Inventory and listing scopes need only a plan with API access. Patient-data scopes (patients,
appointments, clinical notes, drug requests, dispensing history) additionally need the clinic’s API add-on and an
accepted API data agreement — see the overview.
No scope exposes a sale’s price or total, or who served the customer.
A test key may hold the patient-data scopes: it reaches only your workspace’s sandbox, which holds invented
patients, notes and appointments. The add-on and agreement above apply to a live key.
An organization’s live key can carry a patient-data scope only when patient data is open on the platform, the
workspace plan includes it, your organization is approved for that kind of data (apply on Settings →
Verification) and you have accepted the current data-protection addendum on Agreements. In the Create key
panel a scope that is not yet available is greyed out, and hovering it says the first thing that is missing. The same
approval is checked on every request, so a revoked approval stops access with the next one. Connect to a clinic
works the same way: an approved organization can request exactly the kinds it is approved for.
Inventory scopes — one clinic’s own data
Insurance payers
Providers
Patient-data scopes — gated behind the API add-on and the API data agreement
An organization is approved by kind of data; each kind covers these scopes:Listing scopes — the pharmacy network
These apply only to an organization’s key, and only for clinics that have connected to you — see Connections.Requesting the right one
Ask for only what your integration actually uses. A storefront “in stock” badge needsinventory.availability:read; it almost never needs inventory.stock:read. This isn’t just tidy — a key or a connection with fewer scopes does less damage if it ever leaks.
What happens if a scope is missing
Calling an endpoint your key isn’t permitted for returns a403:
plan_required — which looks similar but means the clinic’s plan doesn’t include this resource at all, regardless of what the key was granted.