One consolidated map of the shteg.ai surface: 43 documented endpoints across 8 tags, from sign-in to a settled remittance. Every request and response is JSON over HTTPS against your sandbox origin; every path below is a real route. Each group links to its deep reference page, and each row deep-links to that page’s section.
No live money or live patient data is reachable from the sandbox. Every endpoint fails closed — an unconfigured transport returns a typed 503 (or 501 for unconfigured EMR/FHIR stores) with zero network calls, never a fabricated confirmation. Interactive examples on the deep pages are labeled Example · sandbox-shaped and make no live call.
The same surface as an OpenAPI 3.1 document or a ready-to-import Postman collection — feed it to a client generator, a mock server, or your own explorer.
Describes the documented paths, security schemes, and typed error/fail-closed responses. Servers point at your deployment origin — the spec never asserts a live production endpoint.
Import into Postman to browse every documented endpoint grouped by tag, each with a {{baseUrl}} variable (default the sandbox surface), representative headers, and sandbox-shaped example bodies. Derived from the same OpenAPI spec — it references only documented routes and asserts no live call.
A live projection of the same OpenAPI 3.1 artifact — filter by tag or verb, search across paths, summaries, operationIds, and auth scopes, then expand any endpoint for its parameters and sandbox-shaped request/response. Every card anchors to its operationId for deep links; nothing here makes a live call.
51 of 51 endpoints
Session issuance, step-up re-authentication for money/clinical writes, and strong-factor enrollment (TOTP MFA + WebAuthn/FIDO2 passkeys). The edge baseline authenticates every request; these routes mint and strengthen the session.
The money surface. The deterministic six-condition gate is the sole money authorizer; the operator console records disbursement of KMS-signed instructions; the reconciliation waterfall posts payer 835s in conserving cents. Every money book is one balanced entry on the hash-chained WORM ledger.
837P/837I claim build and transmit stamped with the shteg.ai Type-2 NPI, NCCI/MUE/laterality scrubbing, live 276/277 status inquiry, replacement-claim appeals, and 835 ERA posting. Fails closed before anything leaves the gateway.
Real-time X12 270/271 coverage checks (single-patient and day-roster). Production never simulates coverage — a missing live path fails closed.
There is no standalone credentialing endpoint: credentialing IS gate condition 6 (composite OIG-LEIE + NPPES + PSV screening) inside the money path. This tag exposes only the PHI-free provider directory the screener resolves NPIs against.
Sanctioned EMR/EHR integration via IntegrationConnection records, browser OAuth (authorize/callback), and non-interactive SMART Backend Services / Partner-API pulls into the managed FHIR store. Every connector fails closed (501) with zero network calls until its named credential gate clears.
FHIR R4 CapabilityStatement, resource read/search, Bulk Data $export, CMS Patient Access, SMART App Launch context, CDS Hooks discovery, C-CDA export, and Blue Button 2.0 inbound import. The CapabilityStatement is the authoritative list of honored interactions; prose is not.
Inbound, signature-verified callbacks from payment, EMR, fax, and bank-data partners. Every inbound path fails closed on a missing secret or bad signature.
Grouped index of the documented surface. Nothing here simulates success; open a group's deep page for parameters, schemas, typed errors, and example requests.
Every /api/* request is authenticated before it reaches a handler. Sign in for a session cookie, then step up for money and clinical writes; enroll TOTP or a WebAuthn passkey.
The money surface: a hash-chained WORM ledger, the deterministic six-condition gate as sole authorizer, and the 835 reconciliation waterfall in conserving integer cents.
The registered HIPAA clearinghouse surface: build and transmit an 837P stamped with the shteg.ai Type-2 NPI, scrub before it leaves the gateway, inquire real 276/277 status, and post remits.
Real-time X12 270/271 through connected payer networks. Production never simulates coverage; per-patient failures surface as unknown, never a fabricated success.
Provider legitimacy is not a standalone product — it is gate condition 6. The composite screener resolves each NPI against OIG-LEIE + NPPES inside the money path.
Sanctioned, API-provisioned EMR ingestion only — never portal or session scraping. OAuth and SMART Backend Services pulls into the managed FHIR store; unconfigured credentials fail closed with zero network calls.
FHIR R4 read/search, Bulk Data $export, SMART App Launch, CDS Hooks, C-CDA, and inbound Blue Button. The CapabilityStatement is the source of truth; unconfigured stores return 501, never a fabricated bundle.
Signature-verified inbound events from payment, EMR, fax, and bank-data partners. Every receiver verifies an HMAC-SHA256 signature over the raw body and fails closed when its signing secret is unconfigured.
Tenancy, scopes, integer-cent money, idempotency keys, correlation IDs, and the typed-refusal contract — read them once before you build.
No real dollar has moved. No real PHI has flowed.
What is real: the architecture — hash-chained ledger, settlement gate, and reconciliation waterfall, tested in the current build — the Type-2 organizational NPI and registered HIPAA clearinghouse identity, and the doctrine. We register capability as capability, never as traction.