Skip to main content

Receive the patient on-share

Hosted by the HIP/HIU, not by ABDM. ABDM calls this endpoint at the callback URL registered for your bridge, so the path below is relative to that URL.

POST/v3/patient/on-share/open-order

This is a callback API for patient on-share. This API needs to implement by HIU for receive all the open order.

<ol type='1'> <li> <b>Header</b> <ol type='a'> <br/> <li>Authorisation will be provided by the gateway session API after the successful verification of client ID and Secret [ Example: Bearer <TOKEN> ]</li><li>REQUEST-ID unique UUID[ Example: 18235d89-cb13-479d-ad71-7a57d5f669a8 ]</li> <li>TIMESTAMP actual time of the requested was initiated[ Example: 2022-10-06T10:10:00.587Z ]</li><li>X-HIU-ID [Example: HIU_ID] </ol></li><br/><li> <b>Request Body</b> <ol type='a'><br/> <li>intent This is a key value pair which contains the purpose [ Example: type: OPEN_PAYMENT_ORDER ]</li> <li>ABHA Address of the user/patient.</li> <li>error is optional object in case of any error or Failure then only send error object</li> <li>Procedures which contains the list of open order</li><li>response which contains the requestId [ Example: resquestId: 059fcb69-8ad8-4789-a049-62db16c7b5a0 ]</li> </ol> </ol>

Authorizations

Authorizationbearer tokenRequired

Headers

REQUEST-IDstringRequired

Unique UUID for track the end to end request transaction

TIMESTAMPstringRequired

Actual time of the request was initiated, ISO 8601 represents date and time by starting with the year, followed by the month, the day, the hour, the minutes, seconds and milliseconds.

X-HIU-IDstringRequired

Identifier of the health information user to which the request was intended

Body

intentstringRequired

The intention of share API call

abhaAddressstringRequired

The abha address of the patient. Should start with Alphanumeric . and _ in the middle and must be ending with @abdm or @sbx

patientUidstringRequired
proceduresobject[]Required
procedures.categorystringRequired

The category of the procedure

procedures.servicesobject[]Required
procedures.services.serviceIdstring

Unique identifier for the service

procedures.services.namestringRequired

Name of the service

procedures.services.descriptionstring

Description of the service

procedures.services.amountnumberRequired

Amount for the service

responseobject

This is the response request-id which is generated from the share API

response.requestIdstringRequired

Responses

200

OK

400

Bad Request. The request could not be processed because it was malformed or failed validation - a missing mandatory field, a value in the wrong format, or a header that did not match the body.

Error codes for this module

401

Unauthorized. The request carried no valid credentials, or the access token has expired. Obtain a fresh token from the session API and retry.

Everything returns 401

403

Forbidden. The caller is authenticated but is not permitted to perform this operation on this resource.

Error codes for this module

500

Internal Server Error

Error codes for this module

503

Service Unavailable

Error codes for this module

Where this fits

hiecm-scan-and-pay.yaml declares this callback at module level and names no call against it. Which call produces it is not documented, so this page does not say.