Server-side APIEndpointsClinical records

Prescription PDF

The rendered prescription as application/pdf bytes, keyed by appointment.

GET /v1/prescriptions/{appointmentId}/pdf

Answers application/pdf bytes on success, and JSON on failure — so read the content type rather than assuming the body is a file.

API-key only (a widget session is refused) and entitlement-gated on devapi_prescriptions_pdf.

This one is keyed by appointment, not by prescription

Note the path variable. GET /v1/prescriptions/{id} takes a prescription id; GET /v1/prescriptions/{appointmentId}/pdf takes an appointment id. Passing a prescription id to the PDF route will either 404 or hand you somebody else's document.

Path parameters

NameRequiredDescription
appointmentIdYesThe appointment, not the prescription.

Try it

GET/v1/prescriptions/:appointmentId/pdfAPI key onlydevapi_prescriptions_pdf

Keyed by **appointment** id, not prescription id — the same path segment means a prescription id one route over.

Path

Request
GET /v1/prescriptions//pdf
to https://api.medos.one
Use a dedicated test key, and put your browser's address on its allowlist

A Developer API key authenticates on its own, so it only works from the addresses registered against it — and this page calls from your browser, not your servers. Unless your own public address is on the list you get a 403 naming it, which is the allowlist doing its job. Your browser may also reach us over IPv6 even when your server does not, so the address in the error is often not the one you expected. The key here is kept in memory only and never written to storage, but create a test key for it and deactivate that key when you are done.

Request

curl -s "https://api.medos.one/v1/prescriptions/1024/pdf" \
  -H "x-api-key: $MEDOS_API_KEY" \
  -o prescription.pdf

Common failures

StatusCause
403 with requiredFeatureNot entitled to this operation.
403 "only available to Developer API keys"A widget session token was used. Send x-api-key.

On this page