# Doceree > Doceree Inc. is a US healthcare marketing technology company (Short Hills, New Jersey) running a global network of physician-only platforms for programmatic messaging and point-of-care advertising to healthcare professionals (HCPs). Its public, machine-readable surface is ad-tech: two concurrent generations of ad-request endpoint, a tracking/beacon endpoint, a hosted publisher tag, a first-party Prebid.js header-bidding adapter, and first-party iOS/Android ad SDKs. This file was GENERATED by API Evangelist from Doceree's public surface, last refreshed 2026-08-12. Doceree does not publish its own /llms.txt at any probed host. This is a third-party profile, not a Doceree document — see https://apievangelist.com/about/where-our-data-comes-from. ## APIs Doceree runs TWO ad-serving generations side by side. Doceree publishes no statement that one supersedes the other, and both were live on 2026-08-12. - [Doceree Bidder / Ad Request API](https://doceree.com/publishers) (web/Prebid generation): `https://bidder.doceree.com` — GET /v1/adrequest returns an HCP-targeted ad payload. Also /v1/doceree-init, /v1/init, /v1/initliveintent (identity), POST /v1/savePOCdata, POST /v1/saveDMDInfo (point-of-care and DMD capture), POST /saveadblockinfo (ad feedback), POST /render/logMessage (client diagnostics). - [Doceree Tracking API](https://doceree.com/publishers): `https://tracking.doceree.com` — GET /v1/hbTimeout and GET /v1/hbBidWon beacons carrying a base64-encoded JSON payload on the `data` parameter. Returns a 42-byte image/gif. - [Doceree DAI mobile ad + identity API](https://github.com/doceree/ios-sdk-new) (current mobile generation, used by iOS SDK 6.x): `https://dai.doceree.com` — POST /drs/quest (ad request), POST /drs/nEvent (clinical session event; uid, sid, hid, status, eType), POST /drs/saveAdBlockInfo, POST /dop/settings?version=1 (remote SDK configuration), POST /dop/getHcpSelfValidation and POST /dop/updateHcpSelfValidation (HCP self-validation). All POST-only; GET returns HTTP 405 with a JSON error body. No version segment in the path. ## Specs - No OpenAPI, AsyncAPI, GraphQL schema, gRPC/protobuf, MCP server, or A2A agent card is published by Doceree. Probed 2026-08-04 and re-probed 2026-08-12 across doceree.com, www.doceree.com, support.doceree.com, bidder.doceree.com, tracking.doceree.com, dai.doceree.com, servedbydoceree.doceree.com, admanager.doceree.com and exchange.doceree.com — all 404/403. api.doceree.com, developer.doceree.com, developers.doceree.com, docs.doceree.com and mcp.doceree.com do not resolve. exchange.doceree.com answers 200 with an HTML SPA shell for every /.well-known/* path; that is a catch-all, not a discovery document. ## How errors work (important for agents) - The ad-serving path returns **HTTP 200 on failure**. The ad object comes back with every field empty and the failure carried inline on `errMessage` / `debugMessage`. Checking the HTTP status alone will read every failure as a success. - Observed codes: `ErrorInvalidSlotIdOrInactivePlatform` ("Invalid slotId Or platform not active.") and `ErrorIpRepeativeCallRejects` ("Ip repetitive call"). On the second one the two members are **swapped** — the identifier is in `debugMessage`, the sentence is in `errMessage`. - `dai.doceree.com` uses a different, Spring-style envelope: `{timestamp, code, status, message}` on 405 and `{timestamp, status, error, path}` on 500. Neither envelope is RFC 9457. - See errors/doceree-problem-types.yml. ## Rate limits - None published, and no RateLimit-*/X-RateLimit-*/Retry-After header on any response. An IP-based repetitive-call throttle IS enforced, but it is returned as HTTP 200 with `errMessage: "Ip repetitive call"` — no 429, no threshold, nothing to back off against. See rate-limits/doceree-rate-limits.yml. ## Pricing - No /pricing page and no plan tiers (doceree.com/pricing is 404). Doceree charges a 10% Tech Access Fee and a 10% Managed Services Fee, both on media spend. Bidding models: CPM, CPS (cost per EHR workflow session), and programmatic. Billing is monthly, with an interim invoice if campaign spend exceeds $500 mid-month. See plans/doceree-plans-pricing.yml. ## Authoritative references - [Doceree iOS SDK — implementation guide](https://github.com/doceree/ios-sdk-new/blob/master/iOS_SDK_Implementation.md) — the single richest public document Doceree publishes: consent (`DocereeConsentBuilder`), HCP / health-associate / generic user login builders, patient data, session attributes, action events, and universal IDs, with real field names and examples. - [Doceree iOS SDK sources](https://github.com/doceree/ios-sdk-new) — MIT licensed. HTTPSupport.swift carries the host/path map for every environment; Constants.swift carries the full query-parameter and header vocabulary. - [Prebid.js bidder documentation for `doceree`](https://docs.prebid.org/dev-docs/bidders/doceree.html) — placementId (required), publisherUrl, gdpr, gdprConsent; banner media type; IAB Europe GVL ID 1063. - [docereeBidAdapter.js source](https://github.com/prebid/Prebid.js/blob/master/modules/docereeBidAdapter.js) — request construction and response field mapping. - [Doceree Publisher Tag](https://servedbydoceree.doceree.com/script/render-header.js) — hosted publisher script, unpinned (no version in the URL). - [Doceree help center](https://support.doceree.com/hc/en-us) — several articles return HTTP 403 to anonymous browsers, but the Zendesk REST API at https://support.doceree.com/api/v2/help_center/en-us/articles.json answers anonymously and returns 117 published articles. - [iOS SDK releases](https://github.com/doceree/ios-sdk-new/releases) — the only dated change record Doceree publishes anywhere. ## Docs and company - Website: https://doceree.com/ - Publishers / integration: https://doceree.com/publishers - Technology: https://doceree.com/technology - EHR: https://doceree.com/ehr - Trust & compliance: https://doceree.com/trust - Support: https://support.doceree.com/hc/en-us - Blog: https://blog.doceree.com/ - GitHub: https://github.com/doceree - Exchange login: https://exchange.doceree.com/login - Terms of service (advertiser, US): https://doceree.com/us-terms-of-service-advertiser - Privacy policy: https://doceree.com/privacy-policy ## API Evangelist artifacts - Authentication: authentication/doceree-authentication.yml - Conventions: conventions/doceree-conventions.yml - Conformance: conformance/doceree-conformance.yml - Errors: errors/doceree-problem-types.yml - Rate limits: rate-limits/doceree-rate-limits.yml - Data model: data-model/doceree-data-model.yml - Plans / pricing: plans/doceree-plans-pricing.yml - Changelog: changelog/doceree-changelog.yml - Sandbox / environments: sandbox/doceree-sandbox.yml - Packages / SDKs: packages/doceree-packages.yml - Embedded components: components/doceree-components.yml - Lifecycle: lifecycle/doceree-lifecycle.yml - Well-known probe index: well-known/doceree-well-known.yml - Domain security: security/doceree-domain-security.yml - Trust center: security/doceree-trust-center.yml ## Known gaps - No OpenAPI or other machine-readable contract, on either API generation. - No /.well-known/ document of any kind on any host, no security.txt, no vulnerability disclosure policy, no security contact. - No status page and no uptime SLA. status.doceree.com does not resolve. - No deprecation policy — and it shows: SDK 6.2.0 removed the "Curator API" with a one-line release note, no sunset window and no migration guide. - No OAuth 2.0 or OIDC; credentials (placementId, token, appKey) travel as query parameters. - No public sandbox or test credentials. A public environment selector exists on the SDK, but its QA/dev hosts are undocumented and uncredentialed, and the healthcare-intake endpoint is hardcoded to a QA host (qa-healthcare.doceree.com/v1/intake) with no published production equivalent. - No server-side SDK in any language; every first-party client is an ad-rendering client. - The published SDK is stale relative to the repo: newest installable release is 6.2.1 (2025-10-10), while the podspec on master declares an unreleased 6.3.0. - No HSTS on doceree.com, bidder.doceree.com or tracking.doceree.com; no CAA records; DNSSEC not enabled; DMARC policy is p=none. - The Android SDK's JitPack coordinates are documented only in a support article that is now 403 to anonymous readers.