If you are integrating HealOS with your own software rather than using it in the browser, the full reference lives at docs.healos.ai — authentication, making requests, rate limits, error shapes, the clinical-notes endpoints, and the webhook payloads.
Getting a key
API Keys in the app creates and revokes keys for your practice. A key carries your practice's access, so treat it as a credential: one key per integration, revoked the day it is no longer used, never in client-side code or a public repository.
Webhooks
Webhooks tell your system when something happened in HealOS — a note finished, for example — instead of you polling for it. You register an endpoint, verify the signature on each delivery, and respond quickly; retries follow for anything you do not acknowledge. The payload shapes and the signing scheme are in the webhook section of docs.healos.ai.
Two rules worth stating
- Anything you receive from HealOS can contain PHI. Your endpoint needs the same protections as the rest of your clinical stack, and your agreement with us has to cover it.
- Test against your own practice's data, not a customer's.
For an integration that needs something the API does not expose yet, email team@healos.ai with what you are building and the fields you need.