Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

DEVELOPER

API Catalog

Use versioned REST/FHIR interfaces with explicit authentication, idempotency where required, typed errors and correlation for operational support.

01 / CONCEPT

Integration contract

01

Contract

Method, media type, required scope, schema/profile and version are explicit.

02

Reliability

Use idempotency for retryable creates where supported and bounded retry only for recoverable conditions.

03

Errors

Distinguish validation, authentication, authorization, conflict, rate limit and dependency failures.

04

Correlation

Propagate request/correlation identifiers without placing sensitive clinical data in logs.

02 / WORKFLOW

From sandbox to evidence

  1. 01Select API/resource
  2. 02Confirm scope and schema
  3. 03Send synthetic request
  4. 04Handle success and typed error
  5. 05Correlate in integration logs
  6. 06Promote only after recovery testing
03 / EXAMPLE

Create telehealth appointment / retrieve DiagnosticReport

cURL / pseudocode
POST /fhir/Appointment  # synthetic appointment
GET /fhir/DiagnosticReport?subject=Patient/synthetic-001
04 / SECURITY & PRODUCTION

Production is an evidence decision

API integration must demonstrate idempotency where required, typed error handling, bounded retry, correlation and dependency-failure recovery before production.

EXAMPLE CONTRACTS

Read the contract before writing the client

These are synthetic examples for documentation structure; they are not claims that a named production endpoint is currently published.

01

Create Observation · EXAMPLE

POST /fhir/Observation · OAuth scope: observation.write · application/fhir+json · idempotency key where the deployment contract supports retryable create.

02

Read DiagnosticReport · EXAMPLE

GET /fhir/DiagnosticReport?subject=Patient/{id} · scoped read access · explicit pagination/filter behavior and OperationOutcome-style error diagnostics.

03

Webhook event · EXAMPLE

Signed callback with delivery/event identifier, timestamp and correlation; consumers acknowledge quickly and deduplicate before asynchronous processing.

04

Typed failure

400 validation_error · 401 invalid_token · 403 insufficient_scope · 409 conflict where applicable · 429 rate_limited; dependency errors remain distinguishable from client errors.

Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access