Skip to main content
Every call carries your practice’s API key as a bearer token:

Create a key

An owner or admin of the practice creates keys in Settings → API keys, with the permissions the key needs: The key is shown once, when you create it. Copy it into your server’s secret storage right away. If it’s lost, revoke it and create a new one.

Keep it on your server

The key acts for your whole practice. Use it only from your own server:
  • Never put it in a web page, a mobile app or a browser script. The API is server to server and doesn’t answer browser (CORS) requests.
  • Never commit it to source control.

Expiry, revocation and rotation

  • Keys expire one year after they’re created.
  • Revoke a key any time in Settings → API keys; it stops working right away.
  • To rotate, create the new key, switch your system over, then revoke the old one.
A missing, unknown, revoked or expired key gets 401. A key without the scope an endpoint needs gets 403. See Errors.