API scoping spec
What the API covers, agreed in workshops, and the CEO sign-off that releases the production API build.
API documentation
Read only. You can read this screen. Only the Super admin changes it.
Draft, version 0.9. Two decisions are still open. The spec goes to the CEO only when every family has a decision and the extra endpoints question is answered.
Waiting for the CEO. Version 1.1 was sent to the CEO on 3 Oct 2026. The production API build stays blocked until the sign-off is recorded.
Signed off. Version 1.2 was signed off by the CEO on 2 Oct 2026. The production API build may start. A later change needs a new version and a new sign-off.
Decisions per family
| Family | Push or pull | Auth model | Rate limit | Decision |
|---|---|---|---|---|
| Reception and eligibilityPatients, eligibility checks | Pull and push | OAuth2 client credentials | 300 calls a minute | Decided |
| Finance, payment and claimClaims, batches, payment notices | Pull | OAuth2 client credentials | 300 calls a minute | Decided |
| Diagnosis and doctorDiagnoses, care team | Push | Scoped API key | 1,000 calls a minute | Decided |
| Family | Push or pull | Auth model | Rate limit | Decision |
|---|---|---|---|---|
| Reception and eligibilityPatients, eligibility checks | Pull and push | OAuth2 client credentials | 300 calls a minute | Decided |
| Finance, payment and claimClaims, batches, payment notices | Open | OAuth2 client credentials | Open | Open |
| Diagnosis and doctorDiagnoses, care team | Push | Open | 1,000 calls a minute | Open |
Target entities are listed under each family. Credentials are issued on API access and described on API documentation.
Endpoints beyond the three families
NoConfirmed in spec section 4. Reception, finance and diagnosis cover the go-live scope.
Note: a request for another family (for example pharmacy stock) starts a new spec version with its own sign-off.
To confirmNot answered yet. The spec cannot be sent for sign-off without a yes or a no.
Note: the pharmacy portal pilot asked about stock levels on 24 Sep 2026. It is on the agenda of the 8 Oct 2026 workshop.
Workshops
| Date | Topic | Attendees | Outcome |
|---|---|---|---|
| 14 Sep 2026 | Reception and eligibility: direction and entities | Nadia Haddad (PM), Samir Al-Qadi (Tech Leader), Hadeel Al-Qahtani | Done |
| 21 Sep 2026 | Diagnosis and doctor: push contract | Nadia Haddad, Samir Al-Qadi, Dr. Yasmin Farouk (clinical vendor) | Done |
| 28 Sep 2026 | Finance, payment and claim: pull, auth and limits | Nadia Haddad, Samir Al-Qadi, Faisal Al-Dosari (A/R) | Done |
| 8 Oct 2026 | Endpoints beyond the three families | Nadia Haddad, Samir Al-Qadi, Pharmacy portal vendor | Planned |
| Date | Topic | Attendees | Outcome |
|---|---|---|---|
| 14 Sep 2026 | Reception and eligibility: direction and entities | Nadia Haddad (PM), Samir Al-Qadi (Tech Leader), Hadeel Al-Qahtani | Done |
| 21 Sep 2026 | Diagnosis and doctor: push contract | Nadia Haddad, Samir Al-Qadi, Dr. Yasmin Farouk (clinical vendor) | Done |
| 28 Sep 2026 | Finance, payment and claim: pull, auth and limits | Nadia Haddad, Samir Al-Qadi, Faisal Al-Dosari (A/R) | Done |
| 1 Oct 2026 | Final review of the spec, including the extra endpoints question | Nadia Haddad, Samir Al-Qadi, Tariq Al-Mansour | Done |
Spec versions
| Version | Date | Author | Change | State |
|---|---|---|---|---|
| v0.9 | 4 Oct 2026 | Nadia Haddad | Finance and diagnosis decisions open | Draft |
| v0.5 | 21 Sep 2026 | Nadia Haddad | Reception decisions added | Replaced |
| Version | Date | Author | Change | State |
|---|---|---|---|---|
| v1.1 | 3 Oct 2026 | Nadia Haddad | All families decided, extra endpoints answered | Awaiting sign-off |
| v1.0 | 28 Sep 2026 | Nadia Haddad | First complete draft | Replaced |
| Version | Date | Author | Change | State |
|---|---|---|---|---|
| v1.2 | 2 Oct 2026 | Nadia Haddad | Rate limits aligned with API access | Signed off |
| v1.1 | 1 Oct 2026 | Nadia Haddad | All families decided | Replaced |
| v1.0 | 28 Sep 2026 | Nadia Haddad | First complete draft | Replaced |
Sign-off
- State
- Draft
- Approver
- Dr. Majed Al-Rashid, CEO
- Production API build
- Blocked
- Open items
- 2 decisions, 1 question
- State
- Awaiting sign-off
- Approver
- Dr. Majed Al-Rashid, CEO
- Sent
- 3 Oct 2026, 09:10
- Production API build
- Blocked
- State
- Signed off
- Approver
- Dr. Majed Al-Rashid, CEO
- Signed
- 2 Oct 2026, 11:20
- Version
- v1.2
- Production API build
- Can start
The CEO signs off before the production API build starts. A new version after sign-off resets the state to draft.
Where it is used
The generated API documentation follows the signed-off version. The pilot client is tracked on Pilot client.