Skip to content
Hermes Health API
GuidesOpenAPI spec

Endpoints

Auth intake

POST/v0/companies/{company_id}/projects/{project_id}/auth-intake/embed-token

Mint an auth-intake token for a new patient

Route #1 — brand-new patient. Optional demographics pre-fill the form; an optional site makes the authorization site-specific.

Request bodyapplication/json

object

ReturnsSuccess

  • tokenstring

    The embed token: an opaque encrypted string to pass to the embed as its `token` query parameter. It grants access to what it was minted for until it expires, so mint a fresh one rather than storing it.

Errors

400401404500

POST/v0/companies/{company_id}/projects/{project_id}/patients/{patient_id}/auth-intake/embed-token

Mint an auth-intake token for a patient

Route #2 — existing patient, broad authorization.

Request bodyapplication/json

object

ReturnsSuccess

  • tokenstring

    The embed token: an opaque encrypted string to pass to the embed as its `token` query parameter. It grants access to what it was minted for until it expires, so mint a fresh one rather than storing it.

Errors

400401404500

POST/v0/companies/{company_id}/projects/{project_id}/patients/{patient_id}/record-requests/{request_id}/auth-intake/embed-token

Mint an auth-intake token for a record request

Route #3 — existing patient + record request, site-specific authorization.

Request bodyapplication/json

object

ReturnsSuccess

  • tokenstring

    The embed token: an opaque encrypted string to pass to the embed as its `token` query parameter. It grants access to what it was minted for until it expires, so mint a fresh one rather than storing it.

Errors

400401404500