/api/v2 request:
Environments
The docs navbar Get API keys button always opens the sandbox form.
Production tokens are never issued from that page.
Use the matching host for the token. A sandbox token against production (or the
reverse) returns
401.
Sandbox tokens
Use Get API keys with a company email to receive a sandboxapi_token.
Consumer and disposable email domains are not eligible, and each company
domain can receive one sandbox token. Store the token in a secret manager:
4xx or 5xx do not
consume the allowance. Use synthetic data only.
The sandbox is updated frequently — retry transient errors before escalating.
An optional access code entered on the initial Get API keys form skips the
trial and issues an unlimited 90-day sandbox token. Without a code, Scan reviews
extension requests and can extend the same token to an unlimited 90-day term.
Production credentials are issued separately.
Some endpoints are disabled until Scan enables them for your account, including
payment read, notification read, auto-book, and FHIR. Calls to those endpoints
return 403 with the error envelope (code endpoint_not_enabled).
The token is shown once and cannot be recovered. If it is lost or exposed,
contact [email protected] to revoke it and issue a replacement.
Never put it in browser code, URLs, logs, or chat.
Sandbox limit responses
Once the sandbox window elapses or the request cap is consumed,/api/v2
endpoints stop returning data and respond with one of the following. Treat
either response as the signal to contact Scan.com for an extension.
Both use the envelope in Errors and limits:
error, message,
type, code, request_id, and documentation_url.
Call an authenticated endpoint
Courier SSO
Courier SSO (POST /api/v2/auth/sso) uses the same Bearer token. Send
Authorization: Bearer <api_token> and Scan returns a one-time portal URL.
