REST API Reference

HMS4all exposes a REST API across 37 modules. All endpoints require JWT or API key authentication unless noted otherwise. The complete, always-current reference is the auto-generated Swagger UI — the sample below is a quick tour.


Swagger UI

The interactive Swagger UI is available at your API instance:

# Swagger UI
https://your-api.hms4all.com/api/docs

# OpenAPI JSON spec
https://your-api.hms4all.com/.well-known/openapi.json

Base URL

All API requests go to your API instance. Include the Authorization header and x-tenant-id header (for JWT auth):

curl https://your-api.hms4all.com/patients \
  -H "Authorization: Bearer <token>" \
  -H "x-tenant-id: <tenant-id>"

Endpoint Reference

Key endpoints by category. See Swagger UI for the complete list.

Authentication

MethodPathDescription
POST/auth/loginLogin and get JWT token
GET/auth/meGet current user profile

Patients

MethodPathDescription
GET/patientsList patients (paginated)
POST/patients/registerRegister new patient
GET/patients/:idGet patient by ID

Appointments

MethodPathDescription
GET/appointmentsList appointments
POST/appointmentsCreate appointment
PATCH/appointments/:id/statusUpdate appointment status
GET/appointments/queueGet current queue

Encounters (OPD)

MethodPathDescription
GET/encountersList encounters
POST/encountersCreate encounter
GET/encounters/:idGet encounter details
PATCH/encounters/:id/vitalsAdd vitals
POST/encounters/:id/prescriptionsAdd prescription

Admissions (IPD)

MethodPathDescription
POST/admissionsAdmit patient
GET/admissions/:idGet admission details
POST/admissions/:id/dischargeDischarge patient

AI Agents

MethodPathDescription
GET/agenty/meta/toolsList all MCP tools (public)
GET/agenty/meta/skillsList all A2A skills (public)
GET/agenty/admin/auditAgent audit logs
GET/agent-actions/pendingList pending HITL actions
POST/agent-actions/:id/approveApprove HITL action
POST/agent-actions/:id/rejectReject HITL action

Billing

MethodPathDescription
GET/billingList bills
POST/billingCreate bill
GET/billing/dashboardBilling dashboard stats

API Playground

API Playground

Error Responses

The API returns standard HTTP status codes with JSON error bodies:

{
  "statusCode": 400,
  "message": "Validation failed",
  "error": "Bad Request"
}

// Common codes:
// 400 — Validation error
// 401 — Authentication required
// 403 — Insufficient permissions
// 404 — Resource not found
// 429 — Rate limit exceeded

Next Steps