HPZone API
The HPZone GraphQL API exposes read access to the HPZone communicable-disease control record — cases, contacts, situations, enquiries, actions and contexts — over a single POST endpoint. Access is by OAuth 2.0 client-credentials with the client_id and client_secret issued by InFact to the customer organisation; tokens are minted by an external identity federation rather than by InFact. Two named scopes govern the field set: `standard` returns the pseudonymised subset, while `extended` unlocks directly-identifying and special-category health fields. The API and its documentation are not publicly available.