Server-side APIEndpointsClinical records

Medicine catalogue

Search the medicine catalogue at a location. Stock is per location.

GET /v1/medicines/search

Note the parameter names: searchTerm, not q; limit, not size. A name that does not match is dropped silently rather than refused, which reads as a filter that does not work.

API-key only (a widget session is refused) and entitlement-gated on devapi_medicines_search.

Query parameters

NameRequiredDescription
searchTermYes—
addressIdYesA clinic location, from GET /v1/addresses.
pageNoZero-based.
limitNolimit, not size. Defaults to 10.

Try it

GET/v1/medicines/searchAPI key onlydevapi_medicines_search

searchTerm and limit, not q and size. addressId matters because stock is per location.

Query

Request
GET /v1/medicines/search?searchTerm=paracetamol&addressId=1&page=0&limit=10
to https://api.medos.one
Use a dedicated test key, and put your browser's address on its allowlist

A Developer API key authenticates on its own, so it only works from the addresses registered against it — and this page calls from your browser, not your servers. Unless your own public address is on the list you get a 403 naming it, which is the allowlist doing its job. Your browser may also reach us over IPv6 even when your server does not, so the address in the error is often not the one you expected. The key here is kept in memory only and never written to storage, but create a test key for it and deactivate that key when you are done.

Request

curl -sG "https://api.medos.one/v1/medicines/search" \
  -H "x-api-key: $MEDOS_API_KEY" \
  --data-urlencode "searchTerm=paracetamol" \
  --data-urlencode "addressId=1" \
  --data-urlencode "page=0" \
  --data-urlencode "limit=10"

Common failures

StatusCause
403 with requiredFeatureNot entitled to this operation.
403 "only available to Developer API keys"A widget session token was used. Send x-api-key.

On this page