Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

DEVELOPER

OpenAPI

Treat the packaged OpenAPI contract as a build-time interface description while keeping environment URLs, credentials and deployment policy outside the specification.

01 / CONCEPT

Integration contract

01

Contract use

Generate clients, validate request/response shape and review breaking changes.

02

Environment separation

Sandbox and production endpoints/credentials are not hard-coded into generated clients.

03

Versioning

A breaking schema or behavior change requires an explicit version/migration path.

04

Security

OAuth/mTLS requirements are documented but secrets and private keys never belong in the contract bundle.

02 / WORKFLOW

From sandbox to evidence

  1. 01Download packaged specification
  2. 02Validate schema locally
  3. 03Generate or hand-build client
  4. 04Bind sandbox endpoint securely
  5. 05Run positive/negative contract tests
  6. 06Review release note before upgrade
03 / SECURITY & PRODUCTION

Production is an evidence decision

The OpenAPI file describes a contract, not live availability. Endpoint, credential, policy and version compatibility are confirmed separately per environment.

Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access