REST API

API reference

A thin HTTP face over the diagnos SDK: one process, one service account, one live session. Every route requires a client certificate signed by the CA this deplo

On this page

A thin HTTP face over the diagnos SDK: one process, one service account, one live session. Every route requires a client certificate signed by the CA this deployment trusts — there is no other credential. Every non-2xx response is `{"error": {"code", "message", "trace_id"}}`; branch on `code`.

Endpoints #

patients #

Encrypted patient records: sealed in this process, versioned, never readable by the vault.

exams #

Encrypted exams and their reports, each linked to one patient.

drives #

Files and folders of one security group (`{sg}`), each file under its own key.

session #

The one SDK session this process holds, and the caller's mTLS identity.

health #

Liveness, behind mTLS like everything else.