Canvas Medical · OpenAPI Overlay 1.0.0

API Evangelist enhancements for Canvas Medical FHIR API

9 actions 9 updates update extends openapi/_original/canvas-medical-fhir-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Canvas Medical's API. It is a proposal applied on top of the contract, not a document Canvas Medical publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-slugx-apievangelist-enrichedx-fhir-versionx-capability-statementx-service-base-url-directoryx-onc-certificationx-identifier-formatx-pagination

Targets 3

$.info
$.servers[0]
$.components.securitySchemes

OpenAPI Overlay

Raw ↑
overlay: 1.0.0
info:
  title: API Evangelist enhancements for Canvas Medical FHIR API
  version: 1.0.0
extends: openapi/_original/canvas-medical-fhir-api-openapi.yml
x-provenance:
  generated: '2026-08-14'
  method: generated
  source: >-
    Facts asserted below come from docs.canvasmedical.com (service base URLs, pagination, conditional
    requests, errors, customer authentication) and from live probes of a production Canvas FHIR host
    recorded in well-known/ and conformance/. The overlay never mutates the harvested spec.
actions:
- target: $.info
  update:
    x-apievangelist-slug: canvas-medical
    x-apievangelist-enriched: '2026-08-14'
    x-fhir-version: 4.0.1
    x-capability-statement: https://fumage-{canvas-instance}.canvasmedical.com/metadata
    x-service-base-url-directory: https://docs.canvasmedical.com/api/service-base-urls/
    x-onc-certification: 170.315(g)(10) Standardized API for Patient and Population Services
- target: $.info
  update:
    x-identifier-format:
      patient_and_staff_keys: UUID without dashes
      other_resources: standard dashed UUID
      source: https://docs.canvasmedical.com/llms.txt
- target: $.info
  update:
    x-pagination:
      style: fhir-searchset
      count_param: _count
      offset_param: _offset
      default_page_size: 10
      max_page_size: 100
      max_page_size_stability: server-enforced and may change without warning
      link_relations: [self, first, last, next]
      termination: absence of a `next` relation
      rule: follow the Bundle links; do not construct offsets by hand
      docs: https://docs.canvasmedical.com/api/pagination/
- target: $.info
  update:
    x-concurrency:
      request_header: If-Unmodified-Since
      format: RFC 2616 HTTP-date
      failure_status: 412
      failure_body: OperationOutcome (issue[].code = conflict)
      etag: false
      docs: https://docs.canvasmedical.com/api/conditional-requests/
    x-idempotency:
      supported: false
      note: >-
        No Idempotency-Key header and no FHIR conditional-create (If-None-Exist). A retried POST
        creates a duplicate resource. Use the search-then-update upsert pattern.
- target: $.info
  update:
    x-error-format:
      media_type: application/fhir+json
      shape: FHIR OperationOutcome
      discriminator: issue[].code
      codes: [invalid, unknown, forbidden, not-found, conflict, business-rule, exception]
      rfc9457: false
      catalog: errors/canvas-medical-problem-types.yml
      docs: https://docs.canvasmedical.com/api/errors/
- target: $.info
  update:
    x-rate-limits:
      documented: false
      response_headers: []
      note: >-
        Both published plans advertise unlimited API calls. The platform security overview states the
        edge enforces rate limiting, but no quota, window, header or exhaustion status is published.
    x-network-precondition:
      ip_allow_list: true
      note: Instance endpoints carry IP allow-lists; egress addresses must be allow-listed by the customer.
- target: $.info
  update:
    x-access-model:
      self_serve: false
      request_via: developer-access@canvasmedical.com
      verification_sla_business_days: 10
      enablement_sla_business_days: 5
      fees: none
      docs: https://docs.canvasmedical.com/api/developer-access/
- target: $.servers[0]
  update:
    x-instance-model: one isolated instance per customer; each has its own FHIR base URL and its own OAuth authorization server
    x-environments:
      production: https://fumage-{subdomain}.canvasmedical.com
      dev: https://fumage-{subdomain}-dev.canvasmedical.com
      staging: https://fumage-{subdomain}-staging.canvasmedical.com
    x-auth-base: https://{subdomain}.canvasmedical.com/auth/
- target: $.components.securitySchemes
  update:
    x-smart-configuration: https://fumage-{canvas-instance}.canvasmedical.com/.well-known/smart-configuration
    x-openid-configuration: https://{canvas-instance}.canvasmedical.com/auth/.well-known/openid-configuration
    x-pkce: S256
    x-access-token-ttl-seconds: 36000
    x-refresh-token: non-expiring, single-use
    x-authorization-code-ttl-seconds: 60
    x-launch-parameter-required-for-staff: true
    x-scope-versions: [v1, v2-granular-crus]
    x-scopes-artifact: scopes/canvas-medical-scopes.yml