Skip to main content
Your key is issued by Valiance Health, prefixed hpx_, and shown once at issuance.

Two ways to present the same key

Both work on every endpoint in this reference. Pick whichever your client makes easy — the key is validated identically either way, and neither grants access the other does not.

X-API-Key header

Explicit, and unambiguous if your client also sends a Bearer token for something else.

Authorization: Bearer

The standard slot, so OpenAI-compatible SDKs work unmodified — and so auth=, --user and generated clients need no custom header.
If you send both, X-API-Key is used. That is what lets an SDK which pins Authorization to its own token still authenticate with your key.
Deterministic DRG classification
PHI-safe chat, through the OpenAI SDK

Scopes

A key may be issued with scopes that narrow which endpoints it can reach: drg:classify, llm:chat, redact, search. An out-of-scope call returns 403, and the body names the scopes your key holds. That is a request for access, not a reason to rotate the key. A 401 means the credential itself was not accepted — an unknown, revoked or expired key. Only a 401 is a reason to check the key you are sending.

Rotation, expiry and sandbox keys

Your organization can hold two active keys at once. Request a new key, migrate your traffic, then we revoke the old one. Revocation takes effect on the very next request and is audit-logged.
Pilot keys expire — 12 months by default. Ask us before expiry; a lapsed key fails closed with a 401 rather than degrading.
For integration testing: metered but never invoiced, with a separate small spend allowance, so a test loop can neither bill you nor block your production key.Synthetic data only. A sandbox key carries the same PHI handling as a production one, but the allowance is not sized for real workloads.
Treat keys as secrets. Store them in environment variables or a secrets manager, never in version control. Contact support to rotate a key you believe is exposed.