Create an authorization

post/v1/authorizations

Creates an authorization and returns it. Send an Idempotency-Key header to make the request safe to retry. Available to keys belonging to office staff. Requires a key with write scope.

Authorization

Authorization: Bearer ak_...requiredscope: read + write

An AveeCare API key created in Settings → API Keys. This endpoint changes data, so the key needs read + write scope. About authentication

Headers

Idempotency-Key
stringmax length 255

A unique value (a UUID works well) that makes this request safe to retry for 24 hours. A retry with the same key and body returns the first result; the same key with a different body is refused with idempotency_conflict.

Request body

application/json
patientId
stringrequiredmax length 64

The patient the authorization covers.

payerName
string | nullmax length 200

The payer that issued it.

authorizationNumber
string | nullmax length 100

The payer's authorization number.

serviceType
string | nullmax length 100

Service authorized.

procedureCode
string | nullmax length 20

Procedure (HCPCS) code billed against it.

modifiers
string | nullmax length 50

Procedure code modifiers, comma separated.

startDate
string · date | null

First date the authorization covers.

endDate
string · date | null

Last date the authorization covers.

authorizedUnits
integer | nullmin 0

Units approved.

unitType
string | nullmax length 50

What a unit is, in the payer's words.

unitBasis
string | null

Whether units count time, visits or days.

One ofTimeVisitsDaysnull
minutesPerUnit
integer | nullmin 1

For time-based units, minutes in one unit.

frequency
string | nullmax length 100

Frequency the payer approved.

placeOfService
string | nullmax length 10

Place-of-service code.

status
string | null

Whether the authorization is in effect.

One ofActiveExpiredPendingRenewalnull
notes
string | nullmax length 20000

Notes.

Response

201

The new authorization.

object
stringread-only

String representing the object's type. Always authorization.

id
stringread-only

Unique identifier of the authorization.

patientId
string | nullmax length 64

The patient the authorization covers.

payerName
string | nullmax length 200

The payer that issued it.

authorizationNumber
string | nullmax length 100

The payer's authorization number.

serviceType
string | nullmax length 100

Service authorized.

procedureCode
string | nullmax length 20

Procedure (HCPCS) code billed against it.

modifiers
string | nullmax length 50

Procedure code modifiers, comma separated.

startDate
string · date | null

First date the authorization covers.

endDate
string · date | null

Last date the authorization covers.

authorizedUnits
integer | nullmin 0

Units approved.

unitType
string | nullmax length 50

What a unit is, in the payer's words.

unitBasis
string | null

Whether units count time, visits or days.

One ofTimeVisitsDaysnull
minutesPerUnit
integer | nullmin 1

For time-based units, minutes in one unit.

usedUnits
integer | nullread-only

Units used so far.

remainingUnits
integer | nullread-only

Units left.

frequency
string | nullmax length 100

Frequency the payer approved.

placeOfService
string | nullmax length 10

Place-of-service code.

status
string | null

Whether the authorization is in effect.

One ofActiveExpiredPendingRenewalnull
notes
string | nullmax length 20000

Notes.

createdAt
string · date-time | nullread-only

When the authorization was created.

updatedAt
string · date-time | nullread-only

When the authorization was last changed.

Response headers

Request-IdstringUnique ID of this request. Quote it when contacting support.
RateLimit-LimitintegerRequests allowed in the current window.
RateLimit-RemainingintegerRequests left in the current window.
RateLimit-ResetintegerSeconds until the window resets.
Idempotent-ReplayedstringPresent and true when this response is the stored result of an earlier request with the same Idempotency-Key.

Errors

StatusCodeMeaning
400
n/a
The request was malformed, a value was invalid, or it contained an unknown field (invalid_request, unknown_field).
401
n/a
The API key is missing, malformed, expired or revoked (unauthorized).
403
n/a
The key is read-only (insufficient_scope), or its user's role cannot do this (forbidden).
409
n/a
The Idempotency-Key was already used with a different request, or that request is still running (idempotency_conflict).
429
n/a
Too many requests (rate_limited). Wait for Retry-After seconds.
500
n/a
Something went wrong on our side (internal_error). Retry, and quote the request ID if it persists.

Every error uses the same body. See Errors for the full list of codes.