

Planned; not callable in Connect 1.0 initial release.

Insurance Partner API

connect.insurance.v1 · REST

design

Future authoritative coverage and authorisation exchange.

insurance.coverage.write
insurance.authorisation.write

Planned; Healthcode/direct insurer certification remains separate.

Referral API

connect.referrals.v1 · FHIR

design

Future governed referral creation/status exchange.

referrals.read
referrals.write

Planned; not callable.

Prescription API

connect.prescriptions.v1 · FHIR

design

Future private/NHS prescribing state exchange through separately certified pharmacy integrations.

prescriptions.read
prescriptions.write

Planned; not callable.

Authentication

Bearer API credential

implemented

Opaque one-time-issued secret; only SHA-256 hash is retained by SALUVIORA.

OAuth 2.0 Client Credentials

planned

Requires governed token issuer/signing configuration before runtime enablement.

Mutual TLS

planned

Requires deployment-gateway client-certificate termination and verified certificate binding.

Initial Connect 1.0 runtime uses opaque bearer credentials. OAuth 2.0 client credentials and mTLS remain planned until their issuer/certificate controls are runtime-certified.

Request controls

Correlation: supply x-correlation-id or SALUVIORA generates one.

Idempotency: write endpoints require an Idempotency-Key when the catalogue marks the operation idempotent.

Jurisdiction: credentials are restricted to subscription-approved country codes and release gates.

Authority: a successful API call never upgrades an unverified source into a verified clinical or insurer decision.

Promotion lifecycle
applicant

Stage 1

due diligence

Stage 2

sandbox

Stage 3

certification

Stage 4

pilot

Stage 5

production

Stage 6

Production is never self-service. Promotion requires current certification plus applicable security, contract, DPA, DPIA, clinical-safety, commercial and subscription approvals.

Partner developer access

Start in the governed sandbox.

Approved organisation members can request subscriptions, create sandbox credentials, register signed webhooks and view certification evidence in the Partner Portal.

SALUVIORA

The private health operating system that brings health information, intelligent care navigation, provider access and ongoing healthcare management together in one place.

Clarity. Care. Continuity.

Explore

Safety

SALUVIORA and SaluNavi support healthcare navigation and organisation. They do not replace a clinician's diagnosis or treatment decision. For a medical emergency, contact your local emergency service or go to the nearest appropriate emergency department.

© 2026 SALUVIORA.Your health. Organised around you.