Skip to main content
This tab lists every endpoint you can call, grouped by resource. Each page shows the request (path, query and body), every response with its fields, and the permission the key needs. The guides in Documentation explain how the pieces fit together; this tab is the exact contract.

Base URL

Every path starts with the version, /v1. Nothing breaks inside v1; see Versioning.

Authentication

Send your key as a bearer token on every request:
ehr_live_ keys reach real clinics; ehr_test_ keys reach only your workspace’s sandbox of fictional data. Never call the API from a browser or a mobile app. See Authentication.

Permissions

Each endpoint page names the permission it needs, such as allergies:read. A key carries only the permissions it was given, and an organization’s key reaches a clinic only through that clinic’s connection. A missing permission is refused with 403 scope_missing. See Permissions.

Requests and responses

  • Request and response bodies are JSON (Content-Type: application/json).
  • Lists are cursor-paginated with limit and starting_after, and answer { data, has_more, next_cursor }. See Pagination.
  • Every write accepts an Idempotency-Key header, so a retry is never applied twice; most POSTs require it. See Retries and idempotency.
  • Every failure is application/problem+json with a stable code to branch on. See Errors.
  • Requests are rate limited per key. See Rate limits.

FHIR

Clinical resources can also be read as FHIR R4. See FHIR.

Try it

Copy any example on an endpoint page and run it with your own key. Start in your sandbox with an ehr_test_ key; see the Quickstart. A Postman collection and SDKs are described in SDKs and Postman.