Product

White Label Telehealth API: 9 Platforms Compared (2026)

White label telehealth API compared: 9 platforms on public docs, OpenAPI contracts, auth, signed webhooks, sandbox, SDKs, versioning and plan tier.

MyOrbitHealth Developer Relations TeamOctober 6, 202618 min read

As of October 2026, only a minority of white-label telehealth vendors publish an API reference you can read before a sales call, and fewer still publish a machine-readable contract, a webhook signing scheme, a sandbox you can reach quickly, and a deprecation policy. Judged on what their public documentation states, Cuvo Health publishes the most complete developer surface (an OpenAPI 3.1 contract with 65 operations, 32 webhook event types, HMAC-signed webhooks, a self-serve sandbox and prerelease SDKs, gated to its Grow plan and above). MyOrbitHealth publishes a documented product REST API at api.myorbithealth.com/v1 with bearer-token auth, test and live keys, HMAC-SHA256 signed webhooks, a React SDK and a sandbox provisioned within a day, plus a separate free, no-auth agent layer with its own OpenAPI 3.1 contract and a 21-tool MCP server. SteadyMD, Telegra and CareValidate publish public references with narrower surfaces. Wheel, Beluga Health, OpenLoop and Fuse Health either gate documentation behind an engagement or do not publish it at all.

This post compares all nine on the same eight criteria so an engineering lead can shortlist in an afternoon. One disclosure up front: MyOrbitHealth publishes this blog and appears in the comparison. We have tried to be fair, we did not run live tests against anyone's API, and every competitor claim is hedged to what their public docs said as of October 2026. This is general information, not legal advice.

Key takeaways

  • As of October 2026, per their public docs, Cuvo Health publishes the largest documented telehealth API contract (OpenAPI 3.1, 65 operations, 32 webhook events) but gates API access to its Grow plan at $15,000 setup plus $2,500 per month.
  • MyOrbitHealth documents a product REST API with bearer-token auth, path versioning, 600 requests per minute per key with burst to 1,200, HMAC-SHA256 signed webhooks, a React SDK and a sandbox within a day, alongside a free agent API with an OpenAPI 3.1 contract and a 21-tool MCP server.
  • SteadyMD, Telegra and CareValidate publish readable references; Wheel, Beluga Health, OpenLoop and Fuse Health do not publish a public API reference as of October 2026.
  • The API is only as useful as the clinic behind it: a telehealth API has to move a patient from intake to a licensed provider to a prescription to a pharmacy shipment, not just expose CRUD on records.
  • Judge a vendor on eight documented criteria before the demo: public docs, machine-readable contract, auth model, signed webhooks, sandbox, SDKs, versioning policy and plan tier.

Who this is for

  • Engineering leads at DTC health brands deciding whether to integrate a clinical layer by API or launch on a hosted storefront first.
  • CTOs at digital health startups who need to know, before the sales call, whether a vendor's API is real, documented and testable.
  • Product managers at e-commerce, fitness or supplement companies evaluating what a telehealth API actually does end to end.
  • Founders comparing Cuvo, SteadyMD, Wheel, Beluga, OpenLoop, Fuse, Telegra, CareValidate and MyOrbitHealth on developer experience rather than marketing.

What is a white label telehealth API?

A white label telehealth API is a programmatic interface to a regulated clinic that someone else operates. Your software creates the patient, captures consent, submits an intake, and listens for events; the vendor's licensed providers review the case, prescribe when appropriate, and route the prescription to a pharmacy that ships. Your brand is on the app and the box. The vendor's medical entity, prescribers, pharmacies and compliance program sit behind the API.

That makes it different from a generic healthcare API (FHIR access to an EHR, say) and from a single-purpose e-prescribing API. A telehealth API bundles three regulated layers: clinical decision by a licensed provider, prescription transport over Surescripts, and pharmacy fulfillment. If a vendor's API only covers scheduling and payments, it is a booking API, not a telehealth API. Our telemedicine app development guide walks through what the app layer and the clinical layer each own.

How did we compare the nine platforms?

We read each vendor's public developer documentation and marketing pages as of October 2026 and scored them on eight criteria. We did not call anyone's endpoints and we did not use trial credentials; where a vendor's docs do not state something, we say so.

# Criterion What we looked for
1 Public API docs A reference readable without an account or password
2 Machine-readable contract A published OpenAPI document or Postman collection
3 Auth model How credentials are issued, scoped and rotated
4 Webhooks and signing A documented event catalog and a published signature scheme
5 Sandbox How quickly a test environment is reachable and what it simulates
6 SDKs Official client libraries, and in which languages
7 Versioning and deprecation A stated policy for breaking changes and sunset windows
8 Plan tier Which commercial tier includes API access

Telehealth API comparison table, October 2026

Facts below are what each vendor's public documentation states as of October 2026. Where a cell says "not publicly documented," we could not find it in public docs; it may exist behind an engagement.

Rank Platform Public docs Contract Auth Webhooks and signing Sandbox SDKs Versioning policy API plan tier
1 Cuvo Health Yes, developers.cuvo.co OpenAPI 3.1, 65 operations; Postman Bearer token, test and live keys 32 event types, HMAC-SHA256, timestamped Self-serve test keys, 12 simulator operations TypeScript, Python (prerelease), CLI 12-month deprecation floor Grow ($15,000 setup + $2,500/mo) and above
2 MyOrbitHealth Yes, /api-docs and /developers Product API: not published as a file; agent API: OpenAPI 3.1 at /openapi.json Bearer token, test and live environment-scoped keys, rotation on demand Events such as appointment.completed, prescription.dispensed; HMAC-SHA256 Provisioned within a day after a short partner review React SDK Path versioning; breaking changes ship under a new version Platform engagement, scoped at onboarding; no published price list
3 SteadyMD Yes, docs.steadymd.com Not publicly documented as a single file Not stated in public docs AWS SNS topic notifications at each consult step Sandbox API section with state transitions Not publicly documented Changelog (entries through Feb 2025); one endpoint marked deprecated Custom quotes
4 Telegra Yes, documentation.telegramd.com Not publicly documented Client admin token plus patient SSO key Webhooks v2 with signature verification and secret rotation Development environment with a lifecycle processor Not publicly documented v2 endpoints; changelog through Sept 2026 Custom (published Plus $3,000/mo + $5,000 onboarding; Pro $6,000/mo + $10,000 onboarding)
5 CareValidate Yes, docs.careglp.com Not publicly documented cv-api-key header 30+ events listed; signing not stated Not stated Not publicly documented Not publicly documented Platform fees not published; 3.7% payment processing
6 Wheel Not at a public URL Not publicly documented Not publicly documented Not publicly documented Not publicly documented Not publicly documented Not publicly documented Deal-by-deal enterprise pricing
7 Beluga Health On request Not publicly documented Not publicly documented Not publicly documented Not publicly documented Not publicly documented Not publicly documented No public pricing
8 Fuse Health Not found Not publicly documented Not publicly documented Not publicly documented Not publicly documented Not publicly documented Not publicly documented Partner plan ($3,000/mo + 2% merchant fee)
9 OpenLoop Not found Not publicly documented Not publicly documented Not publicly documented Not publicly documented Not publicly documented Not publicly documented No public pricing

Ranking is by documented developer surface only. It says nothing about clinical quality, provider coverage or pricing fit, which the best white label telehealth platforms roundup covers.

1. Cuvo Health: the most complete published contract

As of October 2026, per developers.cuvo.co, Cuvo publishes an OpenAPI 3.1 document covering 65 operations across patients, consents, cases, prescriptions, pharmacy orders, visits and webhook endpoints, plus a Postman collection. Auth is bearer token with separate test and live keys. Webhooks are signed with HMAC-SHA256 over a timestamp and the raw body, with 32 versioned event types and a polling backstop. The sandbox is self-serve: a test key reaches a shared test organization and 12 simulator operations play the clinician and the pharmacy. SDKs for TypeScript and Python are published as prerelease, with a CLI and a 46-tool MCP server behind OAuth 2.1. The versioning policy commits to a 12-month floor on deprecated operations.

The constraints are commercial. Per Cuvo's pricing page updated October 2, 2026, API, webhooks and MCP are included on Grow ($15,000 setup plus $2,500 per month) and above, not on Launch ($9,800 setup plus $997 per month). All plans carry a $25 fee per completed consult with 0% medication markup and no revenue share. The full commercial comparison lives at /compare/myorbit-vs-cuvo.

2. MyOrbitHealth: documented product API plus a free agent layer

MyOrbitHealth runs two separate developer surfaces, and it is worth being precise about which is which.

The product API at https://api.myorbithealth.com/v1 is the one that touches patients. Per /api-docs, it uses bearer-token auth with environment-scoped test and live keys that can be rotated on demand, is versioned in the path (breaking changes ship under a new version, additions under the current one), and returns X-RateLimit-* headers at a default of 600 requests per minute per key with burst to 1,200. Errors come back as { error: { code, message, details } }. Documented endpoints cover patients, appointments, prescriptions and webhook registration; documented events include appointment.completed and prescription.dispensed, with payloads signed with HMAC-SHA256. A React SDK is available for embedding intake and the patient flow inside an existing product. Sandbox access is provisioned within a day after a short partner review. As of October 2026 the product API's OpenAPI document is not published as a public file, and the operation count is not published, so we do not claim one.

The agent layer, documented at /developers, is free and needs no auth. It consists of a public MCP server at myorbithealth.com/mcp with 21 tools (19 read, 2 consent-gated action tools), an agent REST API with an OpenAPI 3.1 contract at /openapi.json (/ask, /api/articles, /api/comparisons, /api/health), an npm CLI (npx myorbithealth), llms.txt and llms-full.txt, .md mirrors of every page, an RSS feed and .well-known discovery files. Errors are RFC 9457 problem+json. This layer exposes company, pricing-model, compliance and comparison information to AI agents; it does not expose patient data. The healthcare MCP server post goes deeper.

Behind the product API sits the clinic: 2,400+ board-certified providers across 38+ specialties in all 50 states with average response under six minutes during business hours, OrbitRx e-prescribing via Surescripts to a LegitScript-certified pharmacy network at 0% medication markup, and Orbit Labs. Commercially, the API is part of the platform engagement: a flat platform fee scoped at onboarding, no revenue share, no exit fee, month-to-month after onboarding, with the brand as merchant of record. There is no published price list.

An illustrative example against the documented endpoint (field names beyond those documented are examples):

# Example: create a patient in the test environment
curl -X POST https://api.myorbithealth.com/v1/patients \
  -H "Authorization: Bearer $MYORBIT_TEST_KEY" \
  -H "Content-Type: application/json" \
  -d '{"first_name":"Test","last_name":"Patient","state":"TX"}'

3. SteadyMD: public docs for a clinician workforce API

As of October 2026, per docs.steadymd.com, SteadyMD publishes a readable reference covering patients, consults across video, phone and async modalities, episodes of care with intake questionnaires, pharmacy search and preferred-pharmacy management, and lab orders with result retrieval. Status notifications arrive over AWS SNS topics at each step of the consult workflow, which means verification follows the AWS SNS message-signing model rather than a vendor HMAC. A Sandbox API section documents consult state transitions and canned data. The changelog's most recent entry we found is dated February 2025 and one endpoint is marked deprecated. We did not find official SDKs or a stated deprecation window. Pricing is by custom quote. See /compare/myorbit-vs-steadymd.

4. Telegra: public docs, credentials after onboarding

As of October 2026, per documentation.telegramd.com, Telegra documents patient creation, questionnaires, order lifecycle, practitioner consultations, prescriptions, pharmacy routing, lab orders and messaging. Auth is a client-admin token plus a patient SSO key. Webhooks v2 carry signature verification with rotating signing secrets and documented delivery and retry behavior. Testing happens in a development environment with a lifecycle processor rather than a self-serve sandbox. We did not find SDKs or a published OpenAPI file. Published pricing is Plus at $3,000 per month plus $5,000 onboarding and Pro at $6,000 per month plus $10,000 onboarding, with consult fees billed separately. See /compare/myorbit-vs-telegra.

5. CareValidate: public docs, narrower scope

As of October 2026, per docs.careglp.com, CareValidate authenticates with a cv-api-key header issued from organization settings and documents cases, appointments with provider availability checks and Stripe payments, with 30+ webhook events for case changes, payments, calendar events and orders. We did not find a published signing scheme, sandbox description, SDK, contract file or versioning policy. Platform fees are not published; the site lists 3.7% payment processing. See /compare/myorbit-vs-carevalidate.

6. Wheel: enterprise API behind an engagement

Wheel sells an enterprise clinician network and API with deal-by-deal pricing and a go-live target under 90 days. As of October 2026 we could not find a developer reference at a public URL; documentation appears to be shared within an engagement. Nothing about contract, signing, sandbox or SDKs is publicly documented. If you want to read the API before the call, that is not possible today. See /compare/myorbit-vs-wheel.

7. Beluga Health: documentation on request

Beluga Health is a physician-founded white-label DTC telemedicine company with a 50-state physician network and LegitScript certification. As of October 2026, API documentation is available on request rather than at a public URL, and no public pricing is published. See /compare/myorbit-vs-beluga-health.

8. Fuse Health: API on the top plan only

Fuse Health positions itself as a peptide-first storefront. As of October 2026 it publishes Growth at $699 per month and Partner at $3,000 per month plus a 2% merchant fee on sales, with the onboarding fee not published and API access listed on the top plan only. We did not find public API documentation. See /compare/myorbit-vs-fuse-health.

9. OpenLoop: no public API reference found

OpenLoop offers enterprise full-stack telehealth support (staffing, white-label technology, payer and revenue-cycle services, licensing and credentialing) to health plans, health systems and digital health companies. As of October 2026 we found no public API documentation and no public pricing. See /compare/myorbit-vs-openloop.

What should a telehealth API actually do?

Documentation is necessary, not sufficient; the operations also have to cover the whole visit. The table below maps the operations a brand needs to what MyOrbitHealth and Cuvo document publicly as of October 2026; for the other seven, use the vendor sections above.

Operation a brand needs Why it matters MyOrbitHealth (per /api-docs and /platform) Cuvo (per developers.cuvo.co)
Create patient Starts the chart under your brand Documented endpoint Documented operation
Capture consent Required before a clinician reviews Handled in Orbit Intake and the hosted flow; API detail not published Documented operation
Submit intake Adaptive questions, severity scoring, red flags Orbit Intake, embeddable via React SDK Case filing with intake payload
Match a licensed provider State license, specialty, availability Provider Network load balancing, 2,400+ providers 300+ providers, case queue
Schedule a visit Sync video where required Documented appointments endpoint Documented visits operations
Read prescription status Shows the patient what was decided Documented prescriptions endpoint Read-only prescriptions
Pharmacy order and shipment events Tracking, refill prompts prescription.dispensed event; OrbitRx routing Order events through delivery
Labs Provider-ordered, three draw paths Orbit Labs (Quest/Labcorp, Tasso, mobile phlebotomy); API detail not published Labcorp and Quest per its docs
Register webhooks Event-driven backend Documented webhook registration Documented webhook endpoints

The pharmacy API post explains why the prescription-to-shipment events are the hardest part of this table to get from any vendor, and what the pharmacy layer has to do underneath them.

Which auth and webhook models are safe for PHI?

Two patterns show up across the nine vendors and both can be run safely; the difference is how much you have to build.

Bearer tokens with environment-scoped keys (MyOrbitHealth, Cuvo) separate test from live at the credential level, so a developer cannot accidentally point a prototype at real patients. MyOrbitHealth returns X-RateLimit-* headers at 600 requests per minute per key with burst to 1,200; Cuvo documents RFC 9457 problem+json with request IDs.

Signed webhooks are where PHI leaks happen if you skip verification. A good scheme signs a timestamp plus the raw body with HMAC-SHA256 so a replayed or forged payload fails. MyOrbitHealth documents HMAC-SHA256 signing; Cuvo documents HMAC-SHA256 with timestamped signatures; Telegra documents v2 signature verification with secret rotation; SteadyMD uses AWS SNS signatures; CareValidate does not state a scheme in public docs. Whatever the vendor, verify before you parse, dedupe on an event ID, and treat webhooks as a hint to fetch the record rather than as the record itself.

Does the plan tier include the API?

This is where several shortlists fall apart. As of October 2026, per their public pricing:

  • Cuvo includes API, webhooks and MCP on Grow ($15,000 setup plus $2,500 per month) and above, not on Launch.
  • Fuse Health lists API access on its Partner plan at $3,000 per month plus 2% merchant fee.
  • Telegra publishes plan prices (Plus $3,000 per month plus $5,000 onboarding; Pro $6,000 per month plus $10,000 onboarding) with consult fees billed separately; which tier includes which API features is not stated in the public docs we read.
  • SteadyMD, Wheel, Beluga, OpenLoop, CareValidate quote per deal.
  • MyOrbitHealth scopes a flat platform fee at onboarding to verticals, states and volume, with 0% medication markup, no revenue share and no exit fee; API, signed webhooks and the React SDK are part of the platform rather than a separately priced tier. There is no published price list.

If the API is the point of the purchase, get the tier that includes it in writing before you build.

Best for

  • Cuvo Health: teams that want the largest published contract and self-serve sandbox today and can carry Grow pricing plus $25 per completed consult.
  • MyOrbitHealth: brands that want a hosted clinic and an API from the same vendor, a React SDK for embedded intake, 2,400+ providers across 38+ specialties, OrbitRx and Orbit Labs behind the same keys, and a flat fee with no revenue share or exit fee.
  • SteadyMD: companies that primarily need a clinician workforce with a public reference and SNS-based notifications.
  • Telegra: operators comfortable with onboarding-gated credentials who want documented v2 webhooks and published plan pricing.
  • CareValidate: teams whose integration need is cases, scheduling and payments more than prescribing.
  • Wheel: enterprises at a scale where deal-by-deal API access and a sub-90-day go-live are acceptable.
  • Beluga Health: brands that value a physician-founded network and will request documentation during evaluation.
  • Fuse Health: peptide-first storefront operators who can justify the Partner plan for API access.
  • OpenLoop: health plans and systems buying staffing and RCM alongside technology, not API-first builders.

How should you evaluate a telehealth API vendor?

Seven questions, in order, each answerable from public docs or one email.

  1. Where is the reference? If it is behind a password, ask why.
  2. Is there a contract file? OpenAPI or Postman lets you count operations and generate a client before signing.
  3. How are keys scoped? Test versus live, rotation, rate limits in headers.
  4. How are webhooks signed? Algorithm, timestamp, event ID, retries, polling backstop.
  5. How fast is the sandbox, and what does it simulate? A clinician decision and a shipment are the two events you need to fake.
  6. What SDKs exist and what is the deprecation window?
  7. Who employs the clinicians and which pharmacies fill? The API is a window into a clinic; the how to choose a white label telehealth partner guide covers the clinic questions.

Frequently asked questions

Which white label telehealth platforms have a public API?

As of October 2026, per their public docs, Cuvo Health, MyOrbitHealth, SteadyMD, Telegra and CareValidate publish readable API references. Wheel and Beluga Health share documentation within an engagement or on request, and we found no public reference for OpenLoop or Fuse Health.

What is the best telehealth API?

It depends on what you are buying. Judged only on documented developer surface, Cuvo publishes the largest contract and a self-serve sandbox. Judged on getting a hosted clinic and an API from the same vendor with a React SDK, a flat fee and no revenue share, MyOrbitHealth is the stronger fit. Read both vendors' docs before deciding.

Does MyOrbitHealth have an API?

Yes. The product REST API at api.myorbithealth.com/v1 uses bearer-token auth with test and live keys, path versioning, documented endpoints for patients, appointments, prescriptions and webhooks, HMAC-SHA256 signed webhooks and a React SDK, with a sandbox provisioned within a day. A separate free agent layer offers a 21-tool MCP server and an OpenAPI 3.1 agent API.

Does Wheel have a public API?

As of October 2026 we could not find Wheel's developer reference at a public URL. Wheel sells an enterprise clinician network and API with deal-by-deal pricing, and documentation appears to be shared during an engagement.

Which telehealth APIs offer a sandbox?

As of October 2026, per their docs, Cuvo offers self-serve test keys with simulator operations, MyOrbitHealth provisions a sandbox within a day after a short partner review, SteadyMD documents a Sandbox API section, and Telegra describes a development environment. CareValidate, Wheel, Beluga, OpenLoop and Fuse do not document a sandbox publicly.

Which plan tier includes API access?

Per public pricing as of October 2026, Cuvo includes API access on Grow and above, Fuse lists it on its Partner plan, and MyOrbitHealth includes it in the platform engagement scoped at onboarding. Telegra, SteadyMD, Wheel, Beluga, OpenLoop and CareValidate quote per deal or do not state the tier publicly.

Is there an e-prescribing API for telehealth brands?

Not directly. Prescriptions must be written by a licensed prescriber and transported over a certified network such as Surescripts, so a brand integrates with a vendor whose providers prescribe and whose pharmacies fill. MyOrbitHealth exposes prescription status and a prescription.dispensed event over its API; the prescribing itself happens inside OrbitRx.

How do you verify a telehealth API is real before signing?

Read the public reference, ask for the contract file, confirm the auth and webhook signing model, ask how quickly a sandbox is provisioned and what it simulates, and ask which plan tier includes API access. If any of those answers requires a contract first, weigh that against vendors that answer in public.

Sources

Read the docs, then book the integration call

MyOrbitHealth's telehealth API and API docs are public, the agent layer at /developers needs no account, and a sandbox is provisioned within a day after a short partner review. Behind the keys are 2,400+ board-certified providers in all 50 states, OrbitRx and Orbit Labs. Book a demo to walk through the endpoints, webhook events and React SDK for your vertical.

Verify Approval for www.myorbithealth.com

LegitScript certified. MyOrbitHealth (myorbithealth.com) is LegitScript certified. Click the seal to verify.

Related reading

Launch your telehealth brand with MyOrbitHealth.

We power the medical, regulatory, and pharmacy layer. You own the brand and the customer.