Write a prescription
Issue a prescription against an appointment, attributed to the staff member who entered it.
POST /v1/prescriptionsdoctorId and X-Acting-User-Id are different people. doctorId is the
practitioner the prescription is issued under; the acting user is whoever entered it.
Often the same person, frequently not — a nurse recording a doctor's prescription
sends the doctor as doctorId and themselves as the acting user. Both are required.
patientId is required. Everything else — dosages, notes, diagnoses, attachments —
is medos's own prescription shape and passes through, so a field medos gains works
here without waiting for us.
API-key only (a widget session is refused), entitlement-gated on devapi_prescriptions_create, and attributed with X-Acting-User-Id.
Permissions are medos's, not the gateway's
The gateway checks your key, your entitlement, and that the acting user belongs to your workspace. Whether that user may write a prescription is checked by medos against its own roles.
So sending a receptionist's id here is refused by medos, with medos's own
permission error — not by a 400 about the header. If a write fails for reasons
that look like role or permission, the fix is that user's medos role.
Query parameters
| Name | Required | Description |
|---|---|---|
doctorId | Yes | A query parameter, not a body field — and a different person from the acting user: the practitioner it is issued under. |
Body
| Name | Required | Description |
|---|---|---|
appointmentId | Yes | — |
patientId | Yes | — |
medicines | No | JSON array in medos's own prescription shape, so a field medos gains works here without a change on our side. |
notes | No | — |
Try it
/v1/prescriptionsAPI key onlydevapi_prescriptions_createmedos applies its own RBAC to the acting user, so a receptionist's id gets medos's permission error, not a gateway one.
Query
Body
POST /v1/prescriptions?doctorId=4{
"medicines": [
{
"name": "Amoxicillin 500mg",
"frequency": "TID",
"durationDays": 5
}
]
}https://api.medos.oneUse a dedicated test key, and put your browser's address on its allowlist
A Developer API key authenticates on its own, so it only works from the addresses registered against it — and this page calls from your browser, not your servers. Unless your own public address is on the list you get a 403 naming it, which is the allowlist doing its job. Your browser may also reach us over IPv6 even when your server does not, so the address in the error is often not the one you expected. The key here is kept in memory only and never written to storage, but create a test key for it and deactivate that key when you are done.
Request
curl -s -X POST "https://api.medos.one/v1/prescriptions?doctorId=4" \
-H "x-api-key: $MEDOS_API_KEY" \
-H "X-Acting-User-Id: 4821" \
-H "Content-Type: application/json" \
-d '{
"appointmentId": 1024,
"patientId": 1,
"medicines": [
{
"name": "Amoxicillin 500mg",
"frequency": "TID",
"durationDays": 5
}
]
}'Common failures
| Status | Cause |
|---|---|
400 naming x-acting-user-id | A write without the acting-user header. |
400 naming doctorId | A prescription write without the prescribing practitioner. |
400 | patientId missing. |
403 with requiredFeature | Not entitled to this operation. |
403 "only available to Developer API keys" | A widget session token was used. Send x-api-key. |
403 "not an active member" | The acting user is not in your workspace, or is deactivated. |
| a medos permission error | The acting user's role does not allow this. Not a gateway failure. |