# XRHealth > XRHealth is an extended-reality (XR) therapeutics and virtual-clinic company founded in 2016, with > offices in Boston, Massachusetts and Tel Aviv, Israel. It delivers FDA-registered and CE-marked > virtual and augmented reality treatment for physical rehabilitation, cognitive training, pain > management and mental health: patients receive VR headsets at home and work with licensed > clinicians through the XRHealth Virtual Clinic, while therapists prescribe applications and track > outcomes on the XRHealth platform. Its one publicly readable programmable surface is the XRHealth > Platform API on api.xr.health, an OpenAPI 3.1 contract covering patient authentication. Generated by API Evangelist on 2026-09-04 from https://api.xr.health/v1/openapi.json and live probes of the xr.health host set. Method: generated. XRHealth publishes no llms.txt of its own — /llms.txt was probed on developer.xr.health (404) and platform.xr.health (307 to an error page) on 2026-09-04. ## What is callable today The XRHealth Platform API at `https://api.xr.health/v1` describes itself. Its OpenAPI 3.1.0 document is served, unauthenticated, at `https://api.xr.health/v1/openapi.json`, and the document covers the platform **authentication module** only — twelve operations spanning passwordless patient login, PKCE public-client token exchange, refresh-token rotation and revocation, a `/me` subject endpoint, and a JWKS endpoint. The 503 response is described as "The authentication module is temporarily unavailable", which is the provider's own evidence that this is one module of a larger platform API. Two credentials exist: an `X-XRHealth-Application-Token` header for confidential server-side applications, and a registered `client_id` plus PKCE (`S256` only) for public clients. Patient access tokens are JWTs verifiable against `https://api.xr.health/v1/.well-known/jwks.json`. ## What is not published - No pricing, quotas or plans for API access — the XRH Developer portal is invitation-only. - No rate-limit numbers or headers. A `429` is declared on the two code-issuing operations; no `RateLimit-*` or `Retry-After` header was observed on any live response. - No idempotency mechanism of any kind. Every write is a POST with no replay protection. - No status page (`status.xr.health` is NXDOMAIN), no changelog, no deprecation or sunset policy. - No SDK in any public package registry, no CLI, no MCP server, no A2A agent card, no AsyncAPI or webhook catalog, no `/.well-known/` discovery document on any host. - Errors are `{"error": "...", "request_id": "..."}`, not RFC 9457 problem+json. ## APIs - [XRHealth Platform API](https://api.xr.health/v1/openapi.json): OpenAPI 3.1.0, 12 operations, patient authentication and identity. Base URL `https://api.xr.health/v1`. ## Specs and artifacts - [OpenAPI (harvested verbatim)](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/openapi/_original/xrhealth-openapi.json) - [OpenAPI (working copy, absolute server)](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/openapi/xrhealth-platform-openapi.yml) - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/authentication/xrhealth-authentication.yml) - [OAuth-style scopes](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/scopes/xrhealth-scopes.yml) - [API conventions, idempotency and reversibility](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/conventions/xrhealth-conventions.yml) - [Error catalog](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/errors/xrhealth-problem-types.yml) - [Data model](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/data-model/xrhealth-data-model.yml) - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/lifecycle/xrhealth-lifecycle.yml) - [Conformance](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/conformance/xrhealth-conformance.yml) - [Rate limits (an honest zero)](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/rate-limits/xrhealth-rate-limits.yml) - [Plans and pricing (an honest zero)](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/plans/xrhealth-plans-pricing.yml) - [Packages (none found)](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/packages/xrhealth-packages.yml) - [Well-known probe (no documents served)](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/well-known/xrhealth-well-known.yml) - [MCP candidate tool list (no server exists)](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/mcp/xrhealth-mcp.yml) - [Domain security probe](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/security/xrhealth-domain-security.yml) - [Agentic access contracts](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/agentic-access/xrhealth-agentic-access.yml) - [OpenAPI Overlay](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/overlays/xrhealth-platform-overlay.yaml) ## Agent Skills - [Server-side patient login](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/skills/xrhealth-server-side-patient-login.md) - [Public-client PKCE login](https://raw.githubusercontent.com/api-evangelist/xrhealth/refs/heads/main/skills/xrhealth-public-client-pkce-login.md) ## Docs and human surfaces - [XRH Developer portal](https://developer.xr.health/) — invitation-only sign-in - [XRHealth platform](https://platform.xr.health/en/login) - [Website](https://www.xr.health/) — behind a JavaScript robot challenge for non-browser clients - [Blog](https://blog.xr.health/) - [Support](https://support.xr.health/hc/en-us) - [Terms of use](https://platform.xr.health/en/p/terms) - [Privacy policy](https://platform.xr.health/en/p/privacy)