Distribution options
Choose a private hospital pilot, an approved multi-hospital private release, or a future public marketplace listing.
Package and hand off your app
Package source with the allowlisted kit command and hand off the immutable application artifact separately.
Versions and releases
Each release binds app/publisher IDs, version, HTTPS URL/origin, artifact basename/size/SHA-256, bridge protocol, key ID, and Ed25519 signature.
Test your app
Test the app locally, verify the signed release, generate handoff evidence, and then run hospital UAT on the exact bytes.
Publish your app
Public listing will require publisher identity, certification, support, privacy, release, and hospital-safety evidence.
Promote your app
Marketplace promotion will follow verified availability, support quality, and installation outcomes.
Deep links
A bounded medOS deep-link contract for partner apps is planned.
Route descriptors
Host-owned route descriptors will eventually let approved apps request navigation without learning internal router details.
Install links
Signed, tenant-bound install links are not yet part of the medOS app lifecycle.
Assign roles in embedded apps
Future role assignment will project the hospital Role Directory and certified app scopes rather than define app-local clinical roles.
Post-install actions
A governed post-install action pipeline is planned for safe configuration and health checks.
App analytics
Publisher-facing installation, usage, error, and outcome analytics are planned with PHI-free aggregation.
Embedded components
The current external UI unit is the complete sandboxed remote-app frame, not arbitrary components injected into medOS pages.
Embed third-party apps in medOS
Certified third-party services can be mounted only as cross-origin sandboxed frames with exact origin and scope binding.