# LightForce Orthodontics > LightForce Orthodontics, Inc. (lf.co) is a medical device and digital manufacturing company making "generative braces" — fully customized, 3D-printed orthodontic brackets (LightBracket ceramic and metal) and indirect bonding trays, generated from each patient's own tooth anatomy and the treating orthodontist's digital treatment plan. LightForce does not publish a public developer API, developer portal, SDK, or API specification. Its only publicly machine-discoverable API surface is the OpenID Connect identity host that fronts the LightForce Doctor Portal. Generated by the API Evangelist enrichment pipeline on 2026-07-19 from live probes of lf.co, kb.lightforceortho.com, id.lightforceortho.com, github.com/lightforceortho, and the public package registries. Method: generated (no provider-published llms.txt exists at lf.co/llms.txt — 404). ## APIs - [LightForce Identity (OpenID Connect)](https://id.lightforceortho.com/.well-known/openid-configuration): Live OIDC discovery document for the Auth0-hosted identity tenant that authenticates orthodontic practice users into the LightForce Doctor Portal. Base URL https://id.lightforceortho.com. Supports authorization code + PKCE, client credentials, device code, token exchange, refresh tokens, CIBA back-channel authentication, DPoP, MFA, and back-channel logout. ## Specs and artifacts - [OpenID configuration](well-known/lightforce-openid-configuration.json): saved verbatim from the live discovery endpoint. - [OAuth authorization server metadata](well-known/lightforce-oauth-authorization-server.json): RFC 8414 metadata, saved verbatim. - [JWKS](well-known/lightforce-jwks.json): signing keys, saved verbatim. - [Well-known index](well-known/lightforce-well-known.yml): every /.well-known/ path probed on lf.co and id.lightforceortho.com, with HTTP status. - [Authentication profile](authentication/lightforce-authentication.yml): full endpoint, grant type, and token-auth-method profile. - [OAuth scopes](scopes/lightforce-scopes.yml): the 14 identity scopes advertised in discovery. - [Conformance](conformance/lightforce-conformance.yml): standards asserted with evidence (OIDC Core/Discovery, OAuth 2.0, PKCE, device grant, token exchange, revocation, dynamic client registration, DPoP, CIBA, HIPAA). - [Conventions](conventions/lightforce-conventions.yml): cross-cutting semantics; most are recorded as unknown because no public API is documented. - [Domain security](security/lightforce-domain-security.yml): TLS/HSTS/DNS posture probed live. - [Packages](packages/lightforce-packages.yml): verified-empty — no first-party client library on npm, PyPI, RubyGems, or crates.io. ## Docs - [LightForce homepage](https://lf.co): product overview for doctors and patients. - [The LightForce Advantage](https://lf.co/doctors/lightforce-advantage): features and benefits of the generative braces system. - [Doctor resources](https://lf.co/doctors/resources): industry studies and practice success stories. - [Get started (doctors)](https://lf.co/doctors/get-started): onboarding for orthodontic practices. - [Support Center](https://kb.lightforceortho.com/en/): knowledge base and common questions. - [Contact and support](https://lf.co/contact): support@lightforceortho.com, +1 866 506 3070 (US), Mon-Fri 8:00-20:00 ET. - [Blog](https://lf.co/blog): company and clinical posts. - [Press and media](https://lf.co/press-media): coverage and announcements. ## Company - [About LightForce](https://lf.co/about) - [Investors](https://lf.co/investors) - [Careers](https://lf.co/careers) - [GitHub organization](https://github.com/lightforceortho): 12 public repositories, all forks of third-party open source. ## Legal and compliance - [HIPAA Notice of Privacy Practices](https://lf.co/legal/hipaa): PHI notice, effective 2026-01-16; privacy@lfo.co. - [Privacy policy](https://lf.co/legal/privacy) - [Terms](https://lf.co/legal/terms) - [Cookies](https://lf.co/legal/cookies) ## Notes for agents - There is no public LightForce API to call. Do not attempt to construct LightForce API requests — no base URL, resource model, or API key program is published. - No /.well-known/security.txt is published on either host; there is no public bug bounty or vulnerability disclosure program. - LightForce handles Protected Health Information. Any integration work is subject to HIPAA and would run through a business relationship, not a self-serve developer program.