---
updatedAt: 2026-04-21T02:07:24.000Z
agentTools:
  projectIndex: https://developers.halaxy.com/llms.txt
---

# Authentication

This page outlines how to get your API key and generate your access token

## Get your API key

1. Purchase your Halaxy API subscription in the [Add-ons](https://www.halaxy.com/a/pr/profile/addons) page.
2. Open the [Halaxy developer page](https://www.halaxy.com/a/pr/30263631/developer) and create an API Key.
3. Copy your **Client ID** and **Client Secret**.

<Callout icon="🔒" theme="default">
  ### Protect your API keys

  Your API keys grant access to your practice data and must be kept private to prevent unauthorized access and data breaches. Avoid sharing them publicly or with untrusted parties.
</Callout>

<br />

## Authentication

Generate your access token by sending a request with your Client ID and Client Secret.

### Request your token

```shell
curl --location 'https://au-api.halaxy.com/main/oauth/token' \
--header 'Accept: application/fhir+json' \
--header 'Content-Type: application/json' \
--data '{
  "grant_type": "client_credentials",
  "client_id": "<YOUR CLIENT ID>",
  "client_secret": "<YOUR CLIENT SECRET>"
}'
```

### Response

```json
{
"token_type":"Bearer",
"expires_in":3600,
"access_token":"<YOUR ACCESS TOKEN>"
}
```

<Callout icon="🖊️" theme="default">
  ### Note

  Access tokens are valid for 15 minutes.
</Callout>

<br />

## Identify your application

```shell
 -H 'User-Agent: APP_VENDOR_NAME (APP_VENDOR_EMAIL)
```

<br />

## Using your token

This is an example of how to use your access token in a request to generate a patient list.

```shell
curl --location 'https://au-api.halaxy.com/main/Patient' \
--header 'Accept: application/fhir+json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer <YOUR ACCESS TOKEN>'
--header 'User-Agent: APP_VENDOR_NAME (APP_VENDOR_EMAIL)
```

<br />

## Rate limits

All requests authenticated with OAuth are rate-limited to **500 requests per minute**. The API uses a **sliding window** rate limiter. Track your current usage with the rate limit headers returned on each OAuth-authenticated request.

| Header                  | Description                                              |
| :---------------------- | :------------------------------------------------------- |
| `x-ratelimit-limit`     | Total requests available in the current 1-minute window. |
| `x-ratelimit-remaining` | Requests remaining in the current 1-minute window.       |

If you exceed the limit, the API returns **`429 Too Many Requests`**.

The `429` response includes a `retry-after` header that tells you how many seconds to wait before sending another request.

<br />

> 🚧 Use the right server
>
> Depending on your country location, make sure that you are using the proper base URL for your region. Countries in the EU and UK must use `https://eu-api.halaxy.com/main/`, while all other countries must use `https://au-api.halaxy.com/main/`.

<br />