Create or update a patient
Keep your master patient index in step with medos — find-or-create, or update by id.
POST /v1/patientsFind-or-create. Send identifying details and you get back the existing record if there is one, or a new record if there is not. It is the same resolution booking uses, so a patient you sync here and one created by a booking are one record, not two.
Send id to update. Unlike the widget's POST /v2/patients, an id in the
body is honoured — that is how you keep a record you already synced in step.
API-key only (a widget session is refused), entitlement-gated on devapi_patients_upsert, and attributed with X-Acting-User-Id.
Unknown fields are dropped, not rejected
The body is projected down to the fields medos accepts. A typo in a field name is silently ignored rather than refused, so check the returned record if a value you sent does not appear to have taken.
Body
| Name | Required | Description |
|---|---|---|
id | No | Omit to create. |
firstName | No | — |
lastName | No | — |
countryCode | No | — |
phoneNumber | No | — |
email | No | — |
gender | No | — |
dob | No | YYYY-MM-DD |
mrnNumber | No | — |
age | No | — |
bloodGroup | No | — |
patientAddress | No | JSON object, in medos's own address shape. |
Try it
/v1/patientsAPI key onlydevapi_patients_upsertMaster-index sync. Send an id to update, omit it to create. Unknown keys are dropped rather than refused.
Body
POST /v1/patients{
"countryCode": "+91"
}https://api.medos.oneUse a dedicated test key, and put your browser's address on its allowlist
A Developer API key authenticates on its own, so it only works from the addresses registered against it — and this page calls from your browser, not your servers. Unless your own public address is on the list you get a 403 naming it, which is the allowlist doing its job. Your browser may also reach us over IPv6 even when your server does not, so the address in the error is often not the one you expected. The key here is kept in memory only and never written to storage, but create a test key for it and deactivate that key when you are done.
Request
curl -s -X POST "https://api.medos.one/v1/patients" \
-H "x-api-key: $MEDOS_API_KEY" \
-H "X-Acting-User-Id: 4821" \
-H "Content-Type: application/json" \
-d '{
"countryCode": "+91"
}'At least one of id, firstName or phoneNumber is required — without one
there is nothing to match or create on, and you get a 400 rather than a success
with no id.
Common failures
| Status | Cause |
|---|---|
400 naming x-acting-user-id | A write without the acting-user header. |
400 | Nothing identifiable in the body, or a malformed email. |
403 with requiredFeature | Not entitled to this operation. |
403 "only available to Developer API keys" | A widget session token was used. Send x-api-key. |
403 "not an active member" | The acting user is not in your workspace, or is deactivated. |