Skip to main content
Institutional integrations use versioned resources for Practitioner discovery, Bookings, Benefits, Claims and remittance.

Insurers and payers

Connect Coverage, eligibility, pre-authorization, Claims, remittance and reconciliation.

Government and regulators

Review authority, data minimization, audit evidence and controlled exchange boundaries.

Health Organizations

Coordinate Care through purpose-bound Practitioner, Booking and Session capabilities.

Research and open ecosystems

Use approved protocols, synthetic environments and versioned public API definitions.

One operating model

Identity, clinical records, Benefit decisions and payment evidence keep separate authorities. Heyrafiki connects them through typed capabilities, explicit purpose, Organization boundaries, replay-safe writes and auditable state transitions.

Integration boundaries

Credential issuers remain authoritative for professional status. Payers remain authoritative for Benefit and Claim decisions. API responses carry references to those decisions.

Five-role acceptance model

Verify Coverage ingestion, eligibility, pre-authorization, Claim adjudication, remittance, Webhooks, retries and cross-tenant denial against the published API definition.
The insurance acceptance plan turns these roles into one reproducible evidence pack. Sandbox access is issued to an approved Organization and stays isolated from production.

Available interfaces

The sandbox provides:
  • Practitioner discovery and recurring availability;
  • tenant-scoped Bookings and Sessions;
  • Benefit eligibility and pre-authorization;
  • project-scoped Claim submission, review and adjudication;
  • remittance allocation and reconciliation;
  • signed Webhook endpoint management;
  • read-only MCP tools over the same resources.
Use separate projects and keys for each environment. Sandbox data is synthetic.

Insurers and payers

Check eligibility before committing Cover. Where authorization is required, bind the eligibility decision to a covered Booking. Submit Claims from delivered Care, record line decisions, then allocate remittance against the approved amount. Clinical Notes, message content and unrelated identity data are outside the payer interface. Start with the insurance integration guide, then review the financial controls and acceptance test plan.

Health Organizations

Use Practitioner, availability, Booking and Session resources to coordinate Care. Organization access remains purpose-bound and does not expose an individual’s Diagnosis or private Care activity.

Regulators and public systems

Use the sandbox to test identity, Consent, terminology and exchange mappings with synthetic data. Production access follows the authority’s active requirements and approval process.

Government and regulatory integration

A production integration activates only after the institution approves its authority mapping, data purpose, security controls and operating owners. The published API definition and synthetic pilot remain available for technical due diligence before that decision.

Research

Research access requires an approved protocol and the minimum permitted data. Approved exports retain their provenance and access controls. See Security, Data boundaries, Authentication and Webhooks.
Last modified on August 24, 2026