# DrChrono > DrChrono by EverHealth is an all-in-one EHR, practice management and medical billing platform for > independent US medical practices. It exposes two distinct machine-readable API surfaces: a > proprietary OAuth 2.0 REST API (v4, codename "Hunt Valley", 170 paths / 329 operations) covering > patients, scheduling, clinical documentation, labs, tasks, messaging and the full revenue cycle; > and a read-only, ONC-certified SMART on FHIR R4 server covering 27 US Core resource types for > USCDI interoperability. The two share no tokens, no scopes and no identifier space. Generated by the API Evangelist enrichment pipeline on 2026-08-14 from artifacts fetched from DrChrono's own hosts. DrChrono publishes an llms.txt at https://www.drchrono.com/llms.txt, but it is a Rank Math SEO index of marketing and blog pages with no developer content; it is preserved verbatim alongside this file as drchrono-llms-published.txt. ## REST v4 API - [OpenAPI 3.0.0 (live)](https://app.drchrono.com/openapi-schema): DrChrono's own OpenAPI, 170 paths, 329 operations, 100% operationId coverage, 77 component schemas. - [API reference](https://app.drchrono.com/api-docs/): Redoc reference. Also carries the API terms, rate limits, webhooks, versioning and deprecation policy inline in info.description. - [Tutorial / getting started](https://app.drchrono.com/api-docs/tutorial/): create a free account, register an API application, run the OAuth flow. - [API management console](https://app.drchrono.com/api-management/): client id, client secret, redirect URIs, API version pin, webhook configuration. - [API terms](https://app.drchrono.com/api-terms/): includes the Level 1 / Level 2 endpoint classification and the HIPAA/PHI obligations. - Base URL: `https://app.drchrono.com` - Auth: OAuth 2.0 authorization code. Authorize `https://app.drchrono.com/o/authorize/`, token `https://app.drchrono.com/o/token/`, revoke `https://app.drchrono.com/o/revoke_token`. Access tokens live 48 hours. - Scopes: 22, of the form `BASE:[read|write]` over user, calendar, patients, patients:summary, billing, billing:patient-payment, clinical, labs, messages, tasks, settings. - Rate limits: 500 requests/hour per API application, reset at the top of the hour; 10 requests/second burst throttle; 429 on exhaustion; NO rate-limit response headers. - Pagination: page-based, `page_size` up to 250, absolute `next`/`previous` URLs. `/api/appointments` caps at 20. `verbose=true` lowers the cap to 50. - Idempotency: none. Retrying a POST creates a second object. ## SMART on FHIR R4 API - [CapabilityStatement](https://drchrono-fhirpresentation.everhealthsoftware.com/fhir/drchrono/498711/r4/metadata): FHIR 4.0.1, 27 resource types, read and search-type only. - [SMART configuration](https://drchrono-fhirpresentation.everhealthsoftware.com/fhir/drchrono/498711/r4/.well-known/smart-configuration): 233 scopes, 20 SMART capabilities, PKCE S256. - [OpenID Connect discovery](https://drchrono-fhir.everhealthsoftware.com/core/.well-known/openid-configuration) - [Service base directory](https://drchrono-fhirpresentation.everhealthsoftware.com/fhir/r4/endpoints): public FHIR Bundle of 210 Endpoint/Organization entries covering 105 practices. - [FHIR API documentation](https://drchrono-fhirpresentation.everhealthsoftware.com/drchrono/498711/r4/Home/ApiDocumentation): USCDI mapping, client registration, Bulk Data Export. - Base URL: `https://drchrono-fhirpresentation.everhealthsoftware.com/fhir/drchrono/{practice_id}/r4` - Auth: separate authorization server at `https://drchrono-fhir.everhealthsoftware.com/core`. authorization_code (with PKCE), client_credentials (private_key_jwt, for Bulk Export), refresh_token, implicit, device_code. - Read-only. No create, update or delete on any resource. - Certification: 45 CFR ยง170.315(g)(7), (g)(9), (g)(10). Data limited to USCDI. ## Events - [Webhook reference](https://app.drchrono.com/api-docs/): 27 events across appointments, patients, clinical notes, lab orders, line items, payments, tasks, allergies, problems, medications and vaccines. - Delivery: HTTP POST to a subscriber-registered callback URL. Headers `X-drchrono-event`, `X-drchrono-signature`, `X-drchrono-delivery`. Body `{receiver, object}`. - Retries: 1 hour, 3 hours, 7 hours after the event; manual redelivery after that. Any 2xx is success; 302 is a failure. - Verification: HMAC-SHA256 challenge/response on webhook creation and on any callback-URL change. - No AsyncAPI is published by DrChrono. ## Operations and support - [Status page](https://status.drchrono.com/) โ€” machine-readable at https://status.drchrono.com/api/v2/status.json - [API changelog (v4)](https://app.drchrono.com/api-docs-old/v4/changelog) โ€” newest dated entry 2024-11-01 - [Product changelog](https://headwayapp.co/drchrono-changelog) - [Support portal](https://support.drchrono.com/home/api) - [Bug bounty](https://hackerone.com/drchrono) โ€” public, bounties offered, submissions currently disabled - API support: api@drchrono.com ## Commercial - [Plans and pricing](https://www.drchrono.com/plans-and-pricing/): five quote-based tiers (Essentials, Essentials Plus, Advanced, Advanced Plus, Elite). API access on all tiers. No published per-seat price. - [Partners](https://www.drchrono.com/partners/) - [Blog](https://www.drchrono.com/blog/) ## Known gaps - No first-party SDK in any package registry. Every DrChrono client library on npm, PyPI, RubyGems or Packagist is community-maintained and none has shipped since 2023. `drchrono/php-sdk` on Packagist calls itself official and is not. - No MCP server. Every DrChrono MCP server that exists is third-party. - No A2A agent card on any host. - No security.txt on any host, so there is no machine-readable route to the HackerOne program. - No RFC 8414 or OIDC discovery for the REST v4 authorization server. - No RFC 9457 problem+json, no idempotency keys, no rate-limit headers, no RFC 8594 Sunset headers. - No isolated sandbox. Development runs against production on a free account.