Reference

Frequently asked questions, answered plainly.

The questions support actually gets, answered the way support actually answers them.

Getting started

Is there a free tier?

Yes, and it needs no card. A Free key carries drugs:read, atc:read, changes:read and chat:write, with 10 requests and 5¢ of AI credit a month, counted per account. It is enough to call every endpoint and judge the data, not to run on — Pro is $29 a month for 1,500 requests and 50 answers. Quickstart.

I lost my API key. Can you send it to me?

No — we do not have it. Only a SHA-256 hash and the last four characters are stored, so the plaintext genuinely does not exist anywhere after the response that created it. Rotate the key in the console: that mints the replacement first and revokes the old one second, so you are never left with no working key.

My key worked yesterday and returns 401 today.

Three candidates, in order of likelihood: you hit the daily cap or the monthly quota (an exhausted key returns 401, not 429); the key was revoked or rotated; or it is an old ms_-prefixed key, which is no longer accepted. See Errors.

The data

Where does the data come from?

Public national medicines registers and open scientific databases — Swissmedic and the Swiss BAG, the EMA and national EU agencies, the FDA and CMS, the WHO ATC classification, and open pharmacology sources for enrichment. Every value carries its source, and the Sources page shows the live state of each feed. How to read it.

Can I redistribute it?

Read the terms — the short version is that the underlying registers are public but several carry their own conditions, and what you may do with a response is not uniform across sources. Commercially licensed databases are deliberately not in the product at all; where a customer holds their own licence for one, it is connected through their credentials rather than redistributed by us.

How many drugs and countries do you cover?

The honest answer is “check the page that counts it”: Sources computes the drug total, the country count and the number of live feeds from the database on each load, rather than repeating a figure that was true when somebody wrote it down. Coverage is not uniform — a country can be well covered for registrations and have no price data at all.

Why does a medicine show no price?

Because no published price is on file for it in that market. We never estimate one and never show a zero, since a zero is indistinguishable from “free”. Price coverage is a licensing question more than a technical one — see which markets we hold prices for.

Nothing came back for a pair in the interaction checker. Is it safe?

No — it means we hold no reviewed interaction for that pair, which is not the same thing. Interaction data is incomplete by nature. What the verdict is not.

What do ATC, DDD, GTIN and the other codes mean?

Every term of art the registers and the console use — ATC code, defined daily dose, GTIN, Pharmacode, NDC, SmPC and the rest — is defined in plain words in the glossary, with who defines it.

Compliance

Do you process patient data?

No. The prescription-screening endpoint is the only surface that takes clinical context, and it accepts drug identifiers plus coarse non-identifying bands only — age band, sex, pregnancy flag, eGFR band, condition and allergy labels. It runs the screen in-project; nothing is forwarded anywhere.

A request carrying a patient identifier is rejected, not scrubbed. Names, dates of birth, MRNs, email addresses, phone numbers, social-security and insurance numbers, addresses and postcodes are all on a blocklist, and their presence anywhere in the body returns a 422. A misconfigured client should fail loudly rather than have us quietly drop fields it thought it sent.

Which also means

Do not send patient identifiers hoping they will be stripped. And do not treat any response as a clinical decision: everything clinical carries the line informational only; not a medical device and not a substitute for professional clinical judgment, and that is a statement about regulatory status, not modesty.

Is this a medical device?

No. It is a data product. It is not CE-marked, not FDA-cleared, and not intended to inform a clinical decision without a qualified human in the loop. If you are building something that would itself be a regulated device, the obligation is yours and you should be talking to a notified body, not to us.

Can I call the API from a browser?

Technically yes — CORS is open, with no credentialed origin. But an API key in client-side JavaScript is a public key: anyone can read it and spend your quota. Proxy through your own backend. Details.

Integration

Is there a GraphQL API?

Yes, at POST /v1/graphql with the graphql:query scope (Pro and up), and GET /v1/graphql returns the schema as SDL to any valid key. Be aware that the executor is a small hand-written one covering five query fields, and it is honest about its limits:

  • No fragments — inline your selections.
  • No directives (@include, @skip).
  • No full introspection, so tooling that expects __schema will not work. Read the SDL from the GET instead.
  • One operation per request; mutations and subscriptions are errors.

If your client is a code generator or a GraphQL IDE that assumes a full server, use REST. The GraphQL surface is for hand-written queries against known fields.

Do you support FHIR?

Partially. GET /v1/drugs/{id}?format=fhir returns the record as a FHIR R4 Medication resource. There is no FHIR server, no search parameters and no other resource types — it is a format switch on one endpoint, meant for dropping a record into an existing FHIR pipeline.

Are there client libraries?

First-party, MIT-licensed, and thin:

install
npm i @drug-database/sdk          # JS / TS, zero runtime deps
npm i @drug-database/react        # hooks + a drop-in typeahead
npm i @drug-database/hl7v2        # RXE segment helper
npm i @drug-database/mcp-server   # the MCP server
pip install drug-database         # Python

None of them is required. The OpenAPI document at /api/v1/openapi.json is public and complete — pointing a generator at it gives you a client in the language and style your codebase already uses.

Can I get pushed updates instead of polling?

Yes — webhooks, signed with HMAC-SHA256, on the webhooks:write scope (Starter and up). If you prefer to pull, GET /v1/changes is the same feed and is in the free tier.

Can I use my own licensed data source alongside yours?

That is what the BYOL endpoints are for: you store credentials for a source you are licensed for, and queries against it are proxied with your credentials rather than ours. Requires byol:write (Growth and up). See the byol family.

Still stuck

Check status first — if a source is degraded it will say so there. Then write to support@drug-database.com with the endpoint, the status code, the error string and roughly when it happened. Never include your API key in an email — the last four characters are enough for us to find it.