What a live key needs
These routes are live, but reaching them needs more than a key. Every one of them carries a patient-data permission, and a key can only be given one once:- your clinic’s own key: the clinic’s plan is Team (or Business, on the Pharmacy and Diagnostics editions) or Enterprise, the clinic has bought the API add-on (or is on an Enterprise contract, which includes it) and the clinic owner has accepted the current API data agreement;
- an organization’s key: your workspace is on a paid plan whose contract with us includes patient data, your organization has been approved for patient data (an application on Settings → Verification, decided by a reviewer, covering the kinds of data you are approved for), you have accepted the current data-protection addendum, and the clinic you’re connecting to has approved that scope for your connection.
/v1/clinics/{clinic_id}/crm/, and their permissions are patient-data permissions, so the add-on, the
agreement and (for an organization) the approval above all apply. Pipelines and stages are reference data
with no patient in them.
Until both conditions hold, a request for one of these scopes is refused the same way a missing key
would be — see Permissions for the exact scopes (patients:read/write,
appointments:read/write, notes:read/write) and Drug requests for that
family’s own page.