Create a key
An owner or admin of the practice creates keys in Settings → API keys, with the permissions the key needs:
The key is shown once, when you create it. Copy it into your server’s secret storage right away. If it’s lost,
revoke it and create a new one.
Keep it on your server
The key acts for your whole practice. Use it only from your own server:- Never put it in a web page, a mobile app or a browser script. The API is server to server and doesn’t answer browser (CORS) requests.
- Never commit it to source control.
Expiry, revocation and rotation
- Keys expire one year after they’re created.
- Revoke a key any time in Settings → API keys; it stops working right away.
- To rotate, create the new key, switch your system over, then revoke the old one.
401. A key without the scope an endpoint needs gets 403. See
Errors.