/api path on the same origin as the web app and returns JSON unless otherwise noted.
Base URL
All requests go to the AfterCare web app origin:Authentication
Most endpoints require a valid JWT access token supplied as a Bearer token in theAuthorization header. The exceptions are GET /health, the /auth/* routes, and GET /drive/callback, which are all public.
Content Types
Most requests and all standard responses use JSON. Two endpoints return non-JSON bodies:
Send
Content-Type: application/json for all JSON request bodies. For file uploads, send Content-Type: multipart/form-data.
Rate Limiting
The API enforces per-user request budgets on a rolling one-hour window. Once you are authenticated, limits are tracked against your user ID rather than your IP address. Three separate limit tiers apply:- General API requests — applied to most endpoints
- Upload requests — a stricter budget for
POST /upload - Ask requests — the tightest budget for
POST /ask, which triggers live AI inference
429 Too Many Requests and a JSON body:
RateLimit-* response headers. Check these headers to track your remaining quota and reset time before you hit the ceiling.
Health Check
UseGET /health to verify that the API is reachable and that AI provider configuration is present. This endpoint requires no authentication.
200 response confirms the service is healthy.
Error Format
Standard errors (invalid input, missing resources, authentication failures) follow ordinary HTTP status codes and return a plain JSON body with anerror string and an optional code.
AI pipeline errors from POST /ask and GET /process/{documentId} return a richer structured format:
string
required
Machine-readable error code. One of the values in the table below.
string
required
Human-readable explanation of the error, safe to display to end users.
boolean
required
When
true, the same request may succeed if you try again after a short delay. When false, the request will continue to fail until the underlying issue is resolved (for example, missing provider configuration).AI Error Codes
Explore the API
Authentication
Register, log in, refresh tokens, and sign out.
Upload
Upload discharge paperwork and start AI processing.
Medications
Retrieve medication schedules and record doses taken.
Appointments
List upcoming follow-up appointments and download calendar events.