Skip to main content
Partner API v2 uses a Bearer token. Scan issues the token from Get API keys (sandbox) or from the API access tab (production). Send it on every /api/v2 request:
There is no sign-in step. The token is the credential.

Environments

The docs navbar Get API keys button always opens the sandbox form. Production tokens are never issued from that page. Use the matching host for the token. A sandbox token against production (or the reverse) returns 401.

Sandbox tokens

Use Get API keys with a company email to receive a sandbox api_token. Consumer and disposable email domains are not eligible, and each company domain can receive one sandbox token. Store the token in a secret manager:
The initial sandbox allows 2,000 successful authenticated requests and expires after 7 days, whichever happens first. Requests that return 4xx or 5xx do not consume the allowance. Use synthetic data only. The sandbox is updated frequently — retry transient errors before escalating. An optional access code entered on the initial Get API keys form skips the trial and issues an unlimited 90-day sandbox token. Without a code, Scan reviews extension requests and can extend the same token to an unlimited 90-day term. Production credentials are issued separately. Some endpoints are disabled until Scan enables them for your account, including payment read, notification read, auto-book, and FHIR. Calls to those endpoints return 403 with the error envelope (code endpoint_not_enabled). The token is shown once and cannot be recovered. If it is lost or exposed, contact [email protected] to revoke it and issue a replacement. Never put it in browser code, URLs, logs, or chat.

Sandbox limit responses

Once the sandbox window elapses or the request cap is consumed, /api/v2 endpoints stop returning data and respond with one of the following. Treat either response as the signal to contact Scan.com for an extension. Both use the envelope in Errors and limits: error, message, type, code, request_id, and documentation_url.

Call an authenticated endpoint

Courier SSO

Courier SSO (POST /api/v2/auth/sso) uses the same Bearer token. Send Authorization: Bearer <api_token> and Scan returns a one-time portal URL.