canonical: https://jentic.com/apis/oystehr.com/oystehr

# OystEHR API

OystEHR healthcare platform API for managing applications, users, M2M clients, and FHIR-based resources, plus specialized services for messaging, payments, telemedicine, lab, eRx, fax, and cloud storage. The API exposes 28 endpoints secured with bearer authentication.

## For AI agents

Programmatically create an application, list applications. Covers 28 operations with bearer authentication.

## Scope

Does not handle communications, crm, or developer tools - use for payments only.

## Capabilities

- Create an application
- List applications
- Get application details
- Update an application
- Delete an application
- Rotate application secret
- Revoke refresh token

## Use cases

### Payments Operations

Use the OystEHR API to perform payments operations programmatically. The API provides 28 endpoints covering core functionality including create an application, list applications, get application details.

Example prompt: Call POST /application to create an application

### Automated Applications Management

Automate applications operations by combining multiple OystEHR API endpoints. Agents can list applications and then get application details in a single workflow.

Example prompt: Call GET /application to list applications, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call OystEHR API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle bearer tokens manually.

Example prompt: Search Jentic for 'create an application', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | /application | Create an application |
| GET | /application | List applications |
| GET | /application/{applicationId} | Get application details |
| PATCH | /application/{applicationId} | Update an application |
| DELETE | /application/{applicationId} | Delete an application |
| POST | /application/{applicationId}/rotate-secret | Rotate application secret |
| POST | /application/{applicationId}/revoke-refresh-token | Revoke refresh token |
| POST | /application/{applicationId}/revoke-access-token | Revoke access token |

## Key resources

- **Applications** — Application management and credential rotation
- **Users** — User management, invitations, and authentication
- **M2M Clients** — Machine-to-machine client management
- **FHIR** — FHIR R4 resource operations
- **Messaging** — Conversations and SMS messaging

## Why Jentic

- **Setup:** Wiring OystEHR by hand means obtaining a JWT bearer token through its machine-to-machine or user login flow and carrying it on every application-management call. Through Jentic you install once, import the OystEHR API from the API Directory, store the token once, and your agent calls it.
- **Permission scoping:** OystEHR puts the application id in the URL path (/application/{applicationId}), so a rule can pin your agent to one application for the reads and updates you allow. You choose the operations it may call, so destructive ones like deleting an application, rotating its secret, or revoking tokens are not included unless you add them.
- **Credential handling:** Your OystEHR bearer token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'create an application' or 'read an application's settings', and Jentic returns the matching OystEHR operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Stripe** — Alternative payments API
- **Adyen** — Alternative payments API
- **Square** — Complementary payments API
- **Paypal** — Complementary payments API

## FAQ

### What authentication does the OystEHR API use?

The OystEHR API uses a Bearer token in the Authorization header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I create an application with the OystEHR API?

Yes. Use the POST /application endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the OystEHR API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I create an application through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'create an application'. Jentic returns the matching OystEHR API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the OystEHR API have?

The OystEHR API exposes 28 endpoints covering applications, users, m2m clients operations.

### Can I limit what my agent is allowed to do with the OystEHR API?

Yes. Because you self-host Jentic One and write its rules, you decide which OystEHR operations your agent may call, so read and update calls on applications can be permitted while destructive ones like deleting an application, rotating its secret, or revoking access and refresh tokens stay off unless you add them. Since OystEHR carries the application id in the URL path at /application/{applicationId}, a rule can pin your agent to a single application. Your bearer token is stored encrypted by your own instance and injected only at execution time, so the agent never sees the raw secret.
