xCures Public API
REST API for the xCures Clinical Clarity Engine. Register patients (Subjects), dispatch and poll queries against Carequality/TEFCA health information networks, retrieve and publish clinical documents (including reciprocity back to the network), read normalized FHIR R4 resources and a FHIR bulk export, search fifteen Clinical Concepts domains (conditions, medications, labs, biomarkers, imaging, procedures, allergies, vitals, encounters, demographics, coverage, family history, social history, surveys, radiation), evaluate AI Checklists, and fetch AI-generated subject summaries. OAuth 2.0 client-credentials bearer auth with a required ProjectId header on nearly every operation.
This API exposes 69 operations across 63 paths, organized into 11 resource areas, and defines 64 schemas. It is described by OpenAPI 3.0.0, at version V1.
Requests are made against a single base URL, https://partner.xcures.com.
Metadata
The identity and technical contract details declared by the specification.
Authentication & Security 1
xCures Public API declares
1 security scheme
for authenticating requests.
It accepts HTTP bearer tokens (JWT) (bearer).
Paths & Operations 69
Across 63 paths, the API surfaces 69 operations — 1 DELETE, 56 GET, 9 POST, 3 PUT. They span 11 resource areas, including OAuth, Application, Subject, Query, Summary, FHIR, Document, Reciprocity Template, and 3 more. Each is listed below with its method, path, parameters, and response codes.
All API requests to xCures must provide an access token, retrieved via the standard OAuth authorization flow below.
Account creation (e.g., identity proofing, eConsent) that is required for a patient to progress on the xCures Platform.
An individual patient created on the xCures Platform.
A specified, approved request for patient records across the network (e.g., via Carequality/TEFCA to support treatment activities, via TEFCA for IAS queries) with an associated st…
The AI-generated summary of a patient’s overall records and condition(s).
Fast Healthcare Interoperability Resource is an international data model specification developed by HL7 International to enable healthcare data exchange and interoperability betwe…
Patient records retrieved by the xCures platform and/or loaded by platform users.
Reciprocity or "Responder" workflows refer to the process of sharing clinical documentation housed within your system with other organizations/providers, when participating in hea…
AI-powered feature leveraging xCures’ targeted data extraction/processing to populate validated, customizable question/answer-style items. Responses can be highly flexible and eve…
Clinical concepts is a proprietary xCures higher-level, flattened, filtered, opinionated view of medical record information, structured around FHIR guidelines.
A configured workspace on the xCures Platform. Use this endpoint to discover the projectId value(s) required by other API calls, without needing to log into the portal.
Schemas 64
The contract defines 64 schemas that model the data the API accepts and returns. The most detailed are CreateSubjectResult (25 properties), Subject (24 properties), Application (22 properties), CreateApplicationResponse (21 properties). Each schema is shown below with its type and property counts.
Specification
The full machine-readable OpenAPI contract behind this narrative.
Source
This is an independent, third-party profile of xCures Public API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.