{
 "categories": [
  "healthcare",
  "public-sector",
  "government"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-08-30",
   "fact": "homepage",
   "note": "Helsenorge is the national citizen portal for appointments, prescriptions, inbox, GP change, and related health services.",
   "source": "https://www.helsenorge.no/",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "vendor",
   "note": "Norsk Helsenett's developer portal points inhabitant-facing APIs to Helsenorge documentation and personnel APIs to NHN services.",
   "source": "https://utviklerportal.nhn.no/om-utviklerportalen",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "license",
   "note": "The national inhabitant portal is a public service. Integrator access is supplier-gated, not a paid SaaS tenant.",
   "source": "https://www.helsenorge.no/",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.api.exists",
   "note": "Official Helsenorge integration docs describe seamless hop-out, inhabitant-context APIs, and system-context APIs at eksternapi.helsenorge.no.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/691175425",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.api.kinds[0]",
   "note": "Inhabitant-context examples are JSON HTTP POST calls to eksternapi.helsenorge.no.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/23789578",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.api.kinds[1]",
   "note": "Helsenorge messaging uses AMQP, not ebXML, and requires virksomhetssertifikater.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/690913297",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.api.auth[0]",
   "note": "System-to-system calls use HelseID tokens with per-method scopes. All actors shall use DPoP on Ekstern-API. orgnr_parent is required.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/1886191617",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.api.auth[1]",
   "note": "Inhabitant context uses Helsenorge STS OIDC v3 with PAR and PKCE. Confidential clients use RSA client assertion. Public clients require mTLS. APIs take a Bearer access token.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/1348731100",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.api.coverage",
   "note": "Coverage is per API contract and supplier scopes. Some STS system APIs are being phased out in favour of HelseID.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/691175425",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.extensibility.scripting[0]",
   "note": "External citizen apps integrate through seamless hop-out, where Helsenorge is the OpenID Provider and issues ID and access tokens including representation.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/1420034058",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.data_access.export[0]",
   "note": "Inhabitant APIs exchange JSON payloads such as store-inhabitant-copy and read-inhabitant-data examples.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/23789578",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "https://www.helsenorge.no/llms.txt returned 404 on 2026-08-30.",
   "source": "https://www.helsenorge.no/llms.txt",
   "tier": "scraped"
  },
  {
   "date": "2026-08-30",
   "fact": "verdict.scores.api",
   "note": "Documented REST plus two auth planes is a usable production path. NHN supplier terms, HelseID/DPoP, and an incomplete public per-API catalogue keep it in the useful-with-limits tier.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/1886191617",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "freshness.watch[0].url",
   "note": "Opened and verified as the current Helsenorge integration-architecture page.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/691175425",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "freshness.watch[1].url",
   "note": "Opened and verified as the current system-to-system HelseID and DPoP page.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/1886191617",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as the current Helsenorge STS OIDC v3 page.",
   "source": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/1348731100",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "freshness.watch[3].url",
   "note": "Opened and verified as NHN's developer-portal overview separating personnel APIs from Helsenorge inhabitant APIs.",
   "source": "https://utviklerportal.nhn.no/om-utviklerportalen",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-08-30",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/691175425"
   },
   {
    "type": "docs",
    "url": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/1886191617"
   },
   {
    "type": "docs",
    "url": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/1348731100"
   },
   {
    "type": "docs",
    "url": "https://utviklerportal.nhn.no/om-utviklerportalen"
   }
  ]
 },
 "homepage": "https://www.helsenorge.no/",
 "id": "helsenorge",
 "license": "free",
 "modalities": {
  "agent_docs": {
   "llms_txt": false
  },
  "api": {
   "auth": [
    "helseid-dpop",
    "helsenorge-sts-bearer"
   ],
   "coverage": "partial",
   "docs": "https://helsenorge.atlassian.net/wiki/spaces/HELSENORGE/pages/691175425",
   "exists": true,
   "kinds": [
    "rest",
    "amqp"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "api-json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [
    "oidc-hop-out"
   ],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": "unknown",
   "third_party": [],
   "verdict": "unknown"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Helsenorge is the national citizen portal. The documented path is a supplier-registered client calling eksternapi.helsenorge.no with HelseID or Helsenorge STS tokens, not browser control of inhabitant sessions.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Helsenorge",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "helseid",
   "dips"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Norsk Helsenett",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 6,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": null,
   "overall": 6,
   "rpa": null
  },
  "summary": "Helsenorge is automatable as the national citizen portal's external APIs, not as HelseID and not as an EHR. Integrators call https://eksternapi.helsenorge.no/<area>/. Inhabitant apps go through Helsenorge STS OpenID Connect v3 after a seamless hop-out. Those APIs take a Bearer access token. System-to-system calls use HelseID client-credentials tokens and DPoP; leftover Helsenorge STS system clients are being retired. Messaging is AMQP and needs virksomhetssertifikater and Adresseregister. That is not the REST citizen API. Access is supplier-gated through NHN and HelseID. SOAP Adresseregister and CPPA endpoints appear on the messaging firewall table as related NHN services, not as the Helsenorge external API. First-party MCP ownership is not established. Computer-use viability is unassessed. HelseID, Kjernejournal, e-resept, and vendor EHRs are outside this record.\n"
 }
}