# AristaMD > AristaMD is a San Diego based specialty care company whose eConsult platform connects primary care providers to board-certified specialists across 70+ specialties and subspecialties. Primary care clinicians submit a case, AristaMD's nursing team prepares the workup, and a specialist returns documented recommendations asynchronously — reducing unnecessary face-to-face referrals, ED visits and hospitalizations. Buyers are health plans, Medicaid programs, FQHCs and provider groups. AristaMD does not operate a public developer program. It does, however, serve a live Swagger 2.0 definition of its core business-logic API. This file was generated by API Evangelist from that contract and from anonymous probes; AristaMD publishes no llms.txt of its own. ## API - [AristaMD API (Swagger 2.0, live)](https://api.aristamd.com/api-docs): The business logic core that serves all AristaMD sites, tools and integrations. 32 paths, 42 operations, 26 schema definitions. Base URL https://api.aristamd.com. Every documented path is authenticated and returns 401 without credentials. - [Harvested copy of the specification](https://raw.githubusercontent.com/api-evangelist/aristamd/refs/heads/main/openapi/aristamd-openapi-original.json): Verbatim, as served on 2026-08-06. ### Capabilities - **eConsults** (11 operations) — list, create, retrieve, update, patch, delete, assign-to-me, search by status, log panelist availability, drive state transitions via an event handler, and post a specialist heartbeat. - **Patients** (10 operations) — list, create, retrieve, update, patch, search, create from an HL7 v2 message, patient history, external identifiers, and top-referral reporting. - **Panelists** (2 operations) — find specialists by specialty and status group, and resolve the next available panelist for a specialty and patient. - **Specialties** (4 operations) — retrieve, create and update specialties; list specialties that currently have available panelists. - **Workup Checklists** (3 operations) — specialties, chief complaints per specialty, and the checklist for a specialty/chief-complaint pair. - **Reviews** (4 operations) and **Comments** (1 operation) — structured feedback and free-text notes attached to a request. - **Users** (4 operations) — directory, lookup, search by role/permission/organization, and field-level update. - **Intergy/Patients** (1 operation) — patient lookup passthrough to the Greenway Intergy EHR. ### Authentication - OAuth 2.0 authorization server at `https://api.aristamd.com/oauth/token` and `/oauth/authorize`. Observed grant types: `authorization_code`, `client_credentials`, `password`, `refresh_token`. `implicit` and `jwt-bearer` are rejected as unsupported. - SAML 2.0 service provider metadata at [https://api.aristamd.com/saml2/metadata](https://api.aristamd.com/saml2/metadata) for federated single sign-on. - **The published specification declares no securitySchemes.** A machine reading only the spec would wrongly conclude the API is open. It is not. - No OIDC discovery, no RFC 8414 authorization-server metadata, no RFC 9728 protected-resource metadata. ### Conventions an agent needs to know - Error envelope is `{"message": ""}` — not RFC 9457, and carries no machine-readable error code. The only discriminator is the HTTP status. - **No idempotency key.** 21 of 42 operations are unsafe writes, including `POST /econsults` and `POST /patients`. Do not blindly retry a timed-out write; there is no contract-level protection against creating a duplicate clinical record. - Pagination is offset-limit (`start`, `length`, `orderColumn`, `orderDir`, `searchValue`) and exists on only two operations. Most collections are unpaginated. - No versioning of any kind — no path segment, header or media type. - No rate-limit headers are returned. - operationIds are **not unique** (14 distinct ids across 42 operations), so operations cannot be reliably addressed by id. ### PHI warning This API returns United States protected health information — patient names, dates of birth, gender, chronic conditions, insurance coverage, clinical attachments and specialist recommendations. Treat every response as PHI. Do not log, cache, embed or forward response bodies without an appropriate agreement in place. ## Artifacts - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/aristamd/refs/heads/main/authentication/aristamd-authentication.yml) - [API conventions](https://raw.githubusercontent.com/api-evangelist/aristamd/refs/heads/main/conventions/aristamd-conventions.yml) - [Error catalog](https://raw.githubusercontent.com/api-evangelist/aristamd/refs/heads/main/errors/aristamd-problem-types.yml) - [Data model](https://raw.githubusercontent.com/api-evangelist/aristamd/refs/heads/main/data-model/aristamd-data-model.yml) - [Conformance](https://raw.githubusercontent.com/api-evangelist/aristamd/refs/heads/main/conformance/aristamd-conformance.yml) - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/aristamd/refs/heads/main/lifecycle/aristamd-lifecycle.yml) - [Agent skills](https://raw.githubusercontent.com/api-evangelist/aristamd/refs/heads/main/skills/_index.yml) ## Company - [AristaMD](https://www.aristamd.com/) - [eConsults](https://www.aristamd.com/specialty-care/care-delivery/econsults/) - [Security posture](https://www.aristamd.com/security/): Information Security Program following the SOC 2 framework, independent third-party assessments and annual penetration testing, AWS + GCP hosting in the United States. - [Thought leadership](https://www.aristamd.com/thought-leadership/) - [Contact](https://www.aristamd.com/contact/) - [GitHub](https://github.com/aristamd) - [Terms of use](https://www.aristamd.com/terms-of-use/) · [Privacy policy](https://www.aristamd.com/privacy-policy/) ## Not available - No developer portal, getting-started guide, API reference site or authentication documentation. - No SDK or client library in any public package registry. - No changelog, deprecation policy or SLA. - No working status page (`status.aristamd.com` redirects to a deactivated Statuspage). - No MCP server, no A2A agent card, no AsyncAPI and no webhook surface. - `app.aristamd.com`, `developer.aristamd.com` and `help.aristamd.com` return HTTP 200 with the same 1820-byte single-page-app shell for *every* path. Do not treat a 200 from those hosts as evidence that a document exists.