> ## Documentation Index
> Fetch the complete documentation index at: https://docs.clinikehr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List prescriptions

> **Permission:** `medications:read`

List one patient's prescriptions (read only).

`patient_id` is required. Prescriptions are read only and minimal: the drug, the dose, the frequency, the status and when it was written, with `source` telling a prescription sent through the clinic's e-prescribing connection (`eprescribe`) from one written in the clinic (`clinic`). There is no route to create or change a prescription. `status` filters by the prescription's status. A restricted patient's prescriptions, and any the clinic has marked sensitive, are never returned. With `Accept: application/fhir+json` the answer is a searchset Bundle of FHIR R4 MedicationRequest resources.



## OpenAPI

````yaml /openapi/ehr-api.v1.yaml get /v1/clinics/{clinic_id}/prescriptions
openapi: 3.1.0
info:
  title: ClinikEHR API
  version: 1.0.0
  description: >-
    Server-to-server REST API for a clinic's own data, reached with a key the
    clinic (or a developer workspace) creates in the developer portal.


    Authenticate every request with `Authorization: Bearer <key>`. Test keys
    reach only your workspace's own synthetic sandbox; live keys reach the
    clinic that created them. Lists wrap their rows as `{ data, has_more,
    next_cursor }`; single resources are returned directly. Errors are
    `application/problem+json` (RFC 9457) with a stable `code`.


    Write requests accept an `Idempotency-Key` header so a retry never repeats a
    change. See the guides for authentication, permissions, pagination, rate
    limits and retries.
servers:
  - url: https://api.clinikehr.com
security:
  - ApiKey: []
paths:
  /v1/clinics/{clinic_id}/prescriptions:
    get:
      tags:
        - Medications
      summary: List prescriptions
      description: >-
        **Permission:** `medications:read`


        List one patient's prescriptions (read only).


        `patient_id` is required. Prescriptions are read only and minimal: the
        drug, the dose, the frequency, the status and when it was written, with
        `source` telling a prescription sent through the clinic's e-prescribing
        connection (`eprescribe`) from one written in the clinic (`clinic`).
        There is no route to create or change a prescription. `status` filters
        by the prescription's status. A restricted patient's prescriptions, and
        any the clinic has marked sensitive, are never returned. With `Accept:
        application/fhir+json` the answer is a searchset Bundle of FHIR R4
        MedicationRequest resources.
      operationId: listPrescriptions
      parameters:
        - name: clinic_id
          in: path
          required: true
          schema:
            type: string
            format: uuid
        - name: patient_id
          in: query
          required: true
          schema:
            type: string
            format: uuid
        - name: status
          in: query
          required: false
          schema:
            type: string
            enum:
              - pending
              - dispensed
              - cancelled
              - out_of_stock
        - name: updated_since
          in: query
          required: false
          schema:
            type: string
            format: date-time
        - name: limit
          in: query
          required: false
          schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 25
        - name: starting_after
          in: query
          required: false
          schema:
            type: string
            format: uuid
      responses:
        '200':
          description: OK.
          content:
            application/json:
              schema:
                type: object
                required:
                  - data
                  - has_more
                  - next_cursor
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/Prescription'
                  has_more:
                    type: boolean
                  next_cursor:
                    type:
                      - string
                      - 'null'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/TooManyRequests'
      security:
        - ApiKey: []
components:
  schemas:
    Prescription:
      type: object
      description: >-
        A prescription, read only and deliberately minimal: the drug, the dose,
        the frequency, the status and when it was written. Nothing about
        dispensing, payment, scheduling, the prescriber or notes ever leaves the
        clinic. There is no way to create or change a prescription through the
        API. `source` is `eprescribe` for a prescription sent through the
        clinic's e-prescribing connection and `clinic` otherwise. `status:
        unknown` appears only on an `eprescribe` prescription whose status the
        e-prescribing service reports in a form the platform does not recognise.
      required:
        - id
        - patient_id
        - medication
        - status
        - source
      properties:
        id:
          type: string
          format: uuid
        patient_id:
          type: string
          format: uuid
        medication:
          $ref: '#/components/schemas/PrescriptionMedication'
        dosage:
          type:
            - string
            - 'null'
        frequency:
          type:
            - string
            - 'null'
        status:
          type: string
          enum:
            - pending
            - dispensed
            - cancelled
            - out_of_stock
            - unknown
        source:
          type: string
          enum:
            - clinic
            - eprescribe
        prescribed_at:
          type:
            - string
            - 'null'
          format: date-time
        updated_at:
          type:
            - string
            - 'null'
          format: date-time
    PrescriptionMedication:
      type: object
      required:
        - name
      properties:
        name:
          type: string
          description: >-
            The medicine's name as the clinic lists it. Never a brand, batch,
            price or manufacturer.
    Problem:
      type: object
      description: RFC 9457 application/problem+json.
      required:
        - type
        - title
        - status
        - code
        - request_id
      properties:
        type:
          type: string
          format: uri
        title:
          type: string
        status:
          type: integer
        detail:
          type: string
        code:
          type: string
        request_id:
          type: string
        errors:
          type: array
          items:
            type: object
            required:
              - pointer
              - message
            properties:
              pointer:
                type: string
              message:
                type: string
  responses:
    BadRequest:
      description: >-
        The request failed validation (unknown query parameter, limit out of
        range, malformed body).
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
    Unauthorized:
      description: >-
        Missing, malformed, unknown, revoked or expired key, or the wrong
        secret.
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
    Forbidden:
      description: >-
        The key or connection lacks the required scope, the plan does not
        include this resource, the request came from an address this key's IP
        allow-list does not permit, a TEST-environment workspace key asked for a
        clinic_id other than its own workspace's sandbox (`sandbox_only`), or a
        LIVE workspace key asked for a real clinic while its workspace's
        verification has lapsed (`not_verified`) — the response never names
        which addresses ARE allowed, nor which clinic actually is the sandbox.
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
    NotFound:
      description: The record is absent, or out of the key's scope — one message for both.
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
    TooManyRequests:
      description: Rate limited. See the Retry-After header.
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      bearerFormat: ehr_live_<keyId>_<secret> or ehr_test_<keyId>_<secret>

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.