Route status

Route existence in OpenAPI is not the same thing as public product approval. Every endpoint page shows a conservative route class before examples.

Current posture

Generated OpenAPI is the endpoint source of truth, but expanded external publication, SDKs, and production recipes wait on route registry and release evidence.

Status vocabulary

StatusMeaningPublicationAction
PUBLIC_REFERENCEGenerated endpoint contract can be shown as a baseline reference with caveats.Allowed for internal or limited baseline reference only until release evidence is attached.Keep route status, side effects, async/idempotency, file policy, and release evidence visible.
COMPATIBILITY_LIMITEDRoute exists, but versioning or behavior is not stable enough for happy-path docs.May be listed with warnings; exclude from quickstarts, SDKs, and workflow recipes.Exclude from quickstarts, SDKs, and workflow recipes until classified.
Needs publication reviewProduct, tenancy, side-effect, credential, file, PHI, or security semantics still need approval.Show the contract with caveats, but do not promote it as an ordinary production public API.Route through product, security/compliance, module-owner, and developer-experience review.
PRIVATE_OR_INTERNALOperational, worker, callback, admin, or internal route.Excluded from public developer documentation.Exclude from public developer docs.

Current baseline facts

FactValue
Generated operations427 operations across 374 paths
Primary public prefix371 generated paths use /api/v1
Compatibility prefixes2 generated paths use /v2 and 1 generated path uses legacy /api
Compatibility routesPOST /api/credentialing/update-status, POST /v2/era, GET /v2/era/{eraId}
Bearer auth gapGET /api/v1/medical-coding/code-systems needs security review before public use

Required route metadata

FieldWhy
Route classDistinguishes generated baseline routes from compatibility, private, worker, guest, webhook, or internal surfaces.
Auth class and scopesShows whether bearer API key security applies and whether product scopes, feature flags, or RBAC can deny access.
Tenant sourceConfirms whether the API key selects tenant context or whether a compatibility field still needs classification.
Side-effect modePrevents local, queued, dry-run, simulated, metadata-only, or file behavior from being documented as live execution.
Release evidenceLinks route classification to the tests and no-sensitive-data checks required before external publication.

Publication rules by surface

SurfaceRule
QuickstartUse only a classified safe route with PHI-safe examples and current release evidence.
Endpoint indexShow route class and caveats before request examples or try-out controls.
Workflow guidesLink to platform primitives instead of repeating local exceptions as if they were global policy.
SDKsExclude compatibility-limited, private, internal, file-risk, credential-risk, live side-effect-risk, and publication-review routes.

Endpoint pages

Open endpoint index