Patient-authorized EHR integration
Records API
Subjects, normalized records, categories, and change feeds.
List pseudonymous users with active share consent
GET /users
limitintegercursorstring: Opaque cursor. Pass nextCursor back to the endpoint that returned it, for the same subject and category; meta.changeCursor starts the change feed. Don't construct or edit it.offsetinteger: Legacy offset pagination. Prefer cursor.
Retrieve a consent-filtered normalized health-record snapshot
GET /users/{subject}/records
subjectstring (required): Stable within one application and unlinkable across applications.categoriesstring: Comma-separated consent-category subset. Omit for all authorized categories.
List records in one consent category
GET /users/{subject}/records/{category}
Stable record IDs and cursor pagination make this endpoint preferable for production ingestion. Save meta.changeCursor after an initial full read.
subjectstring (required): Stable within one application and unlinkable across applications.categorystring (required)limitintegercursorstring: Opaque cursor. Pass nextCursor back to the endpoint that returned it, for the same subject and category; meta.changeCursor starts the change feed. Don't construct or edit it.
Read incremental upserts and deletion tombstones
GET /users/{subject}/records/{category}/changes
Pass the changeCursor returned by the category snapshot. Apply changes in sequence order. A delete change has record null and must remove the stable recordId locally. Upserts may have record null if a later source deletion occurred before this historical page was read.
subjectstring (required): Stable within one application and unlinkable across applications.categorystring (required)limitintegercursorstring: Opaque cursor. Pass nextCursor back to the endpoint that returned it, for the same subject and category; meta.changeCursor starts the change feed. Don't construct or edit it.