API for HIS vendors and developers
The Caresoft BBMS API lets any HIS create patients and blood requests, read request status and stock, and post transfusions. It accepts JSON and HL7 FHIR R4, authenticates with a bearer token per organisation, and sends events back as signed webhooks. The OpenAPI specification is published.
How do I authenticate?
The blood bank administrator generates an API token in Settings. Send it as Authorization: Bearer <token> to /api/v1/…. Tokens are stored only as hashes and can be replaced at any time.
Which endpoints are available?
| Endpoint | Purpose |
|---|---|
| POST /api/v1/patients | Create or update a patient by HIS patient id |
| POST /api/v1/requisitions | Create a blood request (idempotent on your reference) |
| GET /api/v1/requisitions/{ref} | Status, patient group, reserved and issued bags |
| POST /api/v1/requisitions/{ref}/cancel | Cancel before issue |
| GET /api/v1/stock | Available units by group and component |
| POST /api/v1/transfusions | Record transfusion start and end from the ward |
| POST /api/v1/fhir/Patient | HL7 FHIR R4 Patient |
| POST /api/v1/fhir/ServiceRequest | HL7 FHIR R4 ServiceRequest for blood components |
| GET /api/v1/fhir/ServiceRequest?identifier=… | Search by your order reference |
How do events reach my system?
Set an HTTPS endpoint in Settings. BBMS posts each event with X-BBMS-Signature: sha256=HMAC(secret, timestamp.body) and retries with back-off for up to 12 attempts. Choose BBMS JSON or FHIR format. Events include group verified, units issued, charges posted, transfusion started and completed, reactions and look-back.
Questions people ask
Is there a sandbox?
See it with your own stock and workflow
A 30-minute demo walks through donor to bedside, the safety stops, and how BBMS connects to your HIS.