Skip to content
Hermes Health API
GuidesOpenAPI spec

Endpoints

Clinical data embed

POST/v0/companies/{company_id}/projects/{project_id}/patients/{patient_id}/clinical-data-embed-token

Mint a clinical-data embed token

Mint an embed token for iframing the clinical-data browse surface of one patient.

The token authorizes the read-only embed at GET /ui/clinical-data/embed?token=...: anyone holding it can browse this patient’s visits, procedures, diagnoses, prescription fills, and lab results, all attributed to the minting user. The token is locked to this single patient — the embed surface forces the company/project/patient browse filters server-side, so a holder can never widen past this patient. Tokens are stateless, sealed with authenticated encryption (encrypt-then-MAC, keyed apart from the generic URL-query oracle and the other embed tokens), and expire one hour after minting — mint a fresh token each time you render the page that hosts the iframe.

Prefer this over the per-table browse endpoints (/v0/visits/browse, /v0/diagnoses/browse, …) for any surface that shows a patient’s clinical data to end users: the raw clinical-data table schemas change frequently as we expand claims coverage, and an embedded iframe picks up those changes automatically with no schema-drift maintenance on your side.

See Embedding the clinical-data UI for the full iframe integration guide.

Request bodyapplication/json

object

ReturnsSuccess

  • tokenstring

    The embed token: an opaque encrypted string to pass to the embed as its `token` query parameter. It grants access to what it was minted for until it expires, so mint a fresh one rather than storing it.

Errors

400401404500