Test mode & review
Every Arkaayu app starts in test mode, where it works for you and a small group of people you choose. When it's ready, you submit it for review. Once approved, any Arkaayu user can connect to it.
App lifecycle
| Status | Who can connect | What it means |
|---|---|---|
| test | You and up to 25 test users | The starting state. Build and test freely; everything works with real data. |
| in_review | You and your test users | You've submitted the app and we're reviewing it. You can withdraw the submission to make changes. |
| live | Any Arkaayu user | Approved. Your app can ask any Arkaayu user to connect. |
| suspended | No one | We've stopped the app, usually because of a breach of the Developer Terms. Users can't connect to it and API access is blocked. We'll contact you with the reason. |
Test mode
In test mode your app can be connected by:
- You — the developer account that owns the app.
- Up to 25 test users — people you add on the app's page in the console, identified by the email address they use to sign in to Arkaayu.
Anyone else who tries to connect sees "This app is still being tested" and can't continue. Test users go through the same sign-in and consent screens as everyone else, so what you test is what your users will get.
- Test users must already have an Arkaayu account. Ask them for the exact email they use in the Arkaayu app.
- Removing a test user also revokes their tokens for your app straight away.
http://localhostredirect URIs are allowed in test mode, for local development.
Before you submit
The console won't let you submit until these are in place:
- A description that explains what your app does with Arkaayu data.
- A website (
https://). - A privacy policy URL (
https://). - A support email users can write to.
- No localhost redirect URIs. Remove them, or keep a separate test app for local development.
Then press Submit for review on the app's page, optionally with a note for the reviewer — test credentials, a demo video link, or why you need a sensitive scope like read:ecg.
What we review
We review every app before it can reach all Arkaayu users. Reviewers check that:
- Your privacy policy covers Arkaayu data. It must explain what you collect from Arkaayu, what you use it for, how long you keep it, and how users can have it deleted — in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and other laws that apply to you.
- You ask for the minimum scopes. Each scope must be used by a feature in your app. Be ready to justify
read:ecgin particular. - Redirect URIs are on your own domain — the same organisation as your website, using
https. - Your name and branding don't imitate Arkaayu or Healaxy. App names containing "Arkaayu" or "Healaxy" are refused automatically. See the brand guidelines.
- Your description is honest about what the app does and who makes it, and doesn't make medical claims your product isn't approved to make.
We aim to complete reviews within 5 working days. If we need changes, we'll explain them in a reviewer's note shown on the app's page in the console. Fix the issues and submit again.
Changes after going live
| Change | Live app |
|---|---|
| Edit name, description, website, privacy policy, terms or support email | Allowed. Keep them accurate — reviewers may look again. |
| Add, edit or remove redirect URIs | Allowed, https only. |
| Remove a scope | Allowed at any time. |
| Add a scope | Needs a new review. Create a separate test app with the extra scope, build and test the feature there, then email developers@arkaayu.com with both client IDs. |
| Rotate the client secret | Allowed. The old secret stops working immediately; existing access and refresh tokens stay valid. The new secret is shown once. In production, be ready to deploy it the moment you rotate (or accept a short window of failed token requests). |
| Delete the app | Allowed. All its tokens are revoked and every connected user is disconnected. This can't be undone. |
Limits
| Limit | Value |
|---|---|
| Apps per developer account | 5 |
| Redirect URIs per app | 5 |
| Test users per app | 25 |
Need more? Write to developers@arkaayu.com and tell us about your use case.
Questions or something unclear? Write to developers@arkaayu.com.