Public surface / Payer Provider Directory APIs
AvMed Provider Directory API
This endpoint could not be reached from any vantage on this run, so nothing about what it publishes was observed.
Observed surface
- Base URL
https://avmp.interop.avmed.com/avmp/api/plannet- Category
- Payer Provider Directory APIs
- Availability
- answered 0 of the last 45 daily checks (0%)
- Last answered
- not in the recorded window
- Vantage agreement
- answered HTTP 404 from 3 of 3 vantages but returned no usable document: the endpoint is running and refusing this request, which is not the same as being unreachable: HTTP 404
What each vantage saw
| Vantage | Result | What it saw | Condition |
|---|---|---|---|
github-actions/macos-latest | not reached | HTTP 404 | HTTP 404, not_found |
github-actions/ubuntu-latest | not reached | HTTP 404 | HTTP 404, not_found |
github-actions/windows-latest | not reached | HTTP 404 | HTTP 404, not_found |
Vantages on one network are one network’s view sampled several times. A rule applied to that network’s address space reaches every one of them at once and reads exactly like agreement.
Interpretation
A grade describes two public discovery documents at one point in time. It does not inspect patient data, authenticated behavior, or clinical quality.
Read the scoring method →This endpoint's full report: what was observed, what was not, and what would change it →
What its CapabilityStatement declares, resource by resource →
Findings
- No answer: /metadata answered HTTP 404 from 3 of 3 vantages but returned no usable document: the endpoint is running and refusing this request, which is not the same as being unreachable: HTTP 404 (observed 2026-10-03)R1Spec ↗
- No answer: latency not measured: no vantage was answered (observed 2026-10-03)R2Spec ↗
Observed since 2026-08-20; no changes to declared capability recorded.
Declared app-to-server access
What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded. An absent field is reported as absent, not as a refusal: a document that does not mention a field has not said anything about it.
| Question | Answer | What the document says | Where it is declared |
|---|---|---|---|
| Declares private_key_jwt client authentication at the token endpoint | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: token_endpoint_auth_methods_supported |
| Declares the client_credentials grant, which SMART Backend Services uses | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: grant_types_supported |
| Declares the client-confidential-asymmetric capability | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: capabilities |
| Declares system-level scopes | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: scopes_supported |
| Declares an export operation | not retrieved on this run | no vantage retrieved the CapabilityStatement | CapabilityStatement: rest.operation and rest.resource.operation |
| Instantiates the Bulk Data Access implementation guide | not retrieved on this run | no vantage retrieved the CapabilityStatement | CapabilityStatement: instantiates |
Registry provenance
How this entry was verified
Listed on the organization's own publication of this base URL, not on a retrieved conformance document: base URL printed under the literal heading 'Base URL' in AvMed's own Provider Directory API Documentation PDF (2026), linked from avmed.org/en/for-developers. AvMed prints two addresses for this surface and neither answers; this entry names the one its API documentation of record declares as the base URL (recorded 2026-08-19). Published at https://www.avmed.org/en/for-developers. On the verification date this probe observed: HTTP 404 ({"statusCode": 404, "message": "Resource not found"}) to an unauthenticated GET of /metadata. The other address AvMed publishes for this surface - a myfhir.avmed.org/provider/metadata link titled 'Capability Statement and Meta Data' on the for-developers page - fails TLS verification because the served certificate is AvMed's own (CN=myfhir.avmed.org, O=Avmed) and expired 2026-05-15, an endpoint-side fact rather than a vantage-side one; with verification disabled the same URL serves a 1,666-byte HTML maintenance page, not a CapabilityStatement. Both addresses are in the candidate log. The surface the rule requires to be reachable without authentication is published twice and reachable at neither address. No later re-check is recorded, so the date above is the last time anyone checked this entry against the live endpoint.
This is an observational snapshot of a public, unauthenticated surface. It is not an audit, a ranking of care quality, or a statement about anyone's regulatory compliance. See how we grade.
Every observation on record for this endpoint, with the dates it answered and the dates it did not.