# Healthie > Healthie is an API-first, cloud EHR and practice-management platform for digital health > startups, virtual care companies and modern clinical practices. A single GraphQL API — the > same contract that powers Healthie's own web, iOS and Android apps — exposes scheduling, > charting, telehealth, intake forms, care plans, online programs, messaging, billing, > CMS-1500 claims, lab orders, e-prescribing and the patient portal. Healthie is HIPAA, SOC 2 > Type 2, HITRUST r2 and ONC Health IT certified. Generated by API Evangelist on 2026-08-14. Healthie publishes no llms.txt of its own — https://docs.gethealthie.com/llms.txt and https://www.gethealthie.com/llms.txt both return 404. Individual docs pages ARE available as markdown by appending `/index.md` to the page path (for example https://docs.gethealthie.com/guides/intro/index.md), which is the closest thing Healthie ships to a machine-readable docs surface. ## What an agent needs to know first - The contract is **GraphQL, not REST**. There is no OpenAPI: `/openapi.json`, `/swagger.json`, `/api-docs` and `/v1/openapi.json` all return 404 on api.gethealthie.com. - Production: `https://api.gethealthie.com/graphql`. Sandbox: `https://staging-api.gethealthie.com/graphql`. The two are fully isolated and record IDs do not transfer between them. - Auth is a static per-user API key in headers: `Authorization: Basic ` plus `AuthorizationSource: API` (and `AuthorizationShard: ` for sharded customers). Despite the word "Basic" this is not HTTP Basic auth — send the raw key. There is no OAuth and no OIDC. - A key inherits the permissions of the Healthie **user account** it is attached to. There are no OAuth scopes; you narrow access by provisioning the underlying user. - Version with the `Healthie-GraphQL-API-Version` header. No header means the `2024-06-01` baseline. Latest is `2026-01-01`. Only breaking changes are gated by version; additive changes land in every version immediately. - **There is no idempotency.** `clientMutationId` is documented as unused and was removed in version 2025-10-15. A retried write can duplicate a clinical or financial record. De-duplicate on your side. - **Check `messages` on every mutation.** Validation failures return HTTP 200 with an empty GraphQL `errors[]` array and a populated `messages: [{ field, message }]` list on the payload. A client that only inspects `errors` will read a failed write as a success. - Limits are cost-based: max query complexity 2000, max depth 25, plus an undocumented dynamic request rate. No rate-limit response headers and no `Retry-After` are published. - Anonymous GraphQL introspection is refused on production (HTTP 500) but open on the sandbox endpoint, which serves the same schema. ## Specs - [GraphQL schema (SDL)](https://raw.githubusercontent.com/api-evangelist/healthie/refs/heads/main/graphql/healthie-schema.graphql): The full Healthie GraphQL schema — 386 queries, 427 mutations, 6 subscriptions, 1,583 types. Captured by introspection of the sandbox endpoint. - [Webhooks AsyncAPI 2.6](https://raw.githubusercontent.com/api-evangelist/healthie/refs/heads/main/asyncapi/healthie-webhooks-asyncapi.yml): The outbound HTTP webhook surface, derived from Healthie's webhook docs and event reference. - [Subscriptions AsyncAPI 2.6](https://raw.githubusercontent.com/api-evangelist/healthie/refs/heads/main/asyncapi/healthie-subscriptions-asyncapi.yml): The GraphQL-over-WebSocket surface (ActionCable/AnyCable), derived from the subscription docs and the schema. ## APIs - [Healthie GraphQL API](https://docs.gethealthie.com/): Single endpoint at https://api.gethealthie.com/graphql covering clients, appointments, availability, charting, forms, care plans, goals, allergies, immunizations, medications, diagnoses, lab orders, CMS-1500 claims, insurance authorizations and eligibility, payments, online programs, conversations, messaging, faxing and announcements. ## Docs - [Developer documentation](https://docs.gethealthie.com/): Root of the Healthie developer docs. - [Quickstart](https://docs.gethealthie.com/guides/quickstart): Getting started. - [Schema reference](https://docs.gethealthie.com/reference): Browsable, version-pinned GraphQL schema reference. - [API Explorer / GraphiQL](https://docs.gethealthie.com/graphiql): Hosted query console. - [Authentication](https://docs.gethealthie.com/guides/api-concepts/authentication): API keys, headers, the createApiKey mutation, service-account vs per-user key patterns. - [Environments](https://docs.gethealthie.com/guides/api-concepts/environments): Sandbox vs production, and which integrations work in the sandbox. - [Versioning](https://docs.gethealthie.com/guides/api-concepts/versioning): Date-based opt-in versions and the full breaking-change history. - [Deprecations](https://docs.gethealthie.com/guides/api-concepts/deprecations): Deprecation policy — minimum six months' notice, expressed via the GraphQL @deprecated directive. - [Changelog](https://docs.gethealthie.com/guides/api-concepts/changelog): Weekly, dated, non-breaking schema diffs. - [Rate limits](https://docs.gethealthie.com/guides/api-concepts/rate-limits): Complexity scoring, depth limit, and how complexity is calculated. - [Error handling](https://docs.gethealthie.com/guides/api-concepts/error-handling): GraphQL error semantics and known non-conformances. - [Pagination](https://docs.gethealthie.com/guides/api-concepts/pagination): Cursor pagination (preferred) and legacy offset pagination. - [Client mutation ID](https://docs.gethealthie.com/guides/api-concepts/client-mutation-id): Why clientMutationId is unused. - [File uploads](https://docs.gethealthie.com/guides/api-concepts/file-uploads) - [Timezones](https://docs.gethealthie.com/guides/api-concepts/timezones) - [Webhooks](https://docs.gethealthie.com/guides/webhooks): Thin-payload webhooks with HMAC-SHA256 signatures, retry for up to 3 days, auto-disable. - [Webhook event reference](https://docs.gethealthie.com/guides/webhooks/event-reference/) - [WebSockets and subscriptions](https://docs.gethealthie.com/guides/websockets-and-subscriptions/getting-started/): ActionCable/AnyCable — NOT the Apollo websocket subprotocol. - [React SDKs](https://docs.gethealthie.com/guides/react-sdks/): Chat, Forms, and Booking & Buying components. - [Integrations](https://docs.gethealthie.com/guides/integrations/): Working with Fullscript and lab integrations through the API. ## Domain guides - [Scheduling — appointments](https://docs.gethealthie.com/guides/scheduling/appointments/) - [Scheduling — availability](https://docs.gethealthie.com/guides/scheduling/availability/) - [Scheduling — patient scheduling](https://docs.gethealthie.com/guides/scheduling/patient_scheduling/) - [Forms](https://docs.gethealthie.com/guides/forms/) - [Filled-out forms](https://docs.gethealthie.com/guides/filled_out_forms/) - [Care plans](https://docs.gethealthie.com/guides/care-plans/) - [Goals](https://docs.gethealthie.com/guides/goals/) - [Metrics](https://docs.gethealthie.com/guides/metrics/) - [Journal entries](https://docs.gethealthie.com/guides/journal/) - [Medications](https://docs.gethealthie.com/guides/medications/) - [Lab orders](https://docs.gethealthie.com/guides/lab_orders/) - [Patient encounters and episodes of care](https://docs.gethealthie.com/guides/patient-encounters-episodes-of-care/overview/) - [Insurance](https://docs.gethealthie.com/guides/insurance/) - [Billing items](https://docs.gethealthie.com/guides/billing/billing-items/) - [Invoices](https://docs.gethealthie.com/guides/billing/invoices/) - [Packages](https://docs.gethealthie.com/guides/billing/packages/) - [Payment processing](https://docs.gethealthie.com/guides/billing/payment-processing/) - [Insurance payments](https://docs.gethealthie.com/guides/billing/insurance-payments/) - [Chat](https://docs.gethealthie.com/guides/chat/) - [Documents](https://docs.gethealthie.com/guides/documents/) - [Tasks](https://docs.gethealthie.com/guides/tasks/) - [Programs](https://docs.gethealthie.com/guides/programs/) - [Audit logs](https://docs.gethealthie.com/guides/audit-logs/audit-logs/) - [Organization](https://docs.gethealthie.com/guides/organization/) - [User accounts](https://docs.gethealthie.com/guides/user_accounts/) - [Video chat](https://docs.gethealthie.com/guides/video_chat/) - [Faxing](https://docs.gethealthie.com/guides/faxing/sent_faxes/) ## Tooling - [Healthie Dev Assist (MCP server)](https://github.com/healthie/healthie-dev-assist): First-party MCP server, MIT licensed. Local stdio only — clone and run it; there is no hosted endpoint. Exposes one code-execution tool (`execute_healthie_code`) plus `regenerate_schema`. - [@healthie/sdk on npm](https://www.npmjs.com/package/@healthie/sdk): React components for Chat, Forms and Booking & Buying. - [Sample booking widget](https://github.com/healthie/healthie_sample_booking_widget): Reference implementation. - [GitHub organization](https://github.com/healthie) ## Company - [Website](https://www.gethealthie.com/) - [API platform](https://www.gethealthie.com/api) - [Pricing](https://www.gethealthie.com/pricing): Four self-serve practice plans. API access is sold separately as Healthie+ with no published price. - [Security and compliance](https://www.gethealthie.com/security) - [Trust center](https://trust.gethealthie.com) - [Business Associate Agreement](https://www.gethealthie.com/baa) - [Status](https://status.gethealthie.com/) - [Roadmap](https://portal.productboard.com/gethealthie/1-healthie-product-portal/tabs/4-in-development) - [Help center](https://help.gethealthie.com/) - [Healthie Harbor (integration marketplace)](https://harbor.gethealthie.com/) - [Blog](https://www.gethealthie.com/blog) - [Terms of use](https://www.gethealthie.com/terms) - [Privacy policy](https://www.gethealthie.com/privacy) ## Contact - Developer and API questions: hello@gethealthie.com - Compliance and security questionnaires: compliance@gethealthie.com - No security.txt and no published vulnerability disclosure program (checked 2026-08-14).