Get started
For developers

An API you can integrate before lunch.

Everything the product does runs on this API — the web app is just another client. One base URL, bearer auth, JSON in and out, and honest errors with request ids. Here is what you can use today, the three integrations people actually build, and the programme for listing your own app.

  • Bearer auth
  • Idempotent writes
  • Signed webhooks
Live today

What you can use today

Six pieces, all live today — most switched on inside the product by a clinic's own admin; the OpenAPI document and SDKs are the same contract for every clinic.

LiveAPI keysCreated by an admin, shown once, scoped to named permissions and revoked instantly. A key can only ever reach its own clinic.
LiveWebhooksSigned with HMAC-SHA256, retried with backoff (1 minute up to 8 hours), every delivery logged, and a test event on a button.
LiveDataVault streamsYour own records streamed to your MongoDB, a Google Sheet or a webhook, each stream with its own cursor. A stream carrying patient data needs a recorded acknowledgement first.The DataVault app page →
LiveKeyRingBring your own AI provider, mail domain, payment gateway or WhatsApp number. Keys are sealed, checked with the provider on the spot, and never shown back.The KeyRing app page →
LiveVoice ingest APIFor recorders, phone apps and meeting notetakers: open a session, stream transcript segments, close it. MedAppz sorts what was said into proposals in the Voice Inbox for a person to accept. Device keys (mzv_…) are made in the Voice Inbox; progress comes back as server-sent events and signed webhooks.Voice everywhere →
LiveOpenAPI document and SDKsAn OpenAPI 3.1 document for every route a key can reach, generated from the same controllers as the reference below — and zero-dependency TypeScript and Python clients built from it, both downloadable as a .zip. Build against a contract instead of reverse-engineering the web app’s own calls.Download the document and SDKs →
Three flows

The three integrations people actually build.

Get a key, push a lead, hear back. Every example below runs as written against your own practice.

  1. Get a keyAn admin creates API keys in the app under Admin → Integrations. Keys look like mza_<prefix>_<secret>, are shown once, and are scoped — a lead-pushing key cannot read charts. Revoke any time; revocation is immediate.
    # Every call: the key is a bearer token, same as a login token.
    curl https://medappz.com/v1/leads \
      -H "Authorization: Bearer mza_ab12cd34ef_...yoursecret..."
  2. Push a lead from your website or CRMThe most-built integration: an enquiry form on your site lands in the clinic’s LeadDesk pipeline, deduplicated by phone, worked to a consultation. Send an Idempotency-Key on every write, and a retried request (timeouts, double-clicks, queue replays) can never create two leads, two bills, or two bookings.
    curl -X POST https://medappz.com/v1/leads \
      -H "Authorization: Bearer mza_..." \
      -H "Content-Type: application/json" \
      -H "Idempotency-Key: $(uuidgen)" \
      -d '{
        "name": "Asha Verma",
        "phone": "+919876543210",
        "source": "website",
        "note": "Asked about a skin consultation"
      }'
    
    # 201 → {"data": {"id": "…", "status": "new", …}}
  3. Hear back with webhooksSubscribe to events (lead created, appointment booked, bill paid) and MedAppz calls your URL — signed, retried with backoff, and every delivery inspectable in the app. Use the Send test event button in Admin → Integrations to get a signed hello-world delivery before wiring anything real.
    # Every delivery carries a signature header:
    #   x-medappz-signature: t=1722578400,v1=<hex hmac>
    # Verify: HMAC-SHA256 over "<t>.<raw body>" with your webhook secret.
    
    const [tPart, vPart] = header.split(',');
    const ts = tPart.slice(2), theirs = vPart.slice(3);
    const mine = crypto.createHmac('sha256', SECRET)
      .update(ts + '.' + rawBody).digest('hex');
    // timing-safe compare mine vs theirs; reject if ts is older than 5 min.
House rules

The three rules of the house

They keep every integration safe, and the API enforces them rather than trusting you to remember.

Tenancy comes from the token, never the payload.There is no organisation id parameter anywhere — a key can only ever touch its own clinic’s data.
Writes are idempotent.Send an Idempotency-Key; retries become no-ops, not duplicates.
Patient messaging is consent-gated.Anything that would message a patient checks their consent record first and refuses without it — your integration cannot spam even by accident.
Reference

Errors you can act on, and the full reference

A structured error envelopeEvery error carries a stable code, a human message, and the request id to quote when you write to us.
{
  "error": {
    "code": "BUSINESS_RULE_VIOLATION",
    "message": "This patient already has a session on this date.",
    "requestId": "req_01J…"
  }
}
The full referenceEvery endpoint a key can call, with the scopes it needs, is in the API reference, generated from the code that serves it. Rate limits are per key — 600 requests a minute — and public endpoints are tighter.Building something bigger — an ABDM bridge, a device feed, a lab analyzer? Write to hello@medappz.com and an engineer answers, not a queue. Or start where every integration starts: create a practice and issue yourself a key.
Third-party apps

The app programme for third-party developers

Build in a sandbox clinic, pass the checklist, and MedAppz lists your app for clinics. Three of the four parts are live; payouts of the revenue share are not built yet.

A sandbox clinicLiveSign up below and get a clinic of your own with twelve synthetic patients and an API key. It can never hold real patients: messages, AI and uploads are off, it cannot be turned into a real clinic, and it closes after 30 days without use.
CertificationLiveA checklist the server runs on your app before MedAppz sees it: the scopes it asks for, an https privacy notice, the data it handles (which must cover what the scopes reach), webhooks that have received a delivery, and a test run against your sandbox. Then a person at MedAppz approves it or sends it back with a reason.
Listing and ratingsLiveApproved apps are listed for clinics. A clinic connects one from Admin → Integrations and gets a key with only the approved scopes; only a clinic that connected an app can rate it, once.
Revenue sharePayouts not built yetThe share agreed with you is recorded when your app is approved, and shown in your console. Paying it out is not built yet: it waits on MedAppz’s payments set-up, and nothing is owed or paid through the programme until then.
See the apps other developers have listed. Selling MedAppz itself rather than building on it? That is the partner programme. The roadmap shows everything else in development.
Make your sandbox clinic