Server-side APIEndpointsLocations & configuration

Locations

Every location in your workspace, with the addressId nearly every other endpoint wants.

GET /v1/addresses

Every other endpoint returns ids. This tells you what an addressId means. Read it once at setup, cache it, and refresh when the clinic changes something.

API-key only (a widget session is refused) and entitlement-gated on devapi_catalog_addresses.

The workspace is implicit — and this path differs from medos's own

This does not take a workspaceId. It comes from your API key, and a workspace you name in the path or query is ignored.

That matters because medos's internal API has a path with the same name that is workspace-explicit. GET /v1/addresses here means your key's workspace's locations — not "all locations", and not a workspace you pass in.

Try it

GET/v1/addressesAPI key onlydevapi_catalog_addresses

Your workspace's locations. The workspace comes from the key — sending an id changes nothing.

Request
GET /v1/addresses
to https://api.medos.one
Use a dedicated test key, and put your browser's address on its allowlist

A Developer API key authenticates on its own, so it only works from the addresses registered against it — and this page calls from your browser, not your servers. Unless your own public address is on the list you get a 403 naming it, which is the allowlist doing its job. Your browser may also reach us over IPv6 even when your server does not, so the address in the error is often not the one you expected. The key here is kept in memory only and never written to storage, but create a test key for it and deactivate that key when you are done.

Request

curl -s "https://api.medos.one/v1/addresses" \
  -H "x-api-key: $MEDOS_API_KEY"

Common failures

StatusCause
403 with requiredFeatureNot entitled to this operation.
403 "only available to Developer API keys"A widget session token was used. Send x-api-key.

On this page