# Centene Corporation > Centene Corporation is a Fortune 500 managed care organization delivering government-sponsored > healthcare — Medicaid, Medicare Advantage and Health Insurance Marketplace plans — to roughly one > in fifteen Americans. Its public API surface exists to satisfy the 21st Century Cures Act and the > CMS Interoperability and Patient Access Rule: HL7 FHIR R4 APIs for member record access and > provider directory, published through a partner portal at partners.centene.com. Generated by API Evangelist on 2026-09-07 from Centene's own published contracts and documentation. Centene does not publish an llms.txt of its own; this file is generated, not fetched. ## Start here The **FHIR Provider Directory is public and needs no credential**. Verified 2026-09-07: GET https://iopc-pd.api.centene.com/iopc/pd/fhir/providerdirectory/Practitioner?family=SMITH -> HTTP 200, FHIR searchset Bundle Everything else requires an application registered through the partner portal. ## APIs - [FHIR Patient Access](https://partners.centene.com/apiDetail/2718669d-6e2e-42b5-8c90-0a82f13a30ba): Member clinical, coverage and claims data under SMART on FHIR member consent. 47 operations, FHIR R4 4.0.1. Base: https://iopc-pa.api.centene.com/iopc/pa - [FHIR Provider Directory](https://partners.centene.com/apiDetail/8122bc9c-43d6-4a2a-b6be-2272df8b8566): Public, anonymous in-network provider search. 17 operations, Da Vinci PDEX Plan Net 1.2.0. Base: https://iopc-pd.api.centene.com/iopc/pd/fhir/providerdirectory - [FHIR Provider Directory (California)](https://iopc-provider.api.centene.com/iopc/provider/ca/fhir/providerdirectory): Separate deployment Centene directs California developers to. - [Provider RTR - FHIR PDEX Directory (External)](https://partners.centene.com/apiDetail/6b5c0001-8b47-4f1c-864f-9193971f5c62): Payer-to-payer directory exchange. 18 operations, client_credentials with audience prtrdemographic. - [Provider RTR - Demographics](https://partners.centene.com/apiDetail/fa62cad4-34be-4b39-b599-30d8a8b7163b): 67 read operations over Centene's bespoke provider credentialing and contracting model. - [Provider Carrier Entity Search (PCES)](https://partners.centene.com/apiDetail/a3cbbe9e-c2fe-4460-a248-6599e8b746be): Search-index query API over carrier entities. - [Provider Carrier Entity Search (PCES) Extract](https://partners.centene.com/apiDetail/badcf145-cbcb-4163-bace-bcadc1da3554): Scroll-based bulk extract. - [Provider Search Suggest](https://partners.centene.com/apiDetail/ee19c28c-cc90-4ea7-8181-512be50f210d): Typeahead suggestion endpoint. - [Product Mapping V2](https://partners.centene.com/apiDetail/97211dcb-047f-4f94-94b9-bb15376eb6ef): Networks and counties for an address. - [LWC EDI CORE Real Time Service](https://partners.centene.com/apiDetail/c921dd2a-ed7a-40ca-9324-803c7f65c374): X12 / CAQH CORE Connectivity real-time and batch transaction envelopes. - [CCM Communication](https://partners.centene.com/apiDetail/0a778592-13dd-447b-80b3-c39539d7a993): Care/campaign management communication records. - [Healow Health API](https://partners.centene.com/apiDetail/b795fc7e-44ab-4e11-a99e-9f261c1d48e9): Member gap-in-care search. Full anonymous catalogue: https://external-api.my.centene.com/partner-portal/apis ## Authentication - Authorization server: https://sso.entrykeyid.com (Ping Identity, branded EntryKey ID) - Discovery: https://partners.centene.com/.well-known/openid-configuration - Sandbox authorization server: https://sandbox.entrykeyid.com - Member data: SMART on FHIR 2.0.0 **standalone launch only** (EHR launch is not implemented), `authorization_code`, scopes `patient/*.read` + `openid`. Authorization codes are single-use. Access tokens live 3600 seconds; refresh tokens are issued. - Partner/service data: `client_credentials` with a **per-API `audience`** the gateway validates. A token minted for one Centene API will not open another. - Provider Directory: no authentication at all. ## Standards FHIR R4 4.0.1 · US Core 6.1.0 · CARIN BB 2.0.0 · Da Vinci PDEX 1.0.0 · Da Vinci PDEX Plan Net 1.2.0 · Da Vinci US Drug Formulary 2.0.1 · HL7 SMART App Launch 2.0.0 (standalone) · USCDI · OAuth 2.0 / OIDC with PKCE S256 · ASC X12 / CAQH CORE Connectivity · ISO 27001 certified · HIPAA and HITECH assessed annually. Live CapabilityStatement: https://iopc-pd.api.centene.com/iopc/pd/fhir/providerdirectory/metadata ## Conventions - **Paging**: FHIR Bundle link relations, 200 records per page. Follow the link whose `relation` is `next`. (Centene's docs say read `link[1]` — match on relation instead; FHIR does not guarantee link order.) - **Errors**: FHIR `OperationOutcome` on FHIR surfaces; a `GeneralError` schema on the search APIs; and — undocumented — a SOAP `env:Fault` XML body from the gateway on 403/404 regardless of `Accept`. - **Rate limits**: none published. 429 is declared on 62 operations but no `RateLimit-*` or `Retry-After` header is returned. Back off exponentially. - **Idempotency**: none. No `Idempotency-Key` on any surface, including the EDI batch submission operations. - **Tracing**: an undocumented `x-request-id` is returned on every response. Log it. - **Webhooks**: none for third-party developers. The three portal entries labelled "Webhook" are inbound receivers for Centene's SMS vendor. ## Getting started - [Developer portal](https://partners.centene.com/) - [API catalog](https://partners.centene.com/apis) - [Application developer onboarding](https://partners.centene.com/applicationDeveloper) - [Third-party developer onboarding form](https://partners.centene.com/applicationDeveloper-form) - [Terms](https://partners.centene.com/terms) · [Privacy policy](https://partners.centene.com/policy) - Contact: IOP_External_Onboarding@Centene.com ## Sandbox Patient Access has a real sandbox at `https://iopc-sand.test.api.centene.com/iopc/sand` with six published test members (CNCTESTTPA001–006). No other API has one. ## Known gaps - No SDKs in any language, and no Centene Corporation GitHub organization. (github.com/Centene is an unrelated personal account.) - No status page, no changelog, no deprecation policy, no SLA, no Sunset/Deprecation headers. - No `/.well-known/security.txt` on any host, though a HackerOne vulnerability disclosure program does exist at https://hackerone.com/centene_vdp. - No MCP server and no A2A agent card. - The FHIR contracts have not been republished since October 2024 while their prose docs were refreshed in 2026. - `servers[0]` in most specs names a development gateway (`dev-int-api-gw.centene.com`), not production. Read production hosts from the portal catalogue instead. ## Optional - [Corporate data privacy & security](https://www.centene.com/why-were-different/corporate-sustainability/business-accountability/data-privacy-security.html) - [Vulnerability disclosure program](https://hackerone.com/centene_vdp) - [CARIN Alliance code of conduct](https://www.carinalliance.com/our-work/trust-framework-and-code-of-conduct/) — referenced by Centene's own portal