# Build with Anpheros

> The path from access to production in nine steps — authentication, API, medical data, consent, FHIR, webhooks, SDKs and going live — with the guide for each step.

Source: https://developers.anpheros.com/guides/build-with-anpheros

**Building on Anpheros means using it as the medical-data layer of your application: your product calls the Anpheros API to store and read patient records in HL7 FHIR R4, to obtain patient consent and to receive events.** This page is the map from first access to production; each step links to the guide that covers it in detail.

## 1. Get access

Anpheros Platform is in private beta. The sandbox is self-service: sign in with Google on the dashboard (`https://platform.anpheros.com/dashboard/`) and press *Get a sandbox key* — you get an organisation, a sandbox project with its own 30 synthetic patients, and a key. Production access is by request (`contact@anpheros.com`). You create further projects and API keys in the dashboard or through the Admin API; OAuth applications are registered with `POST /admin/projects/{id}/applications` and webhooks with `POST /v1/webhooks`.

A **project** is the unit of isolation: its keys see only the patients it created (and, with consent, those who granted it access).

## 2. Authenticate

| Credential | For | Looks like |
|---|---|---|
| API key | your servers | `sk_test_…` (sandbox), `sk_live_…` (production) |
| OAuth access token | an app acting for one patient | `at_…`, valid 30 minutes, refreshed with a rotating refresh token |

Send it as `Authorization: Bearer <credential>`. Keys are shown once and never belong in a mobile or web app. → [Authentication and OAuth](https://developers.anpheros.com/guides/authentication)

## 3. Connect to the API

Base URL `https://platform.anpheros.com`; REST at `/v1`, FHIR R4 at `/fhir/R4`. The interactive reference and the OpenAPI specification describe every endpoint.

```bash
curl https://platform.anpheros.com/v1/patients -H "Authorization: Bearer $KEY"
```

→ [API reference](https://developers.anpheros.com/docs) · [Healthcare API](https://developers.anpheros.com/guides/healthcare-api)

## 4. Create and read medical data

Create a patient for each of your users, write observations, conditions, medications and documents with an `Idempotency-Key`, and read them back as lists or a timeline. State the author of every write (`patient`, `practitioner`, `device`, `import`, `ai`).

→ [Getting started](https://developers.anpheros.com/guides/getting-started) · [Medical data API](https://developers.anpheros.com/guides/medical-data-api) · [Build a healthcare app](https://developers.anpheros.com/guides/build-a-healthcare-app)

## 5. Add consent

To reach a record a person already keeps in Anpheros, register an OAuth application with its redirect URI, send the person to the consent page with the scopes you need, and exchange the code (PKCE) for tokens. The person chooses the duration and can revoke access at any time; every read is visible to them.

→ [Consent and access model](https://developers.anpheros.com/guides/consent) · [Authentication and OAuth](https://developers.anpheros.com/guides/authentication)

## 6. Use FHIR where you need the full model

Resource types beyond the REST API — immunizations, procedures, care plans, allergies, encounters and others, 26 in all — are available through FHIR R4, together with search, history, transactions, `$everything` and the International Patient Summary (`$summary`).

→ [FHIR platform](https://developers.anpheros.com/guides/fhir) · [FHIR code systems](https://developers.anpheros.com/guides/fhir-code-systems) · [Healthcare data interoperability](https://developers.anpheros.com/guides/interoperability)

## 7. React to events

Register a webhook endpoint for `resource.*`, `consent.*` or `document.finalized` events and verify the `Anpheros-Signature` of every delivery. Laboratory reports can be sent in one call to the lab connector.

→ [Webhooks](https://developers.anpheros.com/guides/webhooks) · [Lab connector](https://developers.anpheros.com/guides/lab-connector) · [Healthcare integrations](https://developers.anpheros.com/guides/healthcare-integrations)

## 8. Use an SDK

`@anpheros/sdk` (TypeScript: Node 18+, browsers, Deno, Bun) and `anpheros_sdk` (Dart / Flutter) cover the whole public API with the same shape, add idempotency keys to creates, retry on `429`/`5xx`, refresh tokens and implement the consent flow.

```bash
npm install @anpheros/sdk        # or: dart pub add anpheros_sdk
```

→ [SDKs](https://developers.anpheros.com/guides/sdks)

## 9. Go to production

- Production keys (`sk_live_`) are issued to verified organisations with a signed data processing agreement.
- Plan for the limits of the private beta: single zone, no contractual SLA, 600 requests per minute per key and per IP.
- Handle errors by type and keep `Anpheros-Request-Id` for support.
- Review how data is protected and where it is stored.

→ [Security, privacy and data residency](https://developers.anpheros.com/guides/security) · [Limits](https://developers.anpheros.com/guides/limits) · [Errors](https://developers.anpheros.com/guides/errors) · [Versioning and deprecation](https://developers.anpheros.com/guides/versioning)

## Adding AI

If your product includes an AI assistant or agent, the context API prepares the relevant part of a record for the model you use, within a token budget and with every item labelled by source. → [AI healthcare applications](https://developers.anpheros.com/guides/ai-healthcare)

## Related

- [Anpheros for developers](https://developers.anpheros.com/guides/developers)
- [Healthcare software development](https://developers.anpheros.com/guides/healthcare-software)
- [Healthcare startups](https://developers.anpheros.com/guides/healthcare-startups)
