Skip to content

Get started

Authentication

Every call carries an API key for one environment. Retries are safe when you reuse the same ID and body.

API keys

Create a key in the dashboard under Integrations. It's shown once. Send it on every request in the Authorization header:

cURL
curl "https://api.nezercare.com/v1/clinical-cases/CASE_ID/progress" \
  --header "Authorization: Bearer nzh_sb_..."

A missing, invalid, expired or revoked key gets 401 with code INVALID_API_CREDENTIAL.

Keep keys on your server

Never put an API key or a webhook signing secret in browser or mobile code. Rotate any key that has been pasted into chat, logs, source control or another untrusted place.

Environments

Sandbox and production are isolated. A key can reach only the organization and environment that issued it, so a resource from another environment answers 404.

EnvironmentKey prefixBase URL
Sandboxnzh_sb_https://api.nezercare.com
Productionnzh_prod_Ask your NezerCare contact.

The BAA

API keys, webhooks and every patient feature stay off until your organization has signed its BAA. An owner or administrator signs it in the dashboard under Settings, and it takes effect at once. Until then every call answers 403 with code BAA_REQUIRED. Don't retry it: sign the BAA, then call again.

Idempotency and ordering

Every lifecycle event, provider message and case update carries an ID you generate (a UUID): eventId, messageId or updateId.

  • Retry an uncertain request with the same ID and an identical body. You get the original result back, marked duplicate: true.
  • Reusing an ID with a different body returns 409.
  • Case updates must use the consecutive nextSequence from the progress endpoint. An update out of sequence returns 409.

Errors and retries

Errors are JSON with a message, and a code where one applies.

StatusMeaningRetry?
400The request is malformed or breaks the contract.No. Fix the request.
401The API key is missing, invalid, expired or revoked.No.
403The organization hasn't signed its BAA (BAA_REQUIRED).No. Sign the BAA first.
404Not found in this key's environment.No.
409An ID reused with different content, or an update out of sequence.No. The error may carry nextSequence; read the progress if not, then send the right update.
429Not sent yet, but handle it: honor Retry-After.Yes, after the wait.
5xxA problem on our side.Yes, with exponential backoff and jitter.

Network errors are safe to retry too, with the same ID and body.

The clinical boundary

A delivered webhook confirms transport only; it never means a clinician reviewed the case. NezerCare has no appointment-booking API: if your system schedules care, report it with a scheduled case update. Only an explicit resolved update closes a case.