Server-side APIEndpointsWorkspace

Patient form schema

The custom intake questions a clinic asks its patients.

GET /v2/workspaces/patient-form

Clinics extend the standard patient record with their own intake questions — occupation, referral source, a consent checkbox, a signature. This returns that schema, so you can render the same form your Medos users see and send the answers back as patientFormValues.

No parameters, no OTP. The workspace comes from your key.

Try it

GET/v2/workspaces/patient-form
Request
GET /v2/workspaces/patient-form
to https://api.medos.one
Use a dedicated test key, and put your browser's address on its allowlist

A Developer API key authenticates on its own, so it only works from the addresses registered against it — and this page calls from your browser, not your servers. Unless your own public address is on the list you get a 403 naming it, which is the allowlist doing its job. Your browser may also reach us over IPv6 even when your server does not, so the address in the error is often not the one you expected. The key here is kept in memory only and never written to storage, but create a test key for it and deactivate that key when you are done.

Request

curl -s "https://api.medos.one/v2/workspaces/patient-form" \
  -H "x-api-key: $MEDOS_API_KEY"

Response

{
  "fields": [
    {
      "id": "occupation",
      "type": "TEXT",
      "label": "Occupation",
      "sortOrder": 1,
      "required": false,
      "placeholder": "e.g. Architect",
      "helperText": null,
      "staffOnly": false,
      "sensitive": false
    },
    {
      "id": "referral_source",
      "type": "DROPDOWN",
      "label": "How did you hear about us?",
      "sortOrder": 2,
      "required": true,
      "options": ["Search", "Friend", "Doctor referral"]
    }
  ],
  "standardFieldOverrides": {
    "bloodGroup": { "hidden": true }
  },
  "standardSectionOverrides": {},
  "standardFieldOrder": {},
  "nativeFieldIds": ["firstName", "lastName", "email"],
  "hideableNativeFieldIds": ["bloodGroup"],
  "requirableNativeFieldIds": ["email"],
  "supportedFieldTypes": ["TEXT", "DROPDOWN", "YES_NO"]
}
FieldMeaning
fields[]The clinic's custom questions, in sortOrder. Each id is the key you use in patientFormValues.
standardFieldOverridesHow the clinic has changed the built-in fields — hidden, a replacement label, or required: true. Apply these to your own rendering of name, email, blood group and the rest.
standardSectionOverridesWhole built-in sections the clinic has hidden.
standardFieldOrderThe clinic's preferred ordering of built-in fields within each section.
nativeFieldIdsEvery built-in field id, so you can tell a custom question from a standard one.
hideableNativeFieldIds / requirableNativeFieldIdsWhich built-in fields the clinic is even allowed to hide or mandate — useful when you build an admin UI on top of this.
supportedFieldTypesThe field types this Medos version understands. Treat anything outside it as unrenderable rather than guessing.

Field types

SECTION_HEADER, NOTICE, TEXT, LONG_TEXT, NUMBER, DATE, DROPDOWN, YES_NO, CHECKBOX_GROUP, TEXT_LIST, EMAIL, PHONE, RATING, TERMS_ACCEPTANCE, SIGNATURE, FILE_UPLOAD.

Per-type extras appear only where they apply: options on DROPDOWN and CHECKBOX_GROUP, maxRating on RATING, allowedMimeTypes and maxSizeBytes on FILE_UPLOAD, precision on DATE, body on NOTICE, showWhen for conditional display.

FlagWhat to do with it
requiredEnforce it before submitting — Medos rejects a missing answer.
staffOnlyDo not show it to a patient. It is for clinic staff.
sensitiveStored encrypted. Handle and log it accordingly.
removedA retired field kept for historical answers. Do not render it.

Sending answers back

Answers go to update patient details as a patientFormValues object keyed by field id:

{ "patientFormValues": { "occupation": "Architect", "referral_source": "Friend" } }

Common failures

A clinic that has configured nothing returns fields: [] with a 200 — that is the normal state, not an error.

File and signature fields need an upload first

FILE_UPLOAD and SIGNATURE answers reference an uploaded object rather than carrying the file. That upload route is not part of this server-side surface — ask us if your integration needs it.

On this page