# Cardinal Health > Cardinal Health is a Fortune 15 integrated healthcare services and products company: > pharmaceutical distribution, medical-surgical product distribution, and specialty > solutions for hospitals, health systems, pharmacies, ambulatory surgery centers, > clinical laboratories and physician offices. It exchanges very high volumes of B2B > trading data — but it does not publish a developer program, and there is no > machine-readable contract an agent can call. ## What an agent can and cannot do here - There is **no public API contract**. No OpenAPI, no AsyncAPI, no GraphQL SDL, no WSDL, no Protobuf, no Postman collection was found at any probed location. - There is **no MCP server** and **no A2A agent card**. - There is **no first-party SDK** on npm, PyPI, RubyGems, Maven Central, NuGet or pkg.go.dev, and **no public GitHub organization**. - `api.cardinalhealth.com` is a real Cardinal Health API gateway host — Sectigo OV certificate, `O=Cardinal Health, Inc.` — but it sits behind a Google Cloud VPC Service Controls perimeter and returns `403 SecurityPolicyViolated` for every anonymous request, including `/robots.txt`. It cannot be called from outside. - A developer portal at `developer.np.cardinalhealth.com` is still indexed by search engines under the title "Cardinal Health API Developer Portal: Home", but the hostname no longer resolves publicly. - Integration is therefore a **contracted trading-partner relationship**, onboarded through Cardinal Health's customer, supplier and partner teams — not a self-serve developer signup. ## The real integration surface: ASC X12 EDI Cardinal Health trades on ASC X12 EDI. Independent EDI platforms publish Cardinal-Health-specific mapping guides naming these transaction sets: - 810 Invoice - 812 Credit/Debit Adjustment - 844 Product Transfer Account Adjustment - 845 Price Authorization Acknowledgment/Status - 849 Response to Product Transfer Account Adjustment - 850 Purchase Order - 852 Product Activity Data - 855 Purchase Order Acknowledgment - 856 Ship Notice/Manifest (ASN) - 867 Product Transfer and Resale Report - 940 / 943 / 944 / 945 / 947 warehouse shipping, transfer and inventory advices - 997 Functional Acknowledgment These are read from third-party integrator documentation, not from a contract Cardinal Health serves. Treat the list as indicative of the program, not as a spec. ## Docs - [Services](https://www.cardinalhealth.com/en/services.html): the products and services Cardinal Health sells, and the entry point for integration inquiries. - [About Cardinal Health](https://www.cardinalhealth.com/en/about-us.html) - [Contact](https://www.cardinalhealth.com/en/contact-us.html): the route to the trading-partner and integration teams. - [Coordinated Vulnerability Disclosure](https://www.cardinalhealth.com/en/support/coordinated-vulnerability-disclosure.html) ## Security - [Vulnerability Disclosure Program](https://hackerone.com/cardinal_health) on HackerOne. Confirmed live (HTTP 200, verified against a negative control). - No `/.well-known/security.txt` is served on any Cardinal Health host. ## Legal - [Terms and Conditions](https://www.cardinalhealth.com/en/notices/terms-and-conditions.html) - [Privacy Policy](https://www.cardinalhealth.com/en/notices/privacy-policy.html) ## Company - [Investor Relations](https://ir.cardinalhealth.com/) - [Careers](https://www.cardinalhealth.com/en/about-us/careers.html) ## Note on this file Generated by API Evangelist from the catalog record and this repository's probe artifacts on 2026-09-05. Cardinal Health does not publish an llms.txt of its own; `www.cardinalhealth.com` could not be fetched at all this round, because its Akamai edge drops every non-browser connection after the TLS handshake.