Skip to main content
ABDM Connect is a REST API over the ABDM gateway. You call Eka, and Eka handles ABDM’s gateway protocol, encryption and callbacks for you. This page covers what every ABDM Connect call has in common. New to ABDM? Read the ABDM overview first for the ecosystem, roles and milestones.

Postman Collection

Environments

Build and certify against the sandbox, then switch the base URL.

Authentication

Every ABDM Connect API takes an Eka access token for your client.
1

Log in

Call Connect Login with your client_id and client_secret. It returns an access_token and a refresh_token.
2

Send the token

Pass it on every request as Authorization: Bearer <access_token>.
3

Refresh on 401

A 401 means the access token expired. Get a new one with Connect Refresh.
See Authorization to get credentials.

The patient’s ABHA session

Some APIs also act for a specific patient and need their ABHA session with the ABDM gateway. It is separate from your client token:
  • ABHA creation, login and session verify return the patient’s token. APIs that need it, such as KYC, take it as user_x_token in the body.
  • When the ABHA session expires, these APIs return HTTP 491. Check it with Session Status and start a new one with a mobile OTP. See User Session.

Common Headers

Most ABDM Connect APIs take these headers to say which patient and facility the call is for. Each API page lists the headers that call takes.

Multi-step Flows

OTP and linking flows take more than one call. The first call returns a txn_id (or a request_id), and every later step in that flow sends it back.

APIs by Milestone

Callbacks

ABDM is asynchronous: many results reach you later as a webhook. Register your endpoint with the Webhooks API. Every callback is a POST with a JSON body that names its event, and carries an Eka-Webhook-Signature header you should verify.

Encryption

Health records travel between HIPs and HIUs encrypted with ECDH on Curve25519. If Eka stores your records, Eka encrypts and decrypts them for you. If you serve records yourself, see ECDH encryption.

Errors

4XX codes are request errors and 5XX are server errors. Error bodies look like this:
source_error carries ABDM’s own code when the gateway refused the call. See Errors for every code.

SDKs

ABHA Web SDK (M1)

Drop-in ABHA creation, login, KYC and Scan & Share screens.

Consent Management Web SDK (M3)

A UI widget to request, track and act on consents for your patients.

NHPR Web SDK (M4)

A UI widget to register doctors on the HPR and their clinic on the HFR.

Go SDK

Backend client for the ABDM Connect APIs.