# Annexus Health > Annexus Health is a privately held healthcare technology company in Cranberry Township, Pennsylvania that builds software to reduce the administrative burden of patient financial navigation. Its platform AssistPoint helps provider organizations identify, enroll in, and manage copay assistance, charitable foundation grants, and manufacturer patient support programs; its AP Connect integration layer creates a two-way secure exchange between life science and foundation patient support programs and AssistPoint. generated: 2026-08-06 method: generated source: apis.yml + artifacts in the api-evangelist/annexus-health repository note: Annexus Health does not publish an llms.txt (https://www.annexushealth.com/llms.txt returns 404). This file is generated by API Evangelist from publicly probed material and is not published by Annexus Health. ## What is publicly callable Annexus Health runs **no public developer program**. There is no developer portal, no API reference, no OpenAPI or AsyncAPI document, no GraphQL endpoint, no MCP server, and no A2A agent card. `api.annexushealth.com`, `developer.annexushealth.com`, and `docs.annexushealth.com` do not resolve. AP Connect — the API-based integration between life science patient support programs and AssistPoint — is delivered through direct partnership and its contract is not published. The one machine-readable surface that is publicly reachable is the AssistPoint identity tier. ## AssistPoint Identity (OpenID Connect) - [OpenID Connect discovery](https://login.live.annexushealth.com/.well-known/openid-configuration): The production authorization server metadata, served anonymously (200 application/json). - [OAuth 2.0 authorization server metadata](https://login.live.annexushealth.com/.well-known/oauth-authorization-server): RFC 8414 metadata, byte-identical to the OIDC discovery document. - [JWKS](https://login.live.annexushealth.com/.well-known/jwks.json): Public signing keys. - Issuer: `https://login.live.annexushealth.com/` - Endpoints: `/authorize`, `/oauth/token`, `/userinfo`, `/oauth/device/code`, `/oauth/revoke`, `/oidc/register`, `/bc-authorize`, `/mfa/challenge` - Grants: authorization_code, client_credentials, refresh_token, device_code, token-exchange, jwt-bearer (plus the deprecated password and implicit grants) - Scopes: openid, profile, offline_access, name, given_name, family_name, nickname, email, email_verified, picture, created_at, identities, phone, address - Hardening: PKCE (S256 and plain), DPoP (ES256), MFA, private_key_jwt, dynamic client registration, backchannel logout - Tenant: Auth0-hosted on an Annexus Health custom domain Non-production tenants `login.dev.annexushealth.com` and `login.testenv.annexushealth.com` also serve discovery documents. Neither is a published developer sandbox — no test credentials, fixtures, or self-serve signup are documented. ## Products - [AssistPoint](https://www.annexushealth.com/assistpoint/): Enterprise workflow platform for patient access and financial assistance. Its Search Wizard searches more than 10,000 assistance programs against a patient's demographics, diagnosis, regimen, and insurance type. Licensed by 165+ healthcare organizations across 4,200+ sites of care; more than $6 billion in patient financial assistance awards processed since 2018. - [AP Connect](https://www.annexushealth.com/ap-connect/): Two-way secure information exchange between life science / foundation patient support programs and AssistPoint — standardized digital enrollment forms prepopulated from the practice management system, e-signature, and real-time award balance updates. More than 55 therapies are digitally integrated. Partner-only; no public contract. - [Adparo](https://www.annexushealth.com/adparo/): Patient financial navigation service offering. ## Security and compliance - [Trust center](https://trust.annexushealth.com/): SafeBase by Drata. Compliance section names HITRUST. Policies and BC/DR documents are listed but NDA-gated. - [Privacy & security](https://www.annexushealth.com/privacy-security/): HITRUST Risk-based, 2-year (r2) Certification. The certificate is available on request. - No SOC 2, ISO 27001, PCI DSS, or FedRAMP attestation is published. - No `/.well-known/security.txt`, no vulnerability disclosure policy, and no bug bounty. - TLS 1.3 with HSTS (max-age 63072000) on www.annexushealth.com; SPF and DMARC (p=quarantine) present on annexushealth.com; DNSSEC and CAA are not configured. ## Company - [Home](https://www.annexushealth.com/) - [About](https://www.annexushealth.com/about/) - [Leadership](https://www.annexushealth.com/leadership/) - [History](https://www.annexushealth.com/history/) - [Careers](https://www.annexushealth.com/careers/) - [Contact](https://www.annexushealth.com/contact/) - [Customer support](https://www.annexushealth.com/customer-support/) - [Provider FAQs](https://www.annexushealth.com/provider-faqs/) - [Insights](https://www.annexushealth.com/insights/) · [News](https://www.annexushealth.com/news/) · [RSS](https://www.annexushealth.com/feed/) - [Privacy policy](https://www.annexushealth.com/privacy-policy/) · [Cookie policy](https://www.annexushealth.com/cookie-policy/) ## Optional - [assistpoint-de-controls on npm](https://www.npmjs.com/package/assistpoint-de-controls): AssistPoint Digital Enrollment form controls, v1.0.3, published 2023-12-20 by an individual maintainer. Its GitHub repository is not public. Not an official Annexus Health SDK. - Annexus Health has no public GitHub organization. - No status page exists. `annexushealth.statuspage.io` answers 200 but redirects to Atlassian's own marketing page and is a soft-404. - Robots: `https://www.annexushealth.com/robots.txt` sets `Crawl-delay: 10`. Honor it.