Sandwich
Free directory — top of the funnel
joinsandwich.comSandwich is the directory. LovedOne is the family product — the Family Inbox lives inside it, not beside it. Soft is the agency OS. Pipe is partner ingest and is not live yet. Family MCP is how AI assistants read a family’s LovedOne data.
Free directory — top of the funnel
joinsandwich.comThe family product. Family Inbox is a feature inside it.
lovedone.appAgency operating system
soft.lovedone.appPartner event ingest
POST /sandwichpipe/v1/eventsThe free sandwich-generation resource site: the 40–70 rule, guides, and provider pages. Top of the funnel — not the family app.
The family product. One private @lovedone.app address per parent, shared by siblings. The Family Inbox is a feature inside LovedOne. inbox.lovedone.app redirects here; so does app.joinsandwich.com.
The operating system for home-care agencies. Admins run the roster; caregivers clock in from a phone. Families use LovedOne, not Soft.
Event ingest API for partners. Planned POST https://api.lovedone.app/sandwichpipe/v1/events. Built in Terahertz-Inc/sandwichpipe. api.joinsandwich.com is dead — do not use it.
The MCP server that lets AI assistants connect to one family’s LovedOne data. Not a second family product — the agent door into LovedOne.
Any assistant that speaks the
Model Context Protocol
can connect. A family key reads that household’s inbox. A Soft key
reads that agency’s roster. Mixing them returns HTTP 403
WRONG_SURFACE. GET on either MCP URL is liveness/descriptor;
POST is the JSON-RPC transport.
https://api.lovedone.app/mcp/v1 — alias https://inbox.lovedone.app/api/mcp. Docs: docs.lovedone.app/mcp.html · mcp-family.html.https://api.lovedone.app/mcp/vendor/v1 — clients, visits, invoices. Spec: docs.lovedone.app/mcp-vendor.htmlhttps://www.joinsandwich.com/api/mcp — no auth. Not a family inbox.POST https://api.lovedone.app/sandwichpipe/v1/events. HMAC ingest, not MCP, not live yet. Do not POST JSON-RPC there. Old host api.joinsandwich.com is dead. Spec{
"mcpServers": {
"lovedone-family": {
"url": "https://api.lovedone.app/mcp/v1",
"headers": { "Authorization": "Bearer sk-sand-…" }
}
}
}
Every email about Helen — discharge summaries, pharmacy refills, cardiology reminders, insurance EOBs, attorney correspondence — lands in one place. Every sibling sees it. Nobody is out of the loop because they weren't the one holding Mom's phone.
Each loved one gets a private, dedicated email address:
helen-smith-AB12@lovedone.app
Give that address to Helen's doctor, pharmacy, insurance company, attorney — anyone who sends emails about her care. The whole family sees what arrives, in real time.
The address format is locked: {first_name}-{last_name}-{4 alphanumeric}@lovedone.app.
The 4-character code uses letters (A-Z, no I/O) and digits (2-9) — a mental model
every American adult already has — so it's easy to dictate at a hospital intake desk:
“helen, dash, smith, dash, A-B-1-2.”
Two flows so the senior can participate however makes sense for their situation:
Will providers actually accept this?
Yes — because you're asking them to do something they already do. Every EHR scheduling
system, pharmacy management system, and patient intake form already has an “alternate contact
email” field. You're just filling it with a better value. No new workflow, no new system.
What about HIPAA?
HIPAA's personal-representative doctrine (45 CFR §164.502(g)) gives a designated family
member the right to specify a confidential-communications address that providers must use. You're
not asking providers for cooperation — you're asking them to honor a right the patient
already has. See HHS guidance.
Does the senior have to give up their existing email?
No. Providers can keep sending to Helen's personal email too.
Can I change the inbox address?
Addresses are generated once and preserved indefinitely — providers may have it in their systems
for years. If you need a new address (e.g., a compromised address), you can rotate it from settings.
The old address forwards for 90 days, then stops. Old messages are always preserved.
Can other family members see the same inbox?
Yes. That's the whole point. Every sibling you invite to your Sandwich workspace sees the same
inbox. You can assign roles (owner, coordinator, viewer) and everyone gets a per-sibling read
indicator so you always know who has seen what.
What if my mom and aunt have the same first name?
Addresses include both first and last name plus a 4-character code, so two Helens with different last
names get cleanly distinct addresses — e.g. helen-smith-AB12@… and
helen-jones-CD34@…. Distinct addresses, distinct inboxes, no confusion.
What happens to messages — do they get summarized?
Every inbound message gets an AI pass that generates a one-line summary and classifies it into a
category (appointment, pharmacy, billing, discharge, etc.). The summary appears in the inbox list
view so you can triage at a glance without opening every message.
Sandwich Pipe is the planned private-link layer between care-data producers and
LovedOne. Agencies, EHRs, and home-health platforms will POST structured events;
LovedOne lights up the right loved-one record. Pipe is not live yet.
The planned endpoint is
POST https://api.lovedone.app/sandwichpipe/v1/events.
It is being built in
Terahertz-Inc/sandwichpipe.
api.joinsandwich.com is dead and being retired.
institution_id,
subject_ref, event_type, payload — lets us onboard
any partner without redesigning the app.X-SandwichPipe-Signature: sha256=…, computed over the raw body with a
per-partner secret. Replays are cheap; forgeries are not.{
"institution_id": "sandwichsoft-sunrise-home-care",
"subject_ref": "client_8c1f",
"event_type": "visit_ended",
"occurred_at": "2026-04-16T21:04:00Z",
"payload": {
"caregiver_id": "caregiver_maria_r",
"actual_end": "2026-04-16T21:04:00Z",
"duration_minutes": 92
}
}
Compute HMAC-SHA256(raw_body, partner_secret) and send the hex digest
prefixed with sha256=. Sandwich verifies in constant time and rejects
anything older than 5 minutes (clock-skew tolerant).
const sig = "sha256=" + hmacSha256Hex(secret, rawBody); headers["X-SandwichPipe-Signature"] = sig; headers["X-SandwichPipe-Institution"] = institutionId; headers["X-SandwichPipe-Timestamp"] = new Date().toISOString();
LovedOne Soft agencies get Sandwich Pipe for free — it's wired into clock-in and clock-out. Outside partners (EHRs, hospital discharge systems, other agency platforms) can email hello@joinsandwich.com for a sandbox secret and a signed integration agreement.
LovedOne Soft is the operating system for home-care agencies. Each agency is a tenant
with its own portal — soft.lovedone.app/?slug=sunrise-home-care — and its own admin
dashboard, caregiver roster, client list, visit schedule, and message thread.
/me — pick a shift, clock in, log a note, clock out.Every record is namespaced to a tenant — no cross-tenant reads, ever.
tenants/{tenant_id}/
staff/{uid} # caregivers & admins
clients/{client_id} # +family_share_enabled, +secret_hash
visits/{visit_id} # scheduled + in-progress + completed
notes/{note_id} # observations, vitals, med confirmations
media/{media_id} # photos taken during a visit
messages/{msg_id} # threads per client
LovedOne Soft's /me route is a phone-first webapp. Caregivers see their open
shifts, pick one, clock in with a single tap, write a note, attach a photo, and
clock out. Each action emits a Sandwich Pipe event if the client has family share on —
no extra work for the caregiver.
// admin flips family share for a client await enrollFamilyShare(tenantId, clientId); // → generates secret, stores sha256 hash on client row, // → sends secret one-time to admin via secure download // every clock-out after this call emitFamilyShareEvent({ tenantId, clientId, eventType: "visit_ended", payload: { durationMinutes, noteExcerpt } });