Going live

Test mode & review

Every Arkaayu app starts in test mode, where it works for you and a small group of people you choose. When it's ready, you submit it for review. Once approved, any Arkaayu user can connect to it.

App lifecycle

StatusWho can connectWhat it means
testYou and up to 25 test usersThe starting state. Build and test freely; everything works with real data.
in_reviewYou and your test usersYou've submitted the app and we're reviewing it. You can withdraw the submission to make changes.
liveAny Arkaayu userApproved. Your app can ask any Arkaayu user to connect.
suspendedNo oneWe've stopped the app, usually because of a breach of the Developer Terms. Users can't connect to it and API access is blocked. We'll contact you with the reason.

Test mode

In test mode your app can be connected by:

  • You — the developer account that owns the app.
  • Up to 25 test users — people you add on the app's page in the console, identified by the email address they use to sign in to Arkaayu.

Anyone else who tries to connect sees "This app is still being tested" and can't continue. Test users go through the same sign-in and consent screens as everyone else, so what you test is what your users will get.

  • Test users must already have an Arkaayu account. Ask them for the exact email they use in the Arkaayu app.
  • Removing a test user also revokes their tokens for your app straight away.
  • http://localhost redirect URIs are allowed in test mode, for local development.

Before you submit

The console won't let you submit until these are in place:

  • A description that explains what your app does with Arkaayu data.
  • A website (https://).
  • A privacy policy URL (https://).
  • A support email users can write to.
  • No localhost redirect URIs. Remove them, or keep a separate test app for local development.

Then press Submit for review on the app's page, optionally with a note for the reviewer — test credentials, a demo video link, or why you need a sensitive scope like read:ecg.

What we review

We review every app before it can reach all Arkaayu users. Reviewers check that:

  1. Your privacy policy covers Arkaayu data. It must explain what you collect from Arkaayu, what you use it for, how long you keep it, and how users can have it deleted — in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and other laws that apply to you.
  2. You ask for the minimum scopes. Each scope must be used by a feature in your app. Be ready to justify read:ecg in particular.
  3. Redirect URIs are on your own domain — the same organisation as your website, using https.
  4. Your name and branding don't imitate Arkaayu or Healaxy. App names containing "Arkaayu" or "Healaxy" are refused automatically. See the brand guidelines.
  5. Your description is honest about what the app does and who makes it, and doesn't make medical claims your product isn't approved to make.

We aim to complete reviews within 5 working days. If we need changes, we'll explain them in a reviewer's note shown on the app's page in the console. Fix the issues and submit again.

Changes after going live

ChangeLive app
Edit name, description, website, privacy policy, terms or support emailAllowed. Keep them accurate — reviewers may look again.
Add, edit or remove redirect URIsAllowed, https only.
Remove a scopeAllowed at any time.
Add a scopeNeeds a new review. Create a separate test app with the extra scope, build and test the feature there, then email developers@arkaayu.com with both client IDs.
Rotate the client secretAllowed. The old secret stops working immediately; existing access and refresh tokens stay valid. The new secret is shown once. In production, be ready to deploy it the moment you rotate (or accept a short window of failed token requests).
Delete the appAllowed. All its tokens are revoked and every connected user is disconnected. This can't be undone.

Limits

LimitValue
Apps per developer account5
Redirect URIs per app5
Test users per app25

Need more? Write to developers@arkaayu.com and tell us about your use case.

Questions or something unclear? Write to developers@arkaayu.com.