Skip to content
Hermes Health API
GuidesOpenAPI spec

Endpoints

Record request authorization

GET/v0/companies/{company_id}/projects/{project_id}/patients/{patient_id}/record-requests/{request_id}/authorization

Retrieve a record request's authorization

Get authorization analysis for a specific record request. The request’s DOS is threaded through the auth-check pipeline so check_dates_of_service can validate the form’s extracted DOS against the request.

The analysis field inside the response wraps the raw Analysis / AuthCheck schema, which changes often as we expand document-type and edge-case coverage. For end-user-facing surfaces, prefer the iframe embed via the embedToken on RecordRequestOutput — see Embedding the auth-check UI.

ReturnsSuccess

  • uploadHeadersobject

    Extra headers to send with the upload. Normally empty.

  • expiresIninteger

    How long the URLs in this object stay valid, in seconds from when they were issued. Fetch a fresh object rather than caching one.

  • looseFilesobject[]

    Other files stored under this file's location that are not part of its own document set, such as separately uploaded scans, each with its own short-lived download URL. Empty when there are none or when this response only offers an upload.

  • looseFiles[].urlstring

    Short-lived presigned URL to download the file.

  • looseFiles[].fileNamestring

    The name a reader sees. For a record request's deliverables this is the unique name the shared presentation assigned (see `DeliverableView`), so it can differ from the object's own basename when two returns brought the same file name; everywhere else it IS the basename.

  • looseFiles[].keystring

    The file's full storage path, `/`-separated.

  • looseFiles[].sizeinteger

    The file's size in bytes.

  • looseFiles[].lastModifiedstring

    When the file was last written.

Conditional attributes

  • downloadUrlstring

    Short-lived presigned URL to download the file. Null when no file is stored yet, or when this response only offers an upload.

  • uploadUrlstring

    Short-lived presigned URL to upload the file: `PUT` the raw bytes to it exactly as issued, with no `Authorization` header. Uploading again replaces the file. Null when this response only offers a download.

  • extractionobject

    The document's extraction (form data under `data`, plus text and page count). Null for non-auth-check files.

  • verdictsobject

    The auth-check verdicts derived from `extraction`. Null for non-auth-check files or when the document hasn't been analyzed.

  • verdictCountsobject

    Tally of `verdicts` by status, a readability convenience for API consumers. Null exactly when `verdicts` is null.

  • embedTokenstring

    Standalone auth-check embed token, pre-minted on the upload path when the caller supplies patient context alongside the request for an upload URL. Equivalent to the token from `POST /v0/auth-check/<filename>/embed-token`, saving that round-trip. Null when no patient context was supplied.

  • looseFiles[].folderstring

    The display folder this file sits in, `/`-joined, relative to the listing root. Populated only where a listing presents a tree — a record request's deliverables — and omitted from the payload otherwise.

  • looseFiles[].uploadedByobject | object | object | object | object | object | object | object | object | object | object

    Who or what placed this file. Absent for older files recorded without attribution.

  • uploadedByobject | object | object | object | object | object | object | object | object | object | object

    Who or what placed this file. Absent when no attribution was recorded or when this endpoint does not report it.

Errors

401404500