The patient roster
Every patient in the workspace, paged and filterable — granted separately from the lookups.
GET /v1/patientsPage through it for an initial import, then keep up with the narrower lookups rather than re-reading the roster.
API-key only (a widget session is refused) and entitlement-gated on devapi_patients_list.
Granted separately from lookup
devapi_patients_list is its own entitlement because this returns every
patient in the workspace rather than one you had already identified. Expect it to be
refused even where the by-MRN and by-email lookups are allowed.
Query parameters
| Name | Required | Description |
|---|---|---|
addressId | No | A clinic location, from GET /v1/addresses. |
doctorId | No | A practitioner's medos user id, from GET /v1/doctors. |
mrnNumber | No | — |
countryCode | No | — |
phoneNumber | No | — |
email | No | — |
name | No | — |
archived | No | — |
page | No | Zero-based. |
size | No | — |
Try it
/v1/patientsAPI key onlydevapi_patients_listEvery patient in the workspace. Granted separately from the single-patient lookups on purpose.
Query
GET /v1/patients?page=0&size=20https://api.medos.oneUse a dedicated test key, and put your browser's address on its allowlist
A Developer API key authenticates on its own, so it only works from the addresses registered against it — and this page calls from your browser, not your servers. Unless your own public address is on the list you get a 403 naming it, which is the allowlist doing its job. Your browser may also reach us over IPv6 even when your server does not, so the address in the error is often not the one you expected. The key here is kept in memory only and never written to storage, but create a test key for it and deactivate that key when you are done.
Request
curl -sG "https://api.medos.one/v1/patients" \
-H "x-api-key: $MEDOS_API_KEY" \
--data-urlencode "page=0" \
--data-urlencode "size=20"Common failures
| Status | Cause |
|---|---|
403 with requiredFeature | Not entitled to this operation. |
403 "only available to Developer API keys" | A widget session token was used. Send x-api-key. |