generated: '2026-08-15' method: derived source: openapi/luma-health-openapi.yaml (re-fetched 2026-08-15) authentication: style: oauth2-client-credentials -> jwt bearer header: 'Authorization: Bearer ' detail: authentication/luma-health-authentication.yml base_url: https://api.lumahealth.io/api/v2 object_ids: format: 24-char lowercase hex (MongoDB ObjectId) pattern: '[0-9a-f]{24}' common_query_params: - _id (Luma internal object id) - user (root account user id) - deleted (0|1 soft-delete filter) idempotency: supported: false note: >- No Idempotency-Key header/parameter is documented. The word "idempotent" appears once in the spec but only describes checklist-template seeding behavior, not a client-supplied idempotency contract. Do NOT treat writes as safely retryable without dedupe on the caller side. pagination: style: page-number params: - page - limit response_envelopes: - shape: '{ : [...], page, ... }' note: the older/majority collection shape - shape: '{ response: [...], page, size }' note: >- used by the feedbackResponses* collections added in 2026-08. The API does NOT use one collection envelope throughout - clients must not assume a single shape across resources. note: >- List endpoints expose page and limit query parameters (offset/page-number paging). Not all collections advertise both; some also accept sort. No cursor paging, no Link headers, no total-count header. sorting: param: sort note: available on some list operations (e.g. availabilities) metadata: note: no standard cross-resource metadata envelope documented request_tracing: request_id_header: null note: no documented request-id/trace header versioning: style: uri-path (/api/v2) detail: lifecycle/luma-health-lifecycle.yml error_envelope: media_type: application/json shape: '{ "message": string }' detail: errors/luma-health-problem-types.yml rate_limiting: signal: null detail: rate-limits/luma-health-rate-limits.yml note: >- No published rate-limit headers and no documented quotas. Re-verified 2026-08-15 against the 278-operation spec: zero 429 responses declared, and no RateLimit-*, X-RateLimit-* or Retry-After header anywhere. code_samples: present: true format: OpenAPI x-codeSamples langs: [cURL] note: >- x-codeSamples blocks are attached only to the /auth/clients operations (POST and PATCH). The other 276 operations carry no sample, so Redoc renders generated requests for the rest of the API. sandbox: published: false note: >- No sandbox or test-mode host, no test credentials and no fixture tooling are published. https://api.lumahealth.io/api/v2 is the only environment named in servers[]; sandbox.lumahealth.io does not resolve.