Skip to main content
Every call is a POST to one endpoint, with a bearer token:
The endpoint supports introspection, so you can point GraphiQL, Postman or your code generator at it to browse the schema or generate types.

A first call

The Sync patients guide has a small Node.js client that caches the machine token.

Metadata

Every mutation takes a metadata argument that says who is calling. Photon uses it for audit logs and support. source is one of DIRECT_API, WEB_APP, EMBEDDABLE_COMPONENT, MCP_CONNECTOR or LLM_AGENT.
Set client and requestId. When you contact support, they’re the fastest way for us to find your calls.

The result

Each mutation returns a union, so always select __typename and branch on it: Both errors implement OperationError, so you can select them together:
See Errors for the full checklist.