As of October 2026, only a minority of white-label telehealth vendors publish an API reference you can read before a sales call, and fewer still publish a machine-readable contract, a webhook signing scheme, a sandbox you can reach quickly, and a deprecation policy. Judged on what their public documentation states, Cuvo Health publishes the most complete developer surface (an OpenAPI 3.1 contract with 65 operations, 32 webhook event types, HMAC-signed webhooks, a self-serve sandbox and prerelease SDKs, gated to its Grow plan and above). MyOrbitHealth publishes a documented product REST API at api.myorbithealth.com/v1 with bearer-token auth, test and live keys, HMAC-SHA256 signed webhooks, a React SDK and a sandbox provisioned within a day, plus a separate free, no-auth agent layer with its own OpenAPI 3.1 contract and a 21-tool MCP server. SteadyMD, Telegra and CareValidate publish public references with narrower surfaces. Wheel, Beluga Health, OpenLoop and Fuse Health either gate documentation behind an engagement or do not publish it at all.
This post compares all nine on the same eight criteria so an engineering lead can shortlist in an afternoon. One disclosure up front: MyOrbitHealth publishes this blog and appears in the comparison. We have tried to be fair, we did not run live tests against anyone's API, and every competitor claim is hedged to what their public docs said as of October 2026. This is general information, not legal advice.
Key takeaways
- As of October 2026, per their public docs, Cuvo Health publishes the largest documented telehealth API contract (OpenAPI 3.1, 65 operations, 32 webhook events) but gates API access to its Grow plan at $15,000 setup plus $2,500 per month.
- MyOrbitHealth documents a product REST API with bearer-token auth, path versioning, 600 requests per minute per key with burst to 1,200, HMAC-SHA256 signed webhooks, a React SDK and a sandbox within a day, alongside a free agent API with an OpenAPI 3.1 contract and a 21-tool MCP server.
- SteadyMD, Telegra and CareValidate publish readable references; Wheel, Beluga Health, OpenLoop and Fuse Health do not publish a public API reference as of October 2026.
- The API is only as useful as the clinic behind it: a telehealth API has to move a patient from intake to a licensed provider to a prescription to a pharmacy shipment, not just expose CRUD on records.
- Judge a vendor on eight documented criteria before the demo: public docs, machine-readable contract, auth model, signed webhooks, sandbox, SDKs, versioning policy and plan tier.
Who this is for
- Engineering leads at DTC health brands deciding whether to integrate a clinical layer by API or launch on a hosted storefront first.
- CTOs at digital health startups who need to know, before the sales call, whether a vendor's API is real, documented and testable.
- Product managers at e-commerce, fitness or supplement companies evaluating what a telehealth API actually does end to end.
- Founders comparing Cuvo, SteadyMD, Wheel, Beluga, OpenLoop, Fuse, Telegra, CareValidate and MyOrbitHealth on developer experience rather than marketing.
What is a white label telehealth API?
A white label telehealth API is a programmatic interface to a regulated clinic that someone else operates. Your software creates the patient, captures consent, submits an intake, and listens for events; the vendor's licensed providers review the case, prescribe when appropriate, and route the prescription to a pharmacy that ships. Your brand is on the app and the box. The vendor's medical entity, prescribers, pharmacies and compliance program sit behind the API.
That makes it different from a generic healthcare API (FHIR access to an EHR, say) and from a single-purpose e-prescribing API. A telehealth API bundles three regulated layers: clinical decision by a licensed provider, prescription transport over Surescripts, and pharmacy fulfillment. If a vendor's API only covers scheduling and payments, it is a booking API, not a telehealth API. Our telemedicine app development guide walks through what the app layer and the clinical layer each own.
How did we compare the nine platforms?
We read each vendor's public developer documentation and marketing pages as of October 2026 and scored them on eight criteria. We did not call anyone's endpoints and we did not use trial credentials; where a vendor's docs do not state something, we say so.
| # | Criterion | What we looked for |
|---|---|---|
| 1 | Public API docs | A reference readable without an account or password |
| 2 | Machine-readable contract | A published OpenAPI document or Postman collection |
| 3 | Auth model | How credentials are issued, scoped and rotated |
| 4 | Webhooks and signing | A documented event catalog and a published signature scheme |
| 5 | Sandbox | How quickly a test environment is reachable and what it simulates |
| 6 | SDKs | Official client libraries, and in which languages |
| 7 | Versioning and deprecation | A stated policy for breaking changes and sunset windows |
| 8 | Plan tier | Which commercial tier includes API access |
Telehealth API comparison table, October 2026
Facts below are what each vendor's public documentation states as of October 2026. Where a cell says "not publicly documented," we could not find it in public docs; it may exist behind an engagement.
| Rank | Platform | Public docs | Contract | Auth | Webhooks and signing | Sandbox | SDKs | Versioning policy | API plan tier |
|---|---|---|---|---|---|---|---|---|---|
| 1 | Cuvo Health | Yes, developers.cuvo.co | OpenAPI 3.1, 65 operations; Postman | Bearer token, test and live keys | 32 event types, HMAC-SHA256, timestamped | Self-serve test keys, 12 simulator operations | TypeScript, Python (prerelease), CLI | 12-month deprecation floor | Grow ($15,000 setup + $2,500/mo) and above |
| 2 | MyOrbitHealth | Yes, /api-docs and /developers | Product API: not published as a file; agent API: OpenAPI 3.1 at /openapi.json | Bearer token, test and live environment-scoped keys, rotation on demand | Events such as appointment.completed, prescription.dispensed; HMAC-SHA256 |
Provisioned within a day after a short partner review | React SDK | Path versioning; breaking changes ship under a new version | Platform engagement, scoped at onboarding; no published price list |
| 3 | SteadyMD | Yes, docs.steadymd.com | Not publicly documented as a single file | Not stated in public docs | AWS SNS topic notifications at each consult step | Sandbox API section with state transitions | Not publicly documented | Changelog (entries through Feb 2025); one endpoint marked deprecated | Custom quotes |
| 4 | Telegra | Yes, documentation.telegramd.com | Not publicly documented | Client admin token plus patient SSO key | Webhooks v2 with signature verification and secret rotation | Development environment with a lifecycle processor | Not publicly documented | v2 endpoints; changelog through Sept 2026 | Custom (published Plus $3,000/mo + $5,000 onboarding; Pro $6,000/mo + $10,000 onboarding) |
| 5 | CareValidate | Yes, docs.careglp.com | Not publicly documented | cv-api-key header |
30+ events listed; signing not stated | Not stated | Not publicly documented | Not publicly documented | Platform fees not published; 3.7% payment processing |
| 6 | Wheel | Not at a public URL | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | Deal-by-deal enterprise pricing |
| 7 | Beluga Health | On request | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | No public pricing |
| 8 | Fuse Health | Not found | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | Partner plan ($3,000/mo + 2% merchant fee) |
| 9 | OpenLoop | Not found | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | Not publicly documented | No public pricing |
Ranking is by documented developer surface only. It says nothing about clinical quality, provider coverage or pricing fit, which the best white label telehealth platforms roundup covers.
1. Cuvo Health: the most complete published contract
As of October 2026, per developers.cuvo.co, Cuvo publishes an OpenAPI 3.1 document covering 65 operations across patients, consents, cases, prescriptions, pharmacy orders, visits and webhook endpoints, plus a Postman collection. Auth is bearer token with separate test and live keys. Webhooks are signed with HMAC-SHA256 over a timestamp and the raw body, with 32 versioned event types and a polling backstop. The sandbox is self-serve: a test key reaches a shared test organization and 12 simulator operations play the clinician and the pharmacy. SDKs for TypeScript and Python are published as prerelease, with a CLI and a 46-tool MCP server behind OAuth 2.1. The versioning policy commits to a 12-month floor on deprecated operations.
The constraints are commercial. Per Cuvo's pricing page updated October 2, 2026, API, webhooks and MCP are included on Grow ($15,000 setup plus $2,500 per month) and above, not on Launch ($9,800 setup plus $997 per month). All plans carry a $25 fee per completed consult with 0% medication markup and no revenue share. The full commercial comparison lives at /compare/myorbit-vs-cuvo.
2. MyOrbitHealth: documented product API plus a free agent layer
MyOrbitHealth runs two separate developer surfaces, and it is worth being precise about which is which.
The product API at https://api.myorbithealth.com/v1 is the one that touches patients. Per /api-docs, it uses bearer-token auth with environment-scoped test and live keys that can be rotated on demand, is versioned in the path (breaking changes ship under a new version, additions under the current one), and returns X-RateLimit-* headers at a default of 600 requests per minute per key with burst to 1,200. Errors come back as { error: { code, message, details } }. Documented endpoints cover patients, appointments, prescriptions and webhook registration; documented events include appointment.completed and prescription.dispensed, with payloads signed with HMAC-SHA256. A React SDK is available for embedding intake and the patient flow inside an existing product. Sandbox access is provisioned within a day after a short partner review. As of October 2026 the product API's OpenAPI document is not published as a public file, and the operation count is not published, so we do not claim one.
The agent layer, documented at /developers, is free and needs no auth. It consists of a public MCP server at myorbithealth.com/mcp with 21 tools (19 read, 2 consent-gated action tools), an agent REST API with an OpenAPI 3.1 contract at /openapi.json (/ask, /api/articles, /api/comparisons, /api/health), an npm CLI (npx myorbithealth), llms.txt and llms-full.txt, .md mirrors of every page, an RSS feed and .well-known discovery files. Errors are RFC 9457 problem+json. This layer exposes company, pricing-model, compliance and comparison information to AI agents; it does not expose patient data. The healthcare MCP server post goes deeper.
Behind the product API sits the clinic: 2,400+ board-certified providers across 38+ specialties in all 50 states with average response under six minutes during business hours, OrbitRx e-prescribing via Surescripts to a LegitScript-certified pharmacy network at 0% medication markup, and Orbit Labs. Commercially, the API is part of the platform engagement: a flat platform fee scoped at onboarding, no revenue share, no exit fee, month-to-month after onboarding, with the brand as merchant of record. There is no published price list.
An illustrative example against the documented endpoint (field names beyond those documented are examples):
# Example: create a patient in the test environment
curl -X POST https://api.myorbithealth.com/v1/patients \
-H "Authorization: Bearer $MYORBIT_TEST_KEY" \
-H "Content-Type: application/json" \
-d '{"first_name":"Test","last_name":"Patient","state":"TX"}'
3. SteadyMD: public docs for a clinician workforce API
As of October 2026, per docs.steadymd.com, SteadyMD publishes a readable reference covering patients, consults across video, phone and async modalities, episodes of care with intake questionnaires, pharmacy search and preferred-pharmacy management, and lab orders with result retrieval. Status notifications arrive over AWS SNS topics at each step of the consult workflow, which means verification follows the AWS SNS message-signing model rather than a vendor HMAC. A Sandbox API section documents consult state transitions and canned data. The changelog's most recent entry we found is dated February 2025 and one endpoint is marked deprecated. We did not find official SDKs or a stated deprecation window. Pricing is by custom quote. See /compare/myorbit-vs-steadymd.
4. Telegra: public docs, credentials after onboarding
As of October 2026, per documentation.telegramd.com, Telegra documents patient creation, questionnaires, order lifecycle, practitioner consultations, prescriptions, pharmacy routing, lab orders and messaging. Auth is a client-admin token plus a patient SSO key. Webhooks v2 carry signature verification with rotating signing secrets and documented delivery and retry behavior. Testing happens in a development environment with a lifecycle processor rather than a self-serve sandbox. We did not find SDKs or a published OpenAPI file. Published pricing is Plus at $3,000 per month plus $5,000 onboarding and Pro at $6,000 per month plus $10,000 onboarding, with consult fees billed separately. See /compare/myorbit-vs-telegra.
5. CareValidate: public docs, narrower scope
As of October 2026, per docs.careglp.com, CareValidate authenticates with a cv-api-key header issued from organization settings and documents cases, appointments with provider availability checks and Stripe payments, with 30+ webhook events for case changes, payments, calendar events and orders. We did not find a published signing scheme, sandbox description, SDK, contract file or versioning policy. Platform fees are not published; the site lists 3.7% payment processing. See /compare/myorbit-vs-carevalidate.
6. Wheel: enterprise API behind an engagement
Wheel sells an enterprise clinician network and API with deal-by-deal pricing and a go-live target under 90 days. As of October 2026 we could not find a developer reference at a public URL; documentation appears to be shared within an engagement. Nothing about contract, signing, sandbox or SDKs is publicly documented. If you want to read the API before the call, that is not possible today. See /compare/myorbit-vs-wheel.
7. Beluga Health: documentation on request
Beluga Health is a physician-founded white-label DTC telemedicine company with a 50-state physician network and LegitScript certification. As of October 2026, API documentation is available on request rather than at a public URL, and no public pricing is published. See /compare/myorbit-vs-beluga-health.
8. Fuse Health: API on the top plan only
Fuse Health positions itself as a peptide-first storefront. As of October 2026 it publishes Growth at $699 per month and Partner at $3,000 per month plus a 2% merchant fee on sales, with the onboarding fee not published and API access listed on the top plan only. We did not find public API documentation. See /compare/myorbit-vs-fuse-health.
9. OpenLoop: no public API reference found
OpenLoop offers enterprise full-stack telehealth support (staffing, white-label technology, payer and revenue-cycle services, licensing and credentialing) to health plans, health systems and digital health companies. As of October 2026 we found no public API documentation and no public pricing. See /compare/myorbit-vs-openloop.
What should a telehealth API actually do?
Documentation is necessary, not sufficient; the operations also have to cover the whole visit. The table below maps the operations a brand needs to what MyOrbitHealth and Cuvo document publicly as of October 2026; for the other seven, use the vendor sections above.
| Operation a brand needs | Why it matters | MyOrbitHealth (per /api-docs and /platform) | Cuvo (per developers.cuvo.co) |
|---|---|---|---|
| Create patient | Starts the chart under your brand | Documented endpoint | Documented operation |
| Capture consent | Required before a clinician reviews | Handled in Orbit Intake and the hosted flow; API detail not published | Documented operation |
| Submit intake | Adaptive questions, severity scoring, red flags | Orbit Intake, embeddable via React SDK | Case filing with intake payload |
| Match a licensed provider | State license, specialty, availability | Provider Network load balancing, 2,400+ providers | 300+ providers, case queue |
| Schedule a visit | Sync video where required | Documented appointments endpoint | Documented visits operations |
| Read prescription status | Shows the patient what was decided | Documented prescriptions endpoint | Read-only prescriptions |
| Pharmacy order and shipment events | Tracking, refill prompts | prescription.dispensed event; OrbitRx routing |
Order events through delivery |
| Labs | Provider-ordered, three draw paths | Orbit Labs (Quest/Labcorp, Tasso, mobile phlebotomy); API detail not published | Labcorp and Quest per its docs |
| Register webhooks | Event-driven backend | Documented webhook registration | Documented webhook endpoints |
The pharmacy API post explains why the prescription-to-shipment events are the hardest part of this table to get from any vendor, and what the pharmacy layer has to do underneath them.
Which auth and webhook models are safe for PHI?
Two patterns show up across the nine vendors and both can be run safely; the difference is how much you have to build.
Bearer tokens with environment-scoped keys (MyOrbitHealth, Cuvo) separate test from live at the credential level, so a developer cannot accidentally point a prototype at real patients. MyOrbitHealth returns X-RateLimit-* headers at 600 requests per minute per key with burst to 1,200; Cuvo documents RFC 9457 problem+json with request IDs.
Signed webhooks are where PHI leaks happen if you skip verification. A good scheme signs a timestamp plus the raw body with HMAC-SHA256 so a replayed or forged payload fails. MyOrbitHealth documents HMAC-SHA256 signing; Cuvo documents HMAC-SHA256 with timestamped signatures; Telegra documents v2 signature verification with secret rotation; SteadyMD uses AWS SNS signatures; CareValidate does not state a scheme in public docs. Whatever the vendor, verify before you parse, dedupe on an event ID, and treat webhooks as a hint to fetch the record rather than as the record itself.
Does the plan tier include the API?
This is where several shortlists fall apart. As of October 2026, per their public pricing:
- Cuvo includes API, webhooks and MCP on Grow ($15,000 setup plus $2,500 per month) and above, not on Launch.
- Fuse Health lists API access on its Partner plan at $3,000 per month plus 2% merchant fee.
- Telegra publishes plan prices (Plus $3,000 per month plus $5,000 onboarding; Pro $6,000 per month plus $10,000 onboarding) with consult fees billed separately; which tier includes which API features is not stated in the public docs we read.
- SteadyMD, Wheel, Beluga, OpenLoop, CareValidate quote per deal.
- MyOrbitHealth scopes a flat platform fee at onboarding to verticals, states and volume, with 0% medication markup, no revenue share and no exit fee; API, signed webhooks and the React SDK are part of the platform rather than a separately priced tier. There is no published price list.
If the API is the point of the purchase, get the tier that includes it in writing before you build.
Best for
- Cuvo Health: teams that want the largest published contract and self-serve sandbox today and can carry Grow pricing plus $25 per completed consult.
- MyOrbitHealth: brands that want a hosted clinic and an API from the same vendor, a React SDK for embedded intake, 2,400+ providers across 38+ specialties, OrbitRx and Orbit Labs behind the same keys, and a flat fee with no revenue share or exit fee.
- SteadyMD: companies that primarily need a clinician workforce with a public reference and SNS-based notifications.
- Telegra: operators comfortable with onboarding-gated credentials who want documented v2 webhooks and published plan pricing.
- CareValidate: teams whose integration need is cases, scheduling and payments more than prescribing.
- Wheel: enterprises at a scale where deal-by-deal API access and a sub-90-day go-live are acceptable.
- Beluga Health: brands that value a physician-founded network and will request documentation during evaluation.
- Fuse Health: peptide-first storefront operators who can justify the Partner plan for API access.
- OpenLoop: health plans and systems buying staffing and RCM alongside technology, not API-first builders.
How should you evaluate a telehealth API vendor?
Seven questions, in order, each answerable from public docs or one email.
- Where is the reference? If it is behind a password, ask why.
- Is there a contract file? OpenAPI or Postman lets you count operations and generate a client before signing.
- How are keys scoped? Test versus live, rotation, rate limits in headers.
- How are webhooks signed? Algorithm, timestamp, event ID, retries, polling backstop.
- How fast is the sandbox, and what does it simulate? A clinician decision and a shipment are the two events you need to fake.
- What SDKs exist and what is the deprecation window?
- Who employs the clinicians and which pharmacies fill? The API is a window into a clinic; the how to choose a white label telehealth partner guide covers the clinic questions.
Frequently asked questions
Which white label telehealth platforms have a public API?
As of October 2026, per their public docs, Cuvo Health, MyOrbitHealth, SteadyMD, Telegra and CareValidate publish readable API references. Wheel and Beluga Health share documentation within an engagement or on request, and we found no public reference for OpenLoop or Fuse Health.
What is the best telehealth API?
It depends on what you are buying. Judged only on documented developer surface, Cuvo publishes the largest contract and a self-serve sandbox. Judged on getting a hosted clinic and an API from the same vendor with a React SDK, a flat fee and no revenue share, MyOrbitHealth is the stronger fit. Read both vendors' docs before deciding.
Does MyOrbitHealth have an API?
Yes. The product REST API at api.myorbithealth.com/v1 uses bearer-token auth with test and live keys, path versioning, documented endpoints for patients, appointments, prescriptions and webhooks, HMAC-SHA256 signed webhooks and a React SDK, with a sandbox provisioned within a day. A separate free agent layer offers a 21-tool MCP server and an OpenAPI 3.1 agent API.
Does Wheel have a public API?
As of October 2026 we could not find Wheel's developer reference at a public URL. Wheel sells an enterprise clinician network and API with deal-by-deal pricing, and documentation appears to be shared during an engagement.
Which telehealth APIs offer a sandbox?
As of October 2026, per their docs, Cuvo offers self-serve test keys with simulator operations, MyOrbitHealth provisions a sandbox within a day after a short partner review, SteadyMD documents a Sandbox API section, and Telegra describes a development environment. CareValidate, Wheel, Beluga, OpenLoop and Fuse do not document a sandbox publicly.
Which plan tier includes API access?
Per public pricing as of October 2026, Cuvo includes API access on Grow and above, Fuse lists it on its Partner plan, and MyOrbitHealth includes it in the platform engagement scoped at onboarding. Telegra, SteadyMD, Wheel, Beluga, OpenLoop and CareValidate quote per deal or do not state the tier publicly.
Is there an e-prescribing API for telehealth brands?
Not directly. Prescriptions must be written by a licensed prescriber and transported over a certified network such as Surescripts, so a brand integrates with a vendor whose providers prescribe and whose pharmacies fill. MyOrbitHealth exposes prescription status and a prescription.dispensed event over its API; the prescribing itself happens inside OrbitRx.
How do you verify a telehealth API is real before signing?
Read the public reference, ask for the contract file, confirm the auth and webhook signing model, ask how quickly a sandbox is provisioned and what it simulates, and ask which plan tier includes API access. If any of those answers requires a contract first, weigh that against vendors that answer in public.
Sources
- MyOrbitHealth API docs
- MyOrbitHealth developers page
- Cuvo Integrations API documentation
- SteadyMD API documentation
- Telegra API documentation
- CareValidate API documentation
- OpenAPI Specification 3.1.0
- RFC 9457: Problem Details for HTTP APIs
Read the docs, then book the integration call
MyOrbitHealth's telehealth API and API docs are public, the agent layer at /developers needs no account, and a sandbox is provisioned within a day after a short partner review. Behind the keys are 2,400+ board-certified providers in all 50 states, OrbitRx and Orbit Labs. Book a demo to walk through the endpoints, webhook events and React SDK for your vertical.
