# Harbinger Health > Harbinger Health is a Cambridge, Massachusetts biotechnology company founded out of Flagship Pioneering's Flagship Labs in 2018, building blood-based early cancer detection on the Harbinger HX platform (cell-free DNA methylation plus biologically constrained machine learning) and its clinical application, RESOLVE. **Harbinger Health publishes no developer API, no documentation and no SDKs.** This file was GENERATED by API Evangelist from public probes of harbinger-health.com on 2026-08-04 — it is not published by Harbinger Health. Everything below describes the corporate website's surfaces, not any clinical, laboratory or diagnostic system. ## What is and is not callable - **Not callable, not documented, not public:** anything to do with Harbinger HX, RESOLVE, specimens, assays, methylation signals, tumour fraction, tissue-of-origin calls, test orders, results or patients. No FHIR, no HL7, no GA4GH surface exists on any Harbinger Health host. - **Callable anonymously:** the WordPress REST API of the corporate site — articles, pages, an `events` custom post type, media, categories, tags and site search. - **Callable with OAuth:** a real Model Context Protocol server on the provider's own origin, guarded by scope `mcp`. The tool list is auth-gated and is NOT reproduced here, because it has not been observed. ## APIs - [Harbinger Health WordPress REST API](https://harbinger-health.com/wp-json/): 268 routes across 15 namespaces; the `wp/v2` content namespace is anonymously readable in `view`/`embed` context. Base URL `https://harbinger-health.com/wp-json`. - [Harbinger Health MCP Server](https://harbinger-health.com/wp-json/mcp/mcp-oauth-server): JSON-RPC 2.0 Model Context Protocol endpoint. Anonymous `tools/list` returns HTTP 401 `mcp_unauthorized`. - [Harbinger Health MCP adapter default server](https://harbinger-health.com/wp-json/mcp/mcp-adapter-default-server): second registered MCP server; anonymous calls return 401 `rest_forbidden`. - [WordPress Abilities API](https://harbinger-health.com/wp-json/wp-abilities/v1/abilities): the probable tool source for the MCP servers; 401 to anonymous callers. ## Discovery documents served by the provider - [/wp-json/](https://harbinger-health.com/wp-json/): WordPress route-discovery document, 200 application/json. - [/.well-known/oauth-authorization-server](https://harbinger-health.com/.well-known/oauth-authorization-server): RFC 8414 metadata. Authorization code + refresh token, PKCE S256, public clients, client-ID metadata documents, `scopes_supported: ["mcp"]`. - [/.well-known/oauth-protected-resource](https://harbinger-health.com/.well-known/oauth-protected-resource): RFC 9728 metadata naming the MCP server as the protected resource. - [/robots.txt](https://harbinger-health.com/robots.txt) and [/sitemap_index.xml](https://harbinger-health.com/sitemap_index.xml). Not served: `/.well-known/security.txt`, `/.well-known/openid-configuration`, `/.well-known/api-catalog`, `/.well-known/ai-plugin.json`, `/.well-known/agent-card.json`, `/.well-known/agent.json`, `/llms.txt`, `/openapi.json`, `/graphql` — all 404. ## Specs and artifacts (API Evangelist, derived — not provider artifacts) - [OpenAPI 3.1 for wp/v2](openapi/harbinger-health-wordpress-wp-v2-openapi.yml): 110 paths, 236 operations, derived from the route-discovery document. - [Verbatim route-discovery document](openapi/harbinger-health-wp-json-discovery.json) - [Authentication profile](authentication/harbinger-health-authentication.yml) - [OAuth scopes](scopes/harbinger-health-scopes.yml) - [MCP server manifest](mcp/harbinger-health-mcp.yml) and [tool crosswalk](mcp/harbinger-health-tool-crosswalk.yml) - [API conventions](conventions/harbinger-health-conventions.yml) - [Error catalogue](errors/harbinger-health-problem-types.yml) - [Data model](data-model/harbinger-health-data-model.yml) - [Lifecycle](lifecycle/harbinger-health-lifecycle.yml) - [Conformance](conformance/harbinger-health-conformance.yml) - [Domain security](security/harbinger-health-domain-security.yml) - [Well-known index](well-known/harbinger-health-well-known.yml) - [Live response examples](examples/_index.yml) - [Agent skills](skills/_index.yml) ## How to call the public content API Authentication: none required for reads in `view`/`embed` context. Writes and `context=edit` require a WordPress application password over HTTP Basic. Pagination: `page` (default 1) and `per_page` (default 10, max 100). Totals come back in `X-WP-Total` and `X-WP-TotalPages`; the next page is in the RFC 8288 `Link` header. Use `_fields` for sparse fieldsets and `_embed` to expand `_links`. Errors: not RFC 9457. The envelope is `{"code": "...", "message": "...", "data": {"status": N}}`. A method mismatch returns 404 `rest_no_route`, not 405. Rate limits: none advertised. No `RateLimit-*` or `Retry-After` header is returned. `robots.txt` requests `Crawl-delay: 10` from crawlers. ## Docs - [Company](https://harbinger-health.com/) · [About](https://harbinger-health.com/about/) · [RESOLVE](https://harbinger-health.com/resolve/) · [Platform technology](https://harbinger-health.com/platform-technology/) · [The science](https://harbinger-health.com/the-science/) - [News and insights](https://harbinger-health.com/news-insights/) · [Partnerships](https://harbinger-health.com/partnerships/) · [Careers](https://harbinger-health.com/job/) · [Contact](https://harbinger-health.com/contact/) - [Terms of use](https://harbinger-health.com/terms-of-use/) · [Privacy policy](https://harbinger-health.com/privacy-policy/) - Upstream reference for the callable surface: [WordPress REST API handbook](https://developer.wordpress.org/rest-api/) ## Compliance Published in the site footer on every page: "Harbinger health laboratory is CLIA certified and CAP accredited, meeting all nationally recognized standards for high complexity testing." These are laboratory credentials and say nothing about the API surface described above. No SOC 2, ISO 27001, HIPAA statement or trust centre is published. ## Contact info@harbinger-health.com · press@harbinger-health.com · partnerships@harbinger-health.com · 25 Spinelli Place, Cambridge, MA 02138