Get started
Authentication
Every call carries an API key for one environment. Retries are safe when you reuse the same ID and body.
API keys
Create a key in the dashboard under Integrations. It's shown once. Send it on every request in the Authorization header:
curl "https://api.nezercare.com/v1/clinical-cases/CASE_ID/progress" \
--header "Authorization: Bearer nzh_sb_..."A missing, invalid, expired or revoked key gets 401 with code INVALID_API_CREDENTIAL.
Keep keys on your server
Never put an API key or a webhook signing secret in browser or mobile code. Rotate any key that has been pasted into chat, logs, source control or another untrusted place.
Environments
Sandbox and production are isolated. A key can reach only the organization and environment that issued it, so a resource from another environment answers 404.
| Environment | Key prefix | Base URL |
|---|---|---|
| Sandbox | nzh_sb_ | https://api.nezercare.com |
| Production | nzh_prod_ | Ask your NezerCare contact. |
The BAA
API keys, webhooks and every patient feature stay off until your organization has signed its BAA. An owner or administrator signs it in the dashboard under Settings, and it takes effect at once. Until then every call answers 403 with code BAA_REQUIRED. Don't retry it: sign the BAA, then call again.
Idempotency and ordering
Every lifecycle event, provider message and case update carries an ID you generate (a UUID): eventId, messageId or updateId.
- Retry an uncertain request with the same ID and an identical body. You get the original result back, marked
duplicate: true. - Reusing an ID with a different body returns
409. - Case updates must use the consecutive
nextSequencefrom the progress endpoint. An update out of sequence returns409.
Errors and retries
Errors are JSON with a message, and a code where one applies.
| Status | Meaning | Retry? |
|---|---|---|
400 | The request is malformed or breaks the contract. | No. Fix the request. |
401 | The API key is missing, invalid, expired or revoked. | No. |
403 | The organization hasn't signed its BAA (BAA_REQUIRED). | No. Sign the BAA first. |
404 | Not found in this key's environment. | No. |
409 | An ID reused with different content, or an update out of sequence. | No. The error may carry nextSequence; read the progress if not, then send the right update. |
429 | Not sent yet, but handle it: honor Retry-After. | Yes, after the wait. |
5xx | A problem on our side. | Yes, with exponential backoff and jitter. |
Network errors are safe to retry too, with the same ID and body.
The clinical boundary
A delivered webhook confirms transport only; it never means a clinician reviewed the case. NezerCare has no appointment-booking API: if your system schedules care, report it with a scheduled case update. Only an explicit resolved update closes a case.