# Luma Health > Luma Health is a United States patient-engagement (Patient Success) platform for healthcare provider organizations. Its operational AI platform automates the patient journey - self-service scheduling, referral and waitlist management, digital intake and forms, omnichannel two-way messaging and broadcast, appointment reminders and recalls, insurance eligibility verification, payments and billing, patient feedback and reputation management, and a conversational AI assistant (Navigator/lumabot) - and integrates bidirectionally with the major EHRs (Epic, Oracle Health/Cerner, MEDITECH, eClinicalWorks, athenahealth, NextGen, Greenway, Nextech). The public developer surface is a REST API (Rest-Service v2.0.0, OpenAPI 3.0.0, 151 paths / 278 operations as of 2026-08-15) at https://api.lumahealth.io/api/v2, secured with OAuth2 client-credentials that issue JWT bearer tokens. Luma Health does not publish this file; API Evangelist generated it from the provider's own published OpenAPI and public pages. ## APIs - [Scheduling & Appointments API](https://apidocs.lumahealth.io/#tag/appointments): Self-service scheduling, appointment lifecycle, appointment types, provider availabilities, offers, recalls, and waitlists. - [Patients API](https://apidocs.lumahealth.io/#tag/patients): Patient demographics and records, patient forms, and stored credit cards. - [Providers & Facilities API](https://apidocs.lumahealth.io/#tag/providers): Providers, scheduling groups, facilities, specialties, groups, and users. - [Messaging & Engagement API](https://apidocs.lumahealth.io/#tag/messages): Two-way patient messaging, engagements, reminders, and message templates. - [Broadcast & Campaigns API](https://apidocs.lumahealth.io/#tag/broadcastFlows): Broadcast events, flows, templates, and outreach campaigns. - [Intake & Forms API](https://apidocs.lumahealth.io/#tag/checklists): Digital intake via checklists and templates, patient forms, and file uploads. - [Billing & Payments API](https://apidocs.lumahealth.io/#tag/billingCharges): Billing charges, copays, cost estimates, and patient credit-card instruments. - [Eligibility & Insurance API](https://apidocs.lumahealth.io/#tag/insurances): Insurance records with real-time eligibility verification and the payors directory. - [Referrals API](https://apidocs.lumahealth.io/#tag/referrals): Inbound and outbound referral management. - [Feedback & Reputation API](https://apidocs.lumahealth.io/#tag/feedbackResponses): NPS survey responses, Google Business Profile and Yelp reviews with AI-extracted sentiment and themes, AI-drafted review replies with an approve/reject workflow, and per-patient review-platform rotation history. - [Conversational AI Assistant API](https://apidocs.lumahealth.io/#tag/assistantInstances): Navigator/lumabot assistant instances and actions, flows, knowledge base, chat activities, and queue routing. - [Reporting & Audits API](https://apidocs.lumahealth.io/#tag/reports): Operational reports plus system and chat audit trails. - [Authentication API](https://apidocs.lumahealth.io/#tag/auth): OAuth2 client-credentials - generate/rotate client id/secret and exchange for JWT access tokens. ## Specs - [OpenAPI (Rest-Service 2.0.0)](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/openapi/luma-health-openapi.yaml) - captured verbatim from https://apidocs.lumahealth.io/public.yaml - [API Evangelist overlay](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/overlays/luma-health-openapi-overlay.yaml) ## Auth - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/authentication/luma-health-authentication.yml): OAuth2 client-credentials -> JWT bearer. `POST /auth/clients` mints a clientId/clientSecret, `POST /auth/token` with `grant_type=client_credentials` exchanges them for a short-lived JWT. No scopes surface, no OAuth discovery document. ## Conventions & semantics - [API conventions](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/conventions/luma-health-conventions.yml): 24-char hex object ids, page/limit pagination, `{ "message": string }` error envelope, no idempotency key. - [Error catalog](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/errors/luma-health-problem-types.yml) - [Rate limits](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/rate-limits/luma-health-rate-limits.yml): none published - no 429 declared on any operation, no RateLimit-*/Retry-After headers documented. - [Data model / ERD](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/data-model/luma-health-data-model.yml) - [Lifecycle & versioning](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/lifecycle/luma-health-lifecycle.yml): URI-path v2. No deprecation policy, no Sunset headers, no changelog - the spec grew from 270 to 278 operations between 2026-07-24 and 2026-08-15 with no version bump. - [Conformance](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/conformance/luma-health-conformance.yml) - [SDKs / packages](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/packages/luma-health-packages.yml): none - Luma publishes no first-party client library on any registry. Call the REST API directly. - [Plans & pricing](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/plans/luma-health-plans-pricing.yml): no published pricing; enterprise quote only. ## Agent surface - [Agent skills](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/skills/_index.yml): schedule an appointment, register and intake a patient, message a patient, verify eligibility, review feedback and approve review replies. - [MCP candidate](https://raw.githubusercontent.com/api-evangelist/luma-health/refs/heads/main/mcp/luma-health-mcp.yml): Luma Health ships NO MCP server (remote or stdio). This is a derived candidate tool surface, not a callable endpoint. - No A2A agent card is served on any Luma host. ## Docs - [Developer Portal / API Reference](https://apidocs.lumahealth.io) - [Integrations](https://www.lumahealth.io/integrations-2) - [Security & Trust](https://www.lumahealth.io/security-and-trust/): HITRUST CSF r2, SOC 2 Type II, ISO/IEC 27001:2022, ISO/IEC 42001, HIPAA, TX-RAMP Level 2, EU-US Data Privacy Framework. Report vulnerabilities to security@lumahealth.io. - [Status page](https://status.lumahealth.io) - Atlassian Statuspage with a JSON API at /api/v2/summary.json - [Blog](https://www.lumahealth.io/blog) - [Terms of Use](https://www.lumahealth.io/terms-of-use) - [Privacy Policy](https://www.lumahealth.io/privacy-policy)