Scopes
All four scopes on this page are consent-gated health scopes: the API client
must be created with
"consents": { "healthData": true }. Without that
stored consent, these endpoints return 403 scopes.health_consent_required.
See Authentication.List measurement types
measurements:read
Response fields:
List measurement entries
measurements:read
Validation:
Response fields:
Historical access grants are applied when the client relationship has restricted
history access.
Create measurement entry
measurements:write
Request body:
Accepted numeric examples:
201 Created):
Update measurement entry
measurements:write
Allowed fields: value, unit, measuredAt, note.
Validation is identical to create. At least one allowed field is required.
Response fields:
Archive measurement entry
measurements:write
This is a soft archive only. The endpoint sets the entry as deleted for product
views and Public API reads. It does not hard-delete measurement records.
Validation:
Response fields:
List measurement progress summaries
progress_summaries:read
Validation:
Response fields:
Not exposed: notes, provider source refs, derivation refs, health quality flags,
coach IDs, company IDs, suppression metadata, or raw health-processing context.
List progress photos
progress_photos:read
Validation:
Response fields:
Not exposed: raw
imageUrl, S3 keys, createdBy, coachId, companyId,
dimensions, file size, media provider metadata, or hard-delete controls.
Get progress photo
progress_photos:read
Response fields:
The detail endpoint applies the same client access, historical progress-photo
access, orientation, and date-range filters as the list endpoint. It never
returns raw storage keys or the persisted
imageUrl.