Six pieces, all live today — most switched on inside the product by a clinic's own admin; the OpenAPI document and SDKs are the same contract for every clinic.
Get a key, push a lead, hear back. Every example below runs as written against your own practice.
# Every call: the key is a bearer token, same as a login token. curl https://medappz.com/v1/leads \ -H "Authorization: Bearer mza_ab12cd34ef_...yoursecret..."
Idempotency-Key on every write, and a retried request (timeouts, double-clicks, queue replays) can never create two leads, two bills, or two bookings.curl -X POST https://medappz.com/v1/leads \
-H "Authorization: Bearer mza_..." \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"name": "Asha Verma",
"phone": "+919876543210",
"source": "website",
"note": "Asked about a skin consultation"
}'
# 201 → {"data": {"id": "…", "status": "new", …}}# Every delivery carries a signature header:
# x-medappz-signature: t=1722578400,v1=<hex hmac>
# Verify: HMAC-SHA256 over "<t>.<raw body>" with your webhook secret.
const [tPart, vPart] = header.split(',');
const ts = tPart.slice(2), theirs = vPart.slice(3);
const mine = crypto.createHmac('sha256', SECRET)
.update(ts + '.' + rawBody).digest('hex');
// timing-safe compare mine vs theirs; reject if ts is older than 5 min.They keep every integration safe, and the API enforces them rather than trusting you to remember.
Idempotency-Key; retries become no-ops, not duplicates.{
"error": {
"code": "BUSINESS_RULE_VIOLATION",
"message": "This patient already has a session on this date.",
"requestId": "req_01J…"
}
}Build in a sandbox clinic, pass the checklist, and MedAppz lists your app for clinics. Three of the four parts are live; payouts of the revenue share are not built yet.