API
The backend publishes interactive OpenAPI (Swagger) documentation at /api-docs on every running API instance
(for local development: http://localhost:5001/<project>/asia-south1/achalHealthcareApi/api-docs, or through Hosting
at /api/api-docs).
Conventions
- Envelope: every response is
{ success, message, data }(success()/failure()helpers). - Auth: bearer JWT; tenant context comes from the token, never from the request body.
- Errors: 400 bad input, 401 unauthenticated, 403 forbidden (including wrong facility/department scope), 404,
409 version conflict, 422 validation (
{ code, errors: [{ path, code, message }] }), 423 locked document. - Idempotency: state-changing POSTs accept an
Idempotency-Keyheader. - Pagination: list endpoints use cursor pagination (
?cursor=&limit=→{ items, nextCursor }).
A public, versioned API with webhooks is planned for release R5.