Hospital directory lookups and device-registration lifecycle for the OpComm fleet
discovery.opcommservice.com
Public reads for the operational hospital catalog — config, status, and feature flags by HospitalCode or HospitalUID. Source for the mobile picker and tenant bootstrap flows.
Register, retrieve, and deactivate DeviceRegistration rows tied to (phone, hospital). Drives the global push-pipeline addressing key consumed by mobile and the Platform Portal.
Per-phone long-lived secret minted at OTP verification gates every mutation. SHA-256 + constant-time comparison; LastSeenAt bumped on every successful validation.
/api/v1/registrations/* require the X-Phone-Device-Secret header