Skip to main content

hip linking

Generate Link Token

Generates a short-lived link token for a specific patient identified by their ABHA number/address. The link token is passed as X-Link-Token header when calling the care context linking API. Must be called immediately before the linking call, tokens expire quickly.

ConditionalMandatory for the Government Integartors / Private Integrators

Certification cases HIP_INTI_LINK_501, HIP_INTI_LINK_502, HIP_INTI_LINK_503, HIP_INTI_LINK_504, HIP_INTI_LINK_505, HIP_INTI_LINK_506

POST/hiecm/v3/token/generate-token

This call is accepted with 202 and carries no token. The token itself arrives on the m2_on_generate_token_result callback, at the callback URL registered for your bridge.

Authorizations

Authorizationbearer tokenRequired

Bearer token obtained from POST /hiecm/gateway/v3/sessions

Headers

REQUEST-IDstringRequired

A fresh UUID that you generate for this request. The callback that answers it carries the same value, so this is how you match an asynchronous reply to the call that caused it. Store it before you send the request, not after.

TIMESTAMPstringRequired

The current time in ISO 8601, UTC, with milliseconds and a Z suffix, from a synchronised clock. The sandbox rejects IST and accepts UTC.

X-CM-IDstringRequired

Which consent manager you are talking to. sbx on the sandbox and abdm in production. A dedicated error code exists for an invalid value here, which tells you how often it is wrong.

X-HIP-IDstringRequired

Identifier of the Health Information Provider the request or callback belongs to. This is per facility, and it is what a callback arriving at your one bridge URL is routed on. The bridge URL and your credentials belong to the integration, not to the facility.

Body

abhaNumberinteger

14-digit ABHA number (optional if abhaAddress provided)

abhaAddressstringRequired

ABHA address (PHR address) e.g. user@sbx

namestringRequired
genderstringRequired

One of MFO

yearOfBirthintegerRequired

Responses

202

Accepted. No body. The token arrives on the m2_on_generate_token_result callback.

The callback never arrives

400

Bad request, invalid parameters or missing fields

Error codes for this module

401

Unauthorized, missing or invalid Bearer token

Everything returns 401

403

Forbidden. Returned as plain text ("Access Denied"), not JSON.

Error codes for this module

404

Resource not found

Error codes for this module

500

Internal server error.

Error codes for this module

503

Service unavailable. Returned by the link token generation operation.

Error codes for this module

Callbacks

  • After this call, ABDM posts The link token m2_generate_link_token generated, or why it failed to /v3/hip/token/on-generate-token. Open the callback.