# EHRbase

**Canonical:** https://apis.io/providers/ehrbase/  
**Website:** https://ehrbase.org/  
**APIs profiled:** 1

EHRbase is an open source openEHR Clinical Data Repository (CDR) - a standards-based backend for storing, versioning and querying structured clinical data. It implements the official openEHR REST API (ITS-REST 1.0.2) against openEHR Reference Model 1.1.0, is queried with the Archetype Query Language (AQL), and adds Simplified Data Template projections (flat and structured JSON web templates) that make deeply nested openEHR compositions practical to write against. It is Apache-2.0 software each organization self-hosts - no vendor API host, no signup, no metering - maintained by vitagroup AG with the openEHR community, with a commercial distribution (HIP EHRbase) adding multi-tenancy, IHE ATNA audit logging, AQL event triggers, Saga-pattern transaction compensation and SLAs. A public credential-free sandbox at sandkiste.ehrbase.org serves its live OpenAPI 3.1.0 contract of 63 operations.

## Kin Score — 51.4 / 100 (developing)

Scored 2026-09-02 under rubric 0.18.0.

| Facet | Score |
|---|---|
| Discoverability | 68.5 |
| Contract Quality | 46.1 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 47.4 |
| Developer Ergonomics | 80.4 |
| Commercial Clarity | 31.6 |
| Access Clarity | 31.6 |

Regulatory layer — **Health**: 33.8 (matched via tags).

## Agent readiness — 50.0 (agent-native)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | served |
| Idempotency | documented |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | served |
| Protected Resource Metadata | verified |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (3)

- **EHRbase openEHR REST API** — The standard openEHR ITS-REST 1.0.2 surface - 31 paths and 45 operations covering EHR, EHR_STATUS, COMPOSITION, VERSIONED_COMPOSITION, CONTRIBUTION, DIRECTORY, operational templ...
- **EHRbase Admin API** — The opt-in administrative surface - 8 paths and 11 operations for physical deletion of EHRs, compositions, directories and stored queries, and for replacing or removing operatio...
- **EHRbase Status and Metrics API** — A version heartbeat at /rest/status reporting the running EHRbase, openEHR SDK, Archie, JVM, OS and PostgreSQL versions, plus the Spring Boot Actuator surface at /management pro...

## MCP servers (1)

- **EHRbase MCP Server**

## Security (3)

- **Ehrbase Authentication** — 0 schemes
- **Ehrbase Domain Security** — TLSv1.3 · HSTS
- **Ehrbase Vulnerability Disclosure** — Hackerone · contact published

## Plans (1)

- **Ehrbase Plans Pricing**

## Tags

Company, Healthcare, Health IT, Electronic Health Records, Clinical Data, openEHR, Interoperability, Open Source, Databases, Standards

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/ehrbase/). Scores are computed from the provider's own public artifacts under a published rubric.
