# Recuro Health > Recuro Health is an integrated digital health company operating a virtual-first care > delivery platform — a "Digital Medical Home" — sold to employers, health plans, TPAs and > diagnostics companies. It bundles virtual primary care, virtual urgent care and virtual > behavioral health with supplemental benefits (on-demand counseling, pediatric behavioral > health, health advocacy, prescription benefit, wellness programs, virtual MSK therapy) and > at-home lab and genomic diagnostics. Recuro Health is HITRUST certified and absorbed > WellVia Solutions. **Recuro Health publishes no public developer program.** There is no OpenAPI, AsyncAPI, GraphQL SDL, Postman collection, MCP server, A2A agent card, SDK or CLI on any public Recuro Health surface. The one machine-readable contract it does publish is the OpenID Connect discovery metadata for its identity provider. Do not assume an API you cannot read. Generated by API Evangelist (https://apievangelist.com). This is an independent third-party profile, not a Recuro Health publication. ## Machine-readable surfaces - [OpenID Connect discovery](https://auth.recurohealth.com/.well-known/openid-configuration): OIDC Discovery 1.0 document for the Auth0-hosted authorization server at auth.recurohealth.com - [OAuth 2.0 authorization server metadata](https://auth.recurohealth.com/.well-known/oauth-authorization-server): RFC 8414 metadata - [JWKS](https://auth.recurohealth.com/.well-known/jwks.json): RFC 7517 signing keys for token verification - [Sitemap](https://recurohealth.com/sitemap.xml): marketing site page index - [Blog RSS](https://recurohealth.com/feed/): blog feed ## Identity surface - Issuer: `https://auth.recurohealth.com/` - Authorize: `https://auth.recurohealth.com/authorize` - Token: `https://auth.recurohealth.com/oauth/token` - UserInfo: `https://auth.recurohealth.com/userinfo` - Device code: `https://auth.recurohealth.com/oauth/device/code` - Grants: authorization_code, client_credentials, refresh_token, password, implicit, device_code, token-exchange, jwt-bearer - PKCE: S256 supported - Scopes published: openid, profile, offline_access, email, phone, address, plus claim scopes. No API-resource scopes are published. ## Company - [Recuro Health](https://recurohealth.com/): company site - [About](https://recurohealth.com/about/): company overview and leadership - [Offerings](https://recurohealth.com/offerings/): full product catalog - [Providers](https://recurohealth.com/providers/): provider network and signup - [Blog](https://recurohealth.com/blog/): company blog - [Careers](https://recurohealth.com/careers/): open roles - [Contact](https://recurohealth.com/contact/): member questions and business inquiries - [GitHub organization](https://github.com/recurohealth): 3 public repositories, none containing API specifications - [LinkedIn](https://www.linkedin.com/company/recuro-health): company page ## Applications - [Member web app](https://member.recurohealth.com/): member sign-in and care access - [Recuro Care for iOS](https://apps.apple.com/us/app/recuro-care/id1625724898) - [Recuro Care for Android](https://play.google.com/store/apps/details?id=com.wellviasolutions.memberandroid.recuroCare) ## Trust, compliance and legal - [HITRUST certification](https://recurohealth.com/hitrust/): HITRUST CSF certification covering infrastructure, platform and services - [HIPAA policy](https://recurohealth.com/hipaa-policy/): notice of privacy practices - [Privacy policy](https://recurohealth.com/privacy-policy/) - [California privacy rights](https://recurohealth.com/california/) - [Terms and conditions](https://recurohealth.com/terms-conditions/) - [Disclaimer](https://recurohealth.com/disclaimer/) ## What is not published - No OpenAPI or Swagger document (probed on recurohealth.com, api.recurohealth.com, developer.recurohealth.com, docs.recurohealth.com, member.recurohealth.com, provider.recurohealth.com, client.recurohealth.com) - No AsyncAPI, webhook catalog or event surface - No GraphQL endpoint - No MCP server and no A2A agent card - No first-party SDK on npm, PyPI, RubyGems, Packagist or crates.io - No `/.well-known/security.txt`, no vulnerability disclosure policy, no bug bounty - No status page (`recurohealth.statuspage.io` is a soft 404 that redirects to Atlassian marketing) - No changelog, no public roadmap, no pricing page, no sandbox - `developer.recurohealth.com` is CNAMEd to a ReadMe hub that returns HTTP 404; `docs.recurohealth.com` is a GitHub Pages site that HTTP 302s to a GitHub login ## API Evangelist artifacts - [apis.yml](https://raw.githubusercontent.com/api-evangelist/recuro-health/refs/heads/main/apis.yml) - [Well-known index](https://raw.githubusercontent.com/api-evangelist/recuro-health/refs/heads/main/well-known/recuro-health-well-known.yml) - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/recuro-health/refs/heads/main/authentication/recuro-health-authentication.yml) - [OAuth scopes](https://raw.githubusercontent.com/api-evangelist/recuro-health/refs/heads/main/scopes/recuro-health-scopes.yml) - [Conformance](https://raw.githubusercontent.com/api-evangelist/recuro-health/refs/heads/main/conformance/recuro-health-conformance.yml) - [Conventions](https://raw.githubusercontent.com/api-evangelist/recuro-health/refs/heads/main/conventions/recuro-health-conventions.yml) - [Domain security](https://raw.githubusercontent.com/api-evangelist/recuro-health/refs/heads/main/security/recuro-health-domain-security.yml) - [Trust center](https://raw.githubusercontent.com/api-evangelist/recuro-health/refs/heads/main/security/recuro-health-trust-center.yml)