Medplum website screenshot

Medplum

Medplum is an Apache 2.0 open-source, FHIR-native developer platform for shipping clinical software. It bundles a FHIR R4 datastore, REST and GraphQL APIs, a TypeScript SDK, React component library, OAuth 2.0 / SMART on FHIR authentication, declarative Access Policies, Subscriptions, and TypeScript-based serverless Bots — sold as a hosted service at api.medplum.com and as a self-hostable monorepo on GitHub. Medplum is HIPAA, SOC 2 Type II, and ONC-certified.

Medplum publishes 1 API on the APIs.io network: Fhir API. Tagged areas include Healthcare, FHIR, Open Source, Developer Platform, and HIPAA.

The Medplum catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Medplum’s developer surface includes authentication, documentation, getting-started guide, API reference, CLI, developer console, pricing, and 33 more developer resources.

65.9/100 strong ▼ -7.8 Agent 41/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
4 APIs 1 MCP Servers 9 Features 7 Use Cases
HealthcareFHIROpen SourceDeveloper PlatformHIPAASMART on FHIRClinicalInteroperability

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 65.9/100 · strong
Contract Quality 17.4 / 25
Developer Ergonomics 17.0 / 20
Commercial Clarity 15.8 / 20
Operational Transparency 4.8 / 13
Governance 8.3 / 12
Discoverability 6.5 / 10
Agent readiness — 41/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/medplum: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 4

Individual APIs this provider publishes, each with its own machine-readable definition.

Medplum GraphQL API

FHIR-aware GraphQL endpoint at https://api.medplum.com/fhir/R4/$graphql. Supports typed nested queries, reverse-reference traversal (_reference), FHIRPath-style array filtering,...

Medplum Bots

Bots are TypeScript serverless functions (AWS Lambda-style) executed in response to FHIR Subscriptions, HTTP triggers, or scheduled cron. Bots are the backbone of Medplum integr...

Medplum Subscriptions

FHIR Subscription resources that match a search criteria and dispatch real-time notifications via REST hooks (webhooks) or Websockets when matching resources are created or upda...

Medplum Fhir API

The Fhir API from Medplum — 4 operation(s) for fhir.

Postman Collections 1

Ready-to-run Postman collections for exercising this provider's APIs.

Arazzo Workflows 11

Multi-step API workflows described with the Arazzo specification.

Medplum Amend Resource With History

Read a resource, update it, then inspect its version history and prior version.

ARAZZO

Medplum Clinical Data Query

Locate a patient by name, read the Patient resource, then pull that patient's Observations.

ARAZZO

Medplum Create Diagnostic Report

Create an Observation result, then assemble a DiagnosticReport that references it.

ARAZZO

Medplum Deploy Bot

Create a Bot resource, then create a Subscription that invokes the Bot on resource changes.

ARAZZO

Medplum FHIR Resource CRUD

Create a FHIR R4 resource, read it back by id, update it, then search the resource type for it.

ARAZZO

Medplum Finalize Observation

Find a preliminary Observation, patch its status to final, and read it back to confirm.

ARAZZO

Medplum Find And Delete Resource

Search a resource type, and if a match is found read it for audit then delete it.

ARAZZO

Medplum Register Patient With Observation

Create a Patient, then record a vital-sign Observation that references that patient.

ARAZZO

Medplum FHIR Resource Versioning

Create a FHIR resource, update it to mint a new version, read its history, then read a specific version.

ARAZZO

Medplum Schedule Encounter

Create a Practitioner, create an Encounter linking the patient and practitioner, then read it back.

ARAZZO

Medplum Upsert Patient

Search for a Patient by identifier and update it if found, otherwise create it.

ARAZZO

Scroll for all 11

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

medplum-mcp.yml

MCP SERVER

GraphQL 1

GraphQL schemas published by this provider.

Medplum GraphQL API

FHIR-aware GraphQL endpoint at https://api.medplum.com/fhir/R4/$graphql. Supports typed nested queries, reverse-reference traversal (_reference), FHIRPath-style array filtering,...

GRAPHQL

Pricing Plans 1

Published pricing tiers and plan structures.

Medplum Plans Pricing

6 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Medplum Rate Limits

4 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 9

Notable capabilities this provider offers.

FHIR-Native Datastore

PostgreSQL-backed datastore that natively models FHIR R4 resources, including search, history, and versioning.

REST + GraphQL APIs

Dual API surface — FHIR REST and FHIR-aware GraphQL — sharing the same authorization, schema, and access policies.

Bots (Serverless TypeScript Functions)

AWS Lambda-style TypeScript functions executed by Subscriptions, HTTP, or cron triggers; the integration backbone of Medplum.

Subscriptions (Webhooks + Websockets)

FHIR Subscription resources dispatch real-time notifications when matching resources change.

Access Policies

Declarative resource- and field-level authorization rules attached to ProjectMembership.

SMART on FHIR + OAuth 2.0

Standards-based authentication and authorization, supporting SMART App Launch 2.0.0 and Bulk Data 2.0.0.

TypeScript SDK and React Components

@medplum/core, @medplum/react, and @medplum/react-hooks provide typed client and reusable UI primitives.

On-Premise Agent

Bridges local clinical systems (HL7v2, DICOM, MLLP) to Medplum cloud.

AWS CDK Deployment

First-class CDK constructs for self-hosting Medplum on AWS.

Scroll for all 9

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Medplum Context

18 classes · 2 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Medplum API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Medplum API Rules

5 rules · 4 warnings 1 info

SPECTRAL

JSON Schema 9

Standalone JSON Schema definitions for this provider's data models.

Bot

28 properties

JSON SCHEMA

Condition

34 properties

JSON SCHEMA

Encounter

32 properties

JSON SCHEMA

MedicationRequest

43 properties

JSON SCHEMA

Observation

46 properties

JSON SCHEMA

Organization

19 properties

JSON SCHEMA

Patient

27 properties

JSON SCHEMA

Practitioner

19 properties

JSON SCHEMA

Subscription

16 properties

JSON SCHEMA

Scroll for all 9

JSON Structure 1

JSON Structure definitions describing this provider's data shapes.

Medplum Patient Structure

8 properties

JSON STRUCTURE

Examples 5

Example request and response payloads for these APIs.

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Medplum Authentication

http/openIdConnect · 3 schemes

SECURITY

Medplum Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Medplum Vulnerability Disclosure

disclosure policy published

SECURITY

Medplum Trust Center

SOC 2, HIPAA, GDPR, CSA STAR

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Medplum Agentic Access

8 operations · 4 acting

8 operations · 4 acting

AGENTIC

Use Cases 7

What developers build with this provider.

Custom EHR Development

Build custom electronic health records on top of FHIR-native storage and React UI components.

Patient Engagement Portals

Ship patient-facing portals using SMART on FHIR auth and the Medplum React component library.

AI Scribe and Clinical Documentation

Capture clinical notes, run them through LLM pipelines via Bots, and persist structured FHIR resources.

HL7v2 to FHIR Integration

Receive legacy HL7v2 ADT, ORU, and SIU messages via the on-premise Agent and convert them to FHIR with Bots.

Population Health and Analytics

Use Bulk Data 2.0 exports and GraphQL aggregations for cohort and population-level analysis.

Care Management Workflows

Model longitudinal care plans, tasks, and questionnaires with FHIR-native resources.

Revenue Cycle Automation

Automate claim, coverage, and explanation-of-benefit workflows with Bots and Subscriptions.

Scroll for all 7

Integrations 8

Pre-built integrations with other platforms and tools.

AWS

First-class deployment on AWS via CDK, with Bots running on Lambda and storage on RDS PostgreSQL.

HL7v2

Bidirectional HL7v2 messaging via the Medplum on-premise Agent.

FHIRcast

Real-time clinical-context synchronization protocol support.

Stripe

Billing and payment integration examples for revenue cycle.

Twilio

SMS, voice, and messaging integration patterns via Bots.

DocuSeal / DocuSign

Patient consent and document-signing integration examples.

SendGrid / Mailgun

Transactional email integration patterns via Bots.

AWS HealthLake

Cross-platform FHIR data exchange examples.

Scroll for all 8

Solutions 6

Packaged solutions this provider offers.

Custom EHR

Build production EHR systems on top of Medplum.

Patient Portal

Reference patient-facing portal application.

Provider Portal

Reference provider-facing clinical application.

AI-Powered Clinical Scribe

Solution pattern for LLM-driven clinical documentation pipelines.

Population Health Platform

Solution pattern for cohort identification and outcome tracking.

Revenue Cycle Management

Solution pattern for automating claims, coverage, and billing workflows.

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 12

Pagination, idempotency, versioning, errors, and events

Scroll for all 12

Build 7

SDKs, sample code, and the tooling you integrate with

Scroll for all 7

Access & Security 5

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 6

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: medplum
name: Medplum
description: Medplum is an Apache 2.0 open-source, FHIR-native developer platform for shipping clinical software. It bundles
  a FHIR R4 datastore, REST and GraphQL APIs, a TypeScript SDK, React component library, OAuth 2.0 / SMART on FHIR authentication,
  declarative Access Policies, Subscriptions, and TypeScript-based serverless Bots — sold as a hosted service at api.medplum.com
  and as a self-hostable monorepo on GitHub. Medplum is HIPAA, SOC 2 Type II, and ONC-certified.
type: Index
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/medplum.png
tags:
- Healthcare
- FHIR
- Open Source
- Developer Platform
- HIPAA
- SMART on FHIR
- Clinical
- Interoperability
url: https://raw.githubusercontent.com/api-evangelist/medplum/refs/heads/main/apis.yml
created: '2026-05-25'
modified: '2026-07-27'
specificationVersion: '0.19'
apis:
- aid: medplum:medplum-graphql-api
  name: Medplum GraphQL API
  description: FHIR-aware GraphQL endpoint at https://api.medplum.com/fhir/R4/$graphql. Supports typed nested queries, reverse-reference
    traversal (_reference), FHIRPath-style array filtering, and access-policy enforcement at the field level.
  humanURL: https://www.medplum.com/docs/graphql
  baseURL: https://api.medplum.com/fhir/R4/$graphql
  tags:
  - GraphQL
  - FHIR
  - Healthcare
  properties:
  - type: Documentation
    url: https://www.medplum.com/docs/graphql
  - type: Examples
    url: examples/medplum-graphql-patient-query-example.json
  - url: graphql/medplum-graphql.md
    type: GraphQL
- aid: medplum:medplum-bots
  name: Medplum Bots
  description: Bots are TypeScript serverless functions (AWS Lambda-style) executed in response to FHIR Subscriptions, HTTP
    triggers, or scheduled cron. Bots are the backbone of Medplum integrations — HL7v2 to FHIR conversion, document generation,
    webhook fan-out, and questionnaire-driven workflow automation.
  humanURL: https://www.medplum.com/docs/bots
  tags:
  - Bots
  - Automation
  - Serverless
  - Integration
  properties:
  - type: Documentation
    url: https://www.medplum.com/docs/bots
  - type: JSONSchema
    url: json-schema/medplum-bot-schema.json
  - type: Examples
    url: examples/medplum-bot-hl7-to-fhir-example.json
- aid: medplum:medplum-subscriptions
  name: Medplum Subscriptions
  description: FHIR Subscription resources that match a search criteria and dispatch real-time notifications via REST hooks
    (webhooks) or Websockets when matching resources are created or updated. Subscriptions are the primary trigger for Bots
    and external system integrations.
  humanURL: https://www.medplum.com/docs/subscriptions
  tags:
  - Subscriptions
  - Webhooks
  - FHIR
  - Events
  properties:
  - type: Documentation
    url: https://www.medplum.com/docs/subscriptions
  - type: Examples
    url: examples/medplum-subscription-webhook-example.json
- aid: medplum:medplum-fhir-api
  name: Medplum Fhir API
  description: The Fhir API from Medplum — 4 operation(s) for fhir.
  humanURL: https://www.medplum.com/docs/api
  baseURL: https://api.medplum.com/fhir/R4
  tags:
  - Fhir
  properties:
  - type: OpenAPI
    url: openapi/medplum-fhir-api-openapi.yml
  - type: Documentation
    url: https://www.medplum.com/docs/api
  - type: APIReference
    url: https://www.medplum.com/docs/api
  - type: Authentication
    url: https://www.medplum.com/docs/auth
  - type: RateLimits
    url: https://www.medplum.com/docs/rate-limits
  - type: MCPServer
    url: mcp/medplum-mcp.yml
  - type: Documentation
    url: https://www.medplum.com/docs/ai/mcp
  - type: JSONSchema
    url: json-schema/medplum-patient-schema.json
  - type: JSONSchema
    url: json-schema/medplum-observation-schema.json
  - type: JSONSchema
    url: json-schema/medplum-encounter-schema.json
  - type: JSONSchema
    url: json-schema/medplum-practitioner-schema.json
  - type: JSONSchema
    url: json-schema/medplum-organization-schema.json
  - type: JSONSchema
    url: json-schema/medplum-condition-schema.json
  - type: JSONSchema
    url: json-schema/medplum-medicationrequest-schema.json
  - type: JSONSchema
    url: json-schema/medplum-subscription-schema.json
  - type: JSONStructure
    url: json-structure/medplum-patient-structure.json
  - type: Examples
    url: examples/medplum-patient-create-example.json
  - type: Examples
    url: examples/medplum-observation-bloodpressure-example.json
  - type: Examples
    url: examples/medplum-subscription-webhook-example.json
common:
- type: MCPServer
  url: mcp/medplum-mcp.yml
- type: AgenticAccess
  url: agentic-access/medplum-agentic-access.yml
- type: TrustCenter
  url: security/medplum-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/medplum-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/medplum-domain-security.yml
- type: Authentication
  url: authentication/medplum-authentication.yml
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/medplum/overview
- type: Arazzo
  url: arazzo/medplum-amend-resource-with-history-workflow.yml
  name: Medplum Amend Resource With History
- type: Arazzo
  url: arazzo/medplum-create-diagnostic-report-workflow.yml
  name: Medplum Create Diagnostic Report
- type: Arazzo
  url: arazzo/medplum-deploy-and-run-bot-workflow.yml
  name: Medplum Deploy Bot
- type: Arazzo
  url: arazzo/medplum-finalize-observation-workflow.yml
  name: Medplum Finalize Observation
- type: Arazzo
  url: arazzo/medplum-find-and-delete-resource-workflow.yml
  name: Medplum Find And Delete Resource
- type: Arazzo
  url: arazzo/medplum-register-patient-with-observation-workflow.yml
  name: Medplum Register Patient With Observation
- type: Arazzo
  url: arazzo/medplum-schedule-encounter-workflow.yml
  name: Medplum Schedule Encounter
- type: Arazzo
  url: arazzo/medplum-upsert-patient-workflow.yml
  name: Medplum Upsert Patient
- type: Website
  url: https://www.medplum.com
- type: Documentation
  url: https://www.medplum.com/docs
- type: GettingStarted
  url: https://www.medplum.com/docs/tutorials
- type: APIReference
  url: https://www.medplum.com/docs/api
- type: Authentication
  url: https://www.medplum.com/docs/auth
- type: SDKs
  url: https://www.medplum.com/docs/sdk/core
- type: SDKs
  url: https://www.npmjs.com/package/@medplum/core
- type: SDKs
  url: https://www.npmjs.com/package/@medplum/react
- type: CLI
  url: https://www.medplum.com/docs/cli
- type: Console
  url: https://app.medplum.com
- type: Pricing
  url: https://www.medplum.com/pricing
- type: TermsOfService
  url: https://www.medplum.com/terms
- type: PrivacyPolicy
  url: https://www.medplum.com/privacy
- type: Blog
  url: https://www.medplum.com/blog
- type: GitHubOrganization
  url: https://github.com/medplum
- type: GitHubRepository
  url: https://github.com/medplum/medplum
- type: Support
  url: mailto:support@medplum.com
- type: Discord
  url: https://discord.gg/medplum
- type: License
  url: https://www.apache.org/licenses/LICENSE-2.0
- type: SpectralRules
  url: rules/medplum-rules.yml
- type: Vocabulary
  url: vocabulary/medplum-vocabulary.yml
- type: JSONLD
  url: json-ld/medplum-context.jsonld
- type: Plans
  url: plans/medplum-plans-pricing.yml
- type: RateLimits
  url: rate-limits/medplum-rate-limits.yml
- type: FinOps
  url: finops/medplum-finops.yml
- type: Features
  data:
  - name: FHIR-Native Datastore
    description: PostgreSQL-backed datastore that natively models FHIR R4 resources, including search, history, and versioning.
  - name: REST + GraphQL APIs
    description: Dual API surface — FHIR REST and FHIR-aware GraphQL — sharing the same authorization, schema, and access
      policies.
  - name: Bots (Serverless TypeScript Functions)
    description: AWS Lambda-style TypeScript functions executed by Subscriptions, HTTP, or cron triggers; the integration
      backbone of Medplum.
  - name: Subscriptions (Webhooks + Websockets)
    description: FHIR Subscription resources dispatch real-time notifications when matching resources change.
  - name: Access Policies
    description: Declarative resource- and field-level authorization rules attached to ProjectMembership.
  - name: SMART on FHIR + OAuth 2.0
    description: Standards-based authentication and authorization, supporting SMART App Launch 2.0.0 and Bulk Data 2.0.0.
  - name: TypeScript SDK and React Components
    description: '@medplum/core, @medplum/react, and @medplum/react-hooks provide typed client and reusable UI primitives.'
  - name: On-Premise Agent
    description: Bridges local clinical systems (HL7v2, DICOM, MLLP) to Medplum cloud.
  - name: AWS CDK Deployment
    description: First-class CDK constructs for self-hosting Medplum on AWS.
- type: UseCases
  data:
  - name: Custom EHR Development
    description: Build custom electronic health records on top of FHIR-native storage and React UI components.
  - name: Patient Engagement Portals
    description: Ship patient-facing portals using SMART on FHIR auth and the Medplum React component library.
  - name: AI Scribe and Clinical Documentation
    description: Capture clinical notes, run them through LLM pipelines via Bots, and persist structured FHIR resources.
  - name: HL7v2 to FHIR Integration
    description: Receive legacy HL7v2 ADT, ORU, and SIU messages via the on-premise Agent and convert them to FHIR with Bots.
  - name: Population Health and Analytics
    description: Use Bulk Data 2.0 exports and GraphQL aggregations for cohort and population-level analysis.
  - name: Care Management Workflows
    description: Model longitudinal care plans, tasks, and questionnaires with FHIR-native resources.
  - name: Revenue Cycle Automation
    description: Automate claim, coverage, and explanation-of-benefit workflows with Bots and Subscriptions.
- type: Integrations
  data:
  - name: AWS
    description: First-class deployment on AWS via CDK, with Bots running on Lambda and storage on RDS PostgreSQL.
  - name: HL7v2
    description: Bidirectional HL7v2 messaging via the Medplum on-premise Agent.
  - name: FHIRcast
    description: Real-time clinical-context synchronization protocol support.
  - name: Stripe
    description: Billing and payment integration examples for revenue cycle.
  - name: Twilio
    description: SMS, voice, and messaging integration patterns via Bots.
  - name: DocuSeal / DocuSign
    description: Patient consent and document-signing integration examples.
  - name: SendGrid / Mailgun
    description: Transactional email integration patterns via Bots.
  - name: AWS HealthLake
    description: Cross-platform FHIR data exchange examples.
- type: Solutions
  data:
  - name: Custom EHR
    description: Build production EHR systems on top of Medplum.
  - name: Patient Portal
    description: Reference patient-facing portal application.
  - name: Provider Portal
    description: Reference provider-facing clinical application.
  - name: AI-Powered Clinical Scribe
    description: Solution pattern for LLM-driven clinical documentation pipelines.
  - name: Population Health Platform
    description: Solution pattern for cohort identification and outcome tracking.
  - name: Revenue Cycle Management
    description: Solution pattern for automating claims, coverage, and billing workflows.
- type: ArazzoWorkflows
  workflows:
  - url: arazzo/medplum-amend-resource-with-history-workflow.yml
    name: Medplum Amend Resource With History
    summary: Read a resource, update it, then inspect its version history and prior version.
  - url: arazzo/medplum-clinical-data-query-workflow.yml
    name: Medplum Clinical Data Query
    summary: Locate a patient by name, read the Patient resource, then pull that patient's Observations.
  - url: arazzo/medplum-create-diagnostic-report-workflow.yml
    name: Medplum Create Diagnostic Report
    summary: Create an Observation result, then assemble a DiagnosticReport that references it.
  - url: arazzo/medplum-deploy-and-run-bot-workflow.yml
    name: Medplum Deploy Bot
    summary: Create a Bot resource, then create a Subscription that invokes the Bot on resource changes.
  - url: arazzo/medplum-fhir-resource-crud-workflow.yml
    name: Medplum FHIR Resource CRUD
    summary: Create a FHIR R4 resource, read it back by id, update it, then search the resource type for it.
  - url: arazzo/medplum-finalize-observation-workflow.yml
    name: Medplum Finalize Observation
    summary: Find a preliminary Observation, patch its status to final, and read it back to confirm.
  - url: arazzo/medplum-find-and-delete-resource-workflow.yml
    name: Medplum Find And Delete Resource
    summary: Search a resource type, and if a match is found read it for audit then delete it.
  - url: arazzo/medplum-register-patient-with-observation-workflow.yml
    name: Medplum Register Patient With Observation
    summary: Create a Patient, then record a vital-sign Observation that references that patient.
  - url: arazzo/medplum-resource-versioning-workflow.yml
    name: Medplum FHIR Resource Versioning
    summary: Create a FHIR resource, update it to mint a new version, read its history, then read a specific version.
  - url: arazzo/medplum-schedule-encounter-workflow.yml
    name: Medplum Schedule Encounter
    summary: Create a Practitioner, create an Encounter linking the patient and practitioner, then read it back.
  - url: arazzo/medplum-upsert-patient-workflow.yml
    name: Medplum Upsert Patient
    summary: Search for a Patient by identifier and update it if found, otherwise create it.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com