# LetsGetChecked > LetsGetChecked (operating as LetsGetChecked powered by FuzeHealth) runs an end-to-end virtual care and diagnostics platform: it manufactures at-home sample-collection kits, operates its own accredited laboratories in the United States and Europe, and layers telehealth, clinical review and affiliate-pharmacy prescription delivery on top. Its Halo platform exposes B2B REST APIs — Orders (v1 and v2), Results, and Outreach — plus event-driven webhook notifications, so employers, health plans, providers, public-sector programs and life-sciences partners can order pre-activated test kits, track fulfillment, and retrieve laboratory results in JSON, HL7 or PDF inside their own systems. This file was generated by API Evangelist from public documentation. LetsGetChecked does not publish an llms.txt of its own (https://docs.letsgetchecked.com/llms.txt returns 404, checked 2026-08-04). ## Read this first - The APIs are **partner-gated**. There is no self-service sign-up, no public API host, and no interactive console. Credentials and the API hostname are issued privately during onboarding; all documentation writes the host as the placeholder `{LGC-API}`. - There is **no OpenAPI, AsyncAPI, GraphQL schema, MCP server, or agent card**. Everything below is prose documentation. Do not expect a machine-readable contract. - Every path is scoped by a `clientId` issued by LetsGetChecked: `{LGC-API}/{clientId}/api/{version}/{resource}`. ## Getting started - [Introduction to LetsGetChecked APIs](https://docs.letsgetchecked.com/documentation/API%20Reference/Getting%20Started/api-operations/): REST over HTTPS, single endpoint, several request types. - [Authentication flow](https://docs.letsgetchecked.com/documentation/API%20Reference/Getting%20Started/authentication-flow/): OAuth 2.0 `client_credentials` against `{LGC-API}/oauth2/token`, access key ID + secret access key via HTTP Basic, returns a JWT used as a bearer token. No scopes. - [Integration process](https://docs.letsgetchecked.com/documentation/API%20Reference/Getting%20Started/integration-process/): staging credentials and an IP-restricted staging server first; production access only after LetsGetChecked verifies the integration. - [Error codes](https://docs.letsgetchecked.com/documentation/API%20Reference/errors/): conventional HTTP status classes; a "Problem-Detail payload where appropriate" is claimed but no media type, type URIs or example are published. - [Glossary](https://docs.letsgetchecked.com/documentation/Glossary/terms/): 37 terms spanning API, authentication, HL7/LOINC/NPI standards, CLIA and PHI, and clinical concepts. - [Release notes](https://docs.letsgetchecked.com/documentation/release-notes/release_notes/): dated documentation changes; most recent entry 14 September 2023. ## Orders API Order pre-activated test kits, track them from dispatch to results, and read replacement-kit linkage. `PUT` order creation is **idempotent** — the client names the order with its own `clientOrderId`, so a retry after a broken connection returns the previous result rather than creating a second order. HTTP 409 means the order already exists. Version 1: - [Orders API overview and order statuses](https://docs.letsgetchecked.com/documentation/API%20Reference/Orders%20API/orders/): `Submitted`, `Created`, `KitDispatched`, `KitRegistered`, `KitArrivedAtLab`, `ResultsAvailable`, `Cancelled`, `ValidationFailed`. - [PUT Order](https://docs.letsgetchecked.com/documentation/API%20Reference/Orders%20API/Version%201/orders_create/) — `PUT {clientId}/api/v1/orders/{clientOrderId}` - [GET Order Status](https://docs.letsgetchecked.com/documentation/API%20Reference/Orders%20API/Version%201/orders_findstatus/) — `GET {clientId}/api/v1/orders/{clientOrderId}/status` - [GET Questionnaire](https://docs.letsgetchecked.com/documentation/API%20Reference/Orders%20API/Version%201/q_req/) — `GET {clientId}/api/v1/questionnaires/{testKitCode}?gender={genderName}` - [Replacement orders](https://docs.letsgetchecked.com/documentation/API%20Reference/Orders%20API/Version%201/replacement/) Version 2 (documented 14 September 2023; adds an order-item model and cancellation): - [PUT Order](https://docs.letsgetchecked.com/documentation/API%20Reference/Orders%20API/Version%202/orders_create/) — `PUT {clientId}/api/v2/orders/{clientOrderId}` - [GET Order](https://docs.letsgetchecked.com/documentation/API%20Reference/Orders%20API/Version%202/orders_get/) — `GET {clientId}/api/v2/orders/{clientOrderId}` - [PATCH Order](https://docs.letsgetchecked.com/documentation/API%20Reference/Orders%20API/Version%202/orders_update/) — `PATCH {clientId}/api/v2/orders/{clientOrderId}/orderItem/{orderItemId}`; cancels an order item up to `KitArrivedAtLab`, processed **asynchronously** and confirmed by webhook. - [Replacement orders](https://docs.letsgetchecked.com/documentation/API%20Reference/Orders%20API/Version%202/replacement/) ## Results API Read laboratory results by test-kit barcode (`LGC-0000-0000-0000`) plus an optional alpha code (`AAAAAA`). Results carry per-biomarker detail — name, `Qualitative`/`Quantitative`/`Genetic` kind, descriptor band, reference bounds, headline narrative and LOINC coding — and are available as JSON, HL7 or PDF. - [Results API overview](https://docs.letsgetchecked.com/documentation/API%20Reference/Results%20API/results/) - [GET Results](https://docs.letsgetchecked.com/documentation/API%20Reference/Results%20API/results_req/) — `GET {clientId}/api/v1/results/{barcode}?alphaCode={alphaCode}` - [GET Results Status](https://docs.letsgetchecked.com/documentation/API%20Reference/Results%20API/results_status_req/) — `GET {clientId}/api/v1/results/{barcode}?alphaCode={alphaCode}&fields=status` - [GET Lab Results](https://docs.letsgetchecked.com/documentation/API%20Reference/Results%20API/results_lab_results_req/) — `GET {clientId}/api/v1/labresults/{barcode}?alphaCode={alphaCode}` - [Results narratives](https://docs.letsgetchecked.com/documentation/results-narratives/res-narratives/) ## Outreach API Retrieve and download the results letters generated for patients and for a patient's Primary Care Provider. Listing uses cursor paging: the response carries an `X-Continuation-Token` header, you pass it back as the `continuationToken` query parameter, page size is capped at 25, and a null token means the end of the collection. - [Outreach API overview](https://docs.letsgetchecked.com/documentation/API%20Reference/Outreach%20API/outreach/) - [GET Notifications](https://docs.letsgetchecked.com/documentation/API%20Reference/Outreach%20API/notifications_get/) — `GET {clientId}/api/v1/outreach?programName=&startDate=&endDate=&continuationToken=&type=` - [GET Notification by Barcode](https://docs.letsgetchecked.com/documentation/API%20Reference/Outreach%20API/notifications_barcode_get/) — `GET {clientId}/api/v1/outreach/{barcode}` - [GET Results Letters events](https://docs.letsgetchecked.com/documentation/API%20Reference/Outreach%20API/results_letters_events_get/) — `GET {clientId}/api/v1/letters-feed?programName=&startDate=&startEvent=` - [Download Results Letter](https://docs.letsgetchecked.com/documentation/API%20Reference/Outreach%20API/results_letter_download/) — `GET {clientId}/api/v1/letters/{letterId}` ## Webhook notifications `POST` to a client-supplied endpoint whenever an `order`, `Result` or `outreach` resource changes. Payloads carry a resource identifier, a `callbackURL` back into the REST API, a `type` discriminator and a UTC `timestamp`. - [Webhooks](https://docs.letsgetchecked.com/documentation/API%20Reference/API%20Notifications/webhooks/) - [Event handling](https://docs.letsgetchecked.com/documentation/API%20Reference/API%20Notifications/event_handling/) — delivery is **at-least-once and unordered**; make your processing idempotent and reconcile order against the API. Retry ladder: 3 immediate attempts, then 15 minutes and 3 more, looping 4 times (a 1-hour window). 5xx, 401 and 403 from your endpoint count as failures; 200 acknowledges. - [Security](https://docs.letsgetchecked.com/documentation/API%20Reference/API%20Notifications/security/) — optional `Authorization: LGC2-HMAC-SHA256 ` signature over the stringified body, using a signing key you supply. Signing is opt-in, not default. - [Examples](https://docs.letsgetchecked.com/documentation/API%20Reference/API%20Notifications/examples/) ## Company and policy - [Website](https://www.letsgetchecked.com/) - [Platform](https://www.letsgetchecked.com/our-platform/) and [Data and technology](https://www.letsgetchecked.com/data-and-technology/) - [Trust centre](https://trust.letsgetchecked.com/) — the vendor's own record lists GDPR, HITRUST, NIST and ISO 13485, and publishes a 14-entry subprocessor list. SOC 2 and ISO 27001 are **not** claimed. - [Report a vulnerability](https://www.letsgetchecked.com/security.txt) — `security@letsgetchecked.com`. Note: served from the legacy `/security.txt` path, not `/.well-known/security.txt`, and its `Expires` value (2024-03-01) has passed. - [Help centre](https://help.letsgetchecked.com/s/) · [Contact](https://www.letsgetchecked.com/contact-us/) · [Articles](https://www.letsgetchecked.com/articles/) - [Terms of use](https://www.letsgetchecked.com/terms-of-use/) · [Privacy policy](https://www.letsgetchecked.com/privacy-policy/) - [GitHub organization](https://github.com/LetsGetChecked) — three repositories, none of them a specification or client library. ## API Evangelist artifacts Derived and probed artifacts in this profile: `authentication/`, `conventions/`, `errors/`, `lifecycle/`, `changelog/`, `conformance/`, `vocabulary/`, `sandbox/`, `data-model/`, `asyncapi/` (webhook catalogue), `security/`, `well-known/`. ## Known gaps - No OpenAPI, AsyncAPI, GraphQL, gRPC, MCP server, or A2A agent card. - No published API hostname, for either staging or production. - No client libraries or SDKs on npm, PyPI, NuGet, RubyGems, Maven Central or crates.io. - No CLI, no Postman collection, no interactive console, no published test data. - No status page, SLA, deprecation policy, or rate-limit documentation. - The docs site is a Docusaurus build with `url`/`baseUrl` unset: `sitemap.xml` emits every entry as `http://localhost/...`, so crawlers and agents following it resolve nothing. - No release note has been published since 14 September 2023.