# Flume Health > Healthcare data platform for the payer ecosystem. Relay is an integration platform (iPaaS) that moves eligibility, claims and other health-plan data between source and destination Endpoints — SFTP, cloud storage, databases, Snowflake, the Flume Lakehouse, and APIs — through a canonical Flume Data Model. A newer Context layer builds a knowledge graph over a customer's data estate and exposes it to AI agents. Enterprise, contract-only; no self-serve tier. GENERATED BY API EVANGELIST. Flume Health does not publish an llms.txt at www.flumehealth.com/llms.txt (HTTP 404) or docs.flumehealth.com/llms.txt (HTTP 404). This file is assembled from Flume's own published OpenAPI contract and public pages, harvested 2026-08-16. It is a third-party profile, not a Flume document. ## API at a glance - Contract: Swagger 2.0, 108 paths, 153 operations, 270 definitions - Machine-readable spec: https://console.flumehealth.com/api/docs/docs.json - Rendered reference (Redoc): https://console.flumehealth.com/api/docs - Base URL: https://console.flumehealth.com - Auth: OAuth 2.0 / OpenID Connect bearer token, issuer https://auth.flumehealth.com/ - Token endpoint: https://auth.flumehealth.com/oauth/token, audience https://console.flumehealth.com/api - Tenancy: `X-Flume-Account-ID` header, required on 122 of 153 operations. Get ids from GET /api/v1/accounts. - Pagination: cursor — `pageToken` + `pageSize` in, `nextPageToken` out - Errors: vendor envelope `{ code, message, details[] }` as application/json. NOT RFC 9457 problem+json. - Tracing: `x-trace-id` response header on every response - Idempotency: none. No Idempotency-Key on any operation. - Rate limits: none documented, no rate-limit response headers observed. - Versions live: /api/v1/ (148 ops) and /api/v2/trades/ (5 ops) ## Agent surface - Remote MCP endpoint: https://console.flumehealth.com/api/v1/context/mcp - MCP auth: OAuth 2.0. Anonymous JSON-RPC returns HTTP 401 with `WWW-Authenticate: Bearer resource_metadata=...` - Protected-resource metadata (RFC 9728): https://console.flumehealth.com/.well-known/oauth-protected-resource - Authorization server metadata: https://auth.flumehealth.com/.well-known/oauth-authorization-server - Dynamic client registration: https://auth.flumehealth.com/oidc/register - MCP scopes advertised: openid, profile, email, offline_access - The MCP tool list is NOT readable anonymously. Do not assume tool names. - No A2A agent card is served on any Flume host (/.well-known/agent-card.json and /.well-known/agent.json both 404). ## Operation families - Accounts (8) — /api/v1/accounts, account config and secrets - Account Contracts (4) — /api/v1/accounts/{id}/contracts - Connections (4) — /api/v1/connections, the trading-partner relationship - Endpoints (29) — /api/v1/endpoints, per-protocol secrets and connection tests, datalake ingest/query/write - Endpoint Maps (2) — /api/v1/endpoints/{id}/maps/{fieldType}, ordinal-versioned - Shards (3) — /api/v1/endpoints/{endpointId}/shards - Transactions (4) — /api/v1/endpoints/{endpointId}/transactions - Source Files (7) — /api/v1/sourceFiles, with :bulk and :search - Objects (10) — /api/v1/objects and object instances, with :bulk - Context Discovery (23) — approver-gated, time-boxed access sessions for tooling, with an audit log - Context Knowledge (28) — knowledge entries, review queue, artifacts by content hash, attach/supersede/erase - Context Graph (3) — graph status, :query, :search - Jobs v2 (5) + AutomapJobs (5) — /api/v2/trades/jobs, field-mapping jobs and versioned automap runs - Users (8), Flags (5), WorkerSizes (3), Reports (1), Telemetry (1) ## Conventions Non-CRUD state changes use Google AIP-136 colon verbs on the resource path, consistently: `sessions/{id}:approve`, `:deny`, `:cancel`, `:extend`, `:revoke`, `sessions:grant`, `knowledge/{id}:attach`, `:detach`, `:erase`, `:supersede`, `:link-artifact`, `knowledge:bulk`, `review-items/{id}:approve`, `:merge`, `:reject`, `:dismiss`, `sourceFiles:bulk`, `sourceFiles:search`, `instances:bulk`, `graph:query`, `graph:search`. ## Repository artifacts (API Evangelist) - openapi/flume-health-console-api-openapi.yml — the harvested contract - openapi/_original/flume-health-openapi.json — verbatim as served - authentication/flume-health-authentication.yml - scopes/flume-health-scopes.yml - conventions/flume-health-conventions.yml - errors/flume-health-problem-types.yml - data-model/flume-health-data-model.yml - mcp/flume-health-mcp.yml, mcp/flume-health-tool-crosswalk.yml - well-known/flume-health-well-known.yml - conformance/flume-health-conformance.yml - lifecycle/flume-health-lifecycle.yml - security/flume-health-domain-security.yml, security/flume-health-trust-center.yml - plans/flume-health-plans-pricing.yml, rate-limits/flume-health-rate-limits.yml - packages/flume-health-packages.yml - overlays/flume-health-console-api-overlay.yaml - skills/_index.yml and four packaged Agent Skills ## Human pages - Website: https://www.flumehealth.com/ - Platform: https://www.flumehealth.com/platform - Developers: https://www.flumehealth.com/developers - Concept docs: https://docs.flumehealth.com/ - Support portal: https://support.flumehealth.com/portal/en/home - Status: https://status.flumehealth.com/ - Security: https://www.flumehealth.com/security - Terms: https://www.flumehealth.com/terms - Privacy: https://www.flumehealth.com/privacy - Console / login: https://console.flumehealth.com/ - Sales contact: sales@flumehealth.com ## Cautions for agents - www.flumehealth.com/developers advertises Python and TypeScript SDKs, a CLI, and endpoints /api/v1/trace, /api/v1/impact, /api/v1/recover, /api/v1/audit and /api/v1/status. NONE of those endpoints exist in Flume's published contract, and no SDK or CLI is published to npm, PyPI, or the github.com/flumehealth organization (0 public repos). Treat that page as marketing copy, not as an integration reference. - api.flumehealth.com still resolves but serves a TLS certificate for api.vitorihealth.com and returns 404 on every path. Vitori Health acquired Flume's third-party administrator operations in 2023; the Redoc reference now at api.vitorihealth.com is VITORI's contract, not Flume's. Do not attribute it to Flume. - flumetech.readme.io is Flume Water, an unrelated water-monitoring company. Not Flume Health. - The security.txt served at status.flumehealth.com is Atlassian Statuspage's, not Flume's. Flume serves no security.txt on any host it controls. ## Compliance claims - SOC 2 Type II, HITRUST CSF, and "HIPAA-aligned controls" are named at https://www.flumehealth.com/security. No trust portal, no auditor, no attestation date, and no evidence artifact is published behind those claims. - No vulnerability disclosure policy and no bug bounty were found on any Flume host. Last harvested: 2026-08-16