Skip to content
Hermes Health API
GuidesOpenAPI spec

Endpoints

Patient authorization

GET/v0/companies/{company_id}/projects/{project_id}/patients/{patient_id}/authorization

Retrieve a patient's authorization

Fetch the authorization file plus its auth-check analysis for a patient.

The analysis field inside the response wraps the raw Analysis / AuthCheck schema, which changes often as we expand document-type and edge-case coverage. For end-user-facing surfaces, prefer the iframe embed via the embedToken on PatientOutput — see Embedding the auth-check UI.

ReturnsSuccess

  • uploadHeadersobject

    Extra headers to send with the upload. Normally empty.

  • expiresIninteger

    How long the URLs in this object stay valid, in seconds from when they were issued. Fetch a fresh object rather than caching one.

  • looseFilesobject[]

    Other files stored under this file's location that are not part of its own document set, such as separately uploaded scans, each with its own short-lived download URL. Empty when there are none or when this response only offers an upload.

  • looseFiles[].urlstring

    Short-lived presigned URL to download the file.

  • looseFiles[].fileNamestring

    The name a reader sees. For a record request's deliverables this is the unique name the shared presentation assigned (see `DeliverableView`), so it can differ from the object's own basename when two returns brought the same file name; everywhere else it IS the basename.

  • looseFiles[].keystring

    The file's full storage path, `/`-separated.

  • looseFiles[].sizeinteger

    The file's size in bytes.

  • looseFiles[].lastModifiedstring

    When the file was last written.

Conditional attributes

  • downloadUrlstring

    Short-lived presigned URL to download the file. Null when no file is stored yet, or when this response only offers an upload.

  • uploadUrlstring

    Short-lived presigned URL to upload the file: `PUT` the raw bytes to it exactly as issued, with no `Authorization` header. Uploading again replaces the file. Null when this response only offers a download.

  • extractionobject

    The document's extraction (form data under `data`, plus text and page count). Null for non-auth-check files.

  • verdictsobject

    The auth-check verdicts derived from `extraction`. Null for non-auth-check files or when the document hasn't been analyzed.

  • verdictCountsobject

    Tally of `verdicts` by status, a readability convenience for API consumers. Null exactly when `verdicts` is null.

  • embedTokenstring

    Standalone auth-check embed token, pre-minted on the upload path when the caller supplies patient context alongside the request for an upload URL. Equivalent to the token from `POST /v0/auth-check/<filename>/embed-token`, saving that round-trip. Null when no patient context was supplied.

  • looseFiles[].folderstring

    The display folder this file sits in, `/`-joined, relative to the listing root. Populated only where a listing presents a tree — a record request's deliverables — and omitted from the payload otherwise.

  • looseFiles[].uploadedByobject | object | object | object | object | object | object | object | object | object | object

    Who or what placed this file. Absent for older files recorded without attribution.

  • uploadedByobject | object | object | object | object | object | object | object | object | object | object

    Who or what placed this file. Absent when no attribution was recorded or when this endpoint does not report it.

Errors

401404500

DELETE/v0/companies/{company_id}/projects/{project_id}/patients/{patient_id}/authorization

Delete a patient's authorization

Deletes the authorization document on file for the patient, along with its analysis and the documents carved from it. Authorizations are retained for audits, so earlier versions are kept. The call succeeds with an empty body even when no document is on file, so repeating it is safe. It answers 404 when the patient does not exist or the caller cannot see it.

ReturnsSuccess

Errors

401404500

HEAD/v0/companies/{company_id}/projects/{project_id}/patients/{patient_id}/authorization

Check a patient authorization's status

Returns the x-progress and x-etag headers without transferring the document, so you can poll whether auth-check analysis has finished.

ReturnsFile metadata headers

Errors

401404500