# DIPS AS > DIPS AS is Norway's largest supplier of electronic health record systems to hospitals, in > operation since 1987 and headquartered in Bodø. Its DIPS Arena EHR is built on the openEHR > reference model and exposes HL7 FHIR R4 and openEHR REST interfaces. Open DIPS is its public > developer programme: a synthetic-data sandbox, an OpenID Connect provider, a FHIR API, and a > published FHIR R4 Implementation Guide. Generated by API Evangelist on 2026-09-02 from artifacts in this repository and from pages fetched anonymously from DIPS's own hosts. DIPS AS does not publish an llms.txt of its own (https://dips.developer.azure-api.net/llms.txt and https://www.dips.com/llms.txt both return 404). This file is a third-party profile, not a DIPS document. ## What is actually callable Two credentials are needed at once on every request to api.dips.no: an Azure API Management subscription key (`Ocp-Apim-Subscription-Key`) obtained by signing up at the developer portal, and an OpenID Connect access token from the DIPS Federation Service. A request with only one of them returns HTTP 401. - DIPS Federation Service — https://api.dips.no/dips.oauth — OpenID Connect provider and OAuth 2.0 authorization server, built on IdentityServer4. 25 published operations. This is the only API the Open DIPS portal lists without signing in. - DIPS FHIR R4 API — https://api.dips.no/fhir — clinical and administrative data from DIPS Arena. Requires a subscription key; anonymous requests return 401. Profiled by the DIPS Core Implementation Guide. - openEHR REST — DIPS Arena implements the openEHR EHR, Composition and Query (AQL) services. Not exposed on the anonymous Open DIPS gateway. ## Developer surface - Developer portal: https://dips.developer.azure-api.net/ - Getting started: https://dips.developer.azure-api.net/getting-started - API list: https://dips.developer.azure-api.net/apis - Sandbox test data: https://dips.developer.azure-api.net/data - Sign up: https://dips.developer.azure-api.net/signup - Terms of service: https://dips.developer.azure-api.net/terms - Partner programme: https://dips.developer.azure-api.net/partner - GitHub organisation: https://github.com/DIPSAS - DIPS Core FHIR R4 Implementation Guide: https://dipsas.github.io/FHIR-IG/ - Contact: open@dips.no ## Standards this provider actually declares - OAuth 2.0 and OpenID Connect — live discovery document at https://api.dips.no/dips.oauth/.well-known/openid-configuration, with PKCE (S256), token introspection (RFC 7662), revocation (RFC 7009), device code (RFC 8628), JWT bearer (RFC 7523) and SAML 2.0 bearer (RFC 7522) grants, plus CIBA. - HL7 FHIR R4 (4.0.1) — package dips.fhir.no.core 0.1.0, canonical http://dips.no/fhir/R4, 145 StructureDefinitions, 40 ValueSets, 7 CodeSystems, licence CC0-1.0. - HL7 FHIR Norwegian base profiles — depends on hl7.fhir.no.basis 2.1.2. - SMART App Launch — the issuer advertises launch, launch/patient, patient, patient/*.read, fhirUser and offline_access. Reference app: https://github.com/DIPSAS/hello-open-dips. - openEHR — DIPS publishes its validated archetypes (github.com/DIPSAS/archetypes), openEHR REST clients in R and Python, an AQL VS Code extension and openEHR conformance material. ## What this provider does NOT publish Recording these so an agent does not waste calls looking. - No status page. status.dips.no and status.dips.com do not resolve; www.dips.com/status is 404. The substitute is https://api.dips.no/dips.oauth/status/health, which answers anonymously. - No changelog or release notes. - No versioning policy, no deprecation policy, no Sunset or Deprecation headers. - No SLA — the terms explicitly disclaim availability. - No published rate limits and no RateLimit-* or Retry-After headers. - No pricing page. Public APIs are free; partner and production access is negotiated. - No idempotency keys and no dry-run mode. - No RFC 9457 problem+json — errors are the OAuth error object, the Azure gateway {statusCode, message} object, or a FHIR OperationOutcome. - No MCP server and no A2A agent card. Probes of /mcp and /.well-known/agent-card.json return 404 on every DIPS host. - No security.txt and no published vulnerability-disclosure programme or trust centre. - No first-party SDK for the REST APIs. The published integration path is a generic certified OpenID Connect library plus a generic FHIR client. ## Artifacts in this repository - openapi/dips-federation-service-openapi.yml — 25 operations, 19 paths, 23 schemas - openapi/_original/ — the portal's own OpenAPI 3.0.1 and Swagger 2.0 exports, verbatim - well-known/ — the live OIDC discovery document and JWKS, plus the full probe record - scopes/dips-scopes.yml — all 49 scopes the issuer advertises - authentication/dips-authentication.yml - conformance/dips-conformance.yml and the DIPS Core ImplementationGuide resource - data-model/dips-data-model.yml — the FHIR entity graph, derived from the DIPS profiles - conventions/dips-conventions.yml — including the reversibility assessment - errors/dips-problem-types.yml - lifecycle/dips-lifecycle.yml - plans/dips-plans-pricing.yml, rate-limits/dips-rate-limits.yml - sandbox/dips-sandbox.yml — test user, test patients, reference app - packages/dips-packages.yml - overlays/dips-federation-service-overlay.yaml - mcp/dips-mcp.yml — a candidate tool surface; DIPS ships no MCP server - skills/ — three packaged agent skills