Investment Plans workspace
Open raw ↗

# HAD Digital - API Contract

Version: 1.0.0 Date: 5 September 2026 Base URL: http://127.0.0.1:8080/api


Authentication

All endpoints except /login require a valid session cookie. The session cookie is set by the /login endpoint and must be included in subsequent requests.

Session Cookie: HAD_SESSION Max Age: 86400 seconds (24 hours)


Endpoints

Authentication

MethodPathDescriptionAuth Required
POST/loginAuthenticate user and create sessionNo
POST/logoutDestroy current sessionYes
GET/whoamiGet current user infoNo (returns unauthenticated if no session)

POST /login

Request Body:

{
  "username": "string",
  "password": "string"
}

Success Response (200):

{
  "message": "Login successful",
  "user": {
    "id": 1,
    "username": "admin",
    "role": "admin",
    "display_name": "Marie Dupont"
  }
}

Error Response (401):

{
  "error": "Invalid username or password"
}

POST /logout

Success Response (200):

{
  "message": "Logged out successfully"
}

GET /whoami

Success Response (200) - Authenticated:

{
  "authenticated": true,
  "user": {
    "id": 1,
    "username": "admin",
    "role": "admin",
    "display_name": "Marie Dupont"
  }
}

Success Response (200) - Unauthenticated:

{
  "authenticated": false
}

Patients

MethodPathDescriptionAuth RequiredRoles
GET/patientsList patients (role-filtered)YesAll
GET/patients/{id}Get patient detailsYesAll

GET /patients

Query Parameters:

Success Response (200):

{
  "patients": [
    {
      "id": 1,
      "mrn": "MRN-2024-001",
      "first_name": "Jeanne",
      "last_name": "Durand",
      "date_of_birth": "1958-03-15",
      "gender": "F",
      "phone": "+33 6 12 34 56 78",
      "address": "15 Rue de la Paix, Paris",
      "treatment_protocol": "FOLFOX6",
      "current_cycle": "Cycle 3 Day 8"
    }
  ]
}

Toxicity Reports

MethodPathDescriptionAuth RequiredRoles
POST/reportsSubmit toxicity reportYesPatient, Caregiver, Clinician
GET/reportsList reportsYesAll

POST /reports

Request Body:

{
  "patient_id": 1,
  "symptoms": {
    "nausea": 2,
    "vomiting": 1,
    "diarrhea": 0,
    "fatigue": 3,
    "bleeding": 0,
    "infection_signs": 0,
    "rash": 0,
    "skin_changes": 0,
    "numbness": 1,
    "weakness": 2,
    "fever": 0,
    "weight_loss": 0
  },
  "notes": "Additional notes about symptoms",
  "type": "patient_report"
}

Symptom Values:

Success Response (200):

{
  "message": "Report submitted successfully",
  "report_id": 42,
  "grades": [
    {
      "term": "Nausea",
      "grade": 2,
      "provisional": true
    }
  ],
  "alert": {
    "tier": "urgent",
    "message": "Grade 3 fatigue detected"
  }
}

Alerts

MethodPathDescriptionAuth RequiredRoles
GET/alertsList alertsYesClinician
POST/alerts/{id}/acknowledgeAcknowledge an alertYesClinician

Timeline

MethodPathDescriptionAuth RequiredRoles
GET/timelineGet care coordination timelineYesAll

Treatment Plan

MethodPathDescriptionAuth RequiredRoles
GET/treatment-planGet treatment planYesAll

Messages

MethodPathDescriptionAuth RequiredRoles
POST/messagesSend a messageYesAll
GET/messagesList messagesYesAll

Export

MethodPathDescriptionAuth RequiredRoles
GET/export/summaryGenerate toxicity summaryYesClinician

Guidance

MethodPathDescriptionAuth RequiredRoles
GET/guidanceGet patient guidanceYesAll

Audit Log

MethodPathDescriptionAuth RequiredRoles
GET/audit-logGet audit trailYesAdmin

AI Chat

MethodPathDescriptionAuth RequiredRoles
POST/chatAI chat (stub adapter)YesAll

Notes

  1. All timestamps are in ISO 8601 format (UTC).
  1. All IDs are integers, auto-incremented by SQLite.
  1. Session cookies are HttpOnly but not Secure (for local development).
  1. The audit log is append-only and cannot be modified or deleted.
  1. The AI chat endpoint uses a stub adapter by default; set GLM_API_KEY environment variable to use the GLM adapter.