Agent skill

Serving Openmed REST API

by maziyarpanahi in maziyarpanahi/openmed

Stand up OpenMed's FastAPI REST service for clinical NER, PII extraction, and de-identification, with health checks, model keep-alive/unload, optional dynamic batching, and no-PHI logging.

Apache-2.0Auto-check passedBackend & APIs

Install Serving Openmed REST API

skills CLI
$ npx skills add maziyarpanahi/openmed --skill serving-openmed-rest-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maziyarpanahi/openmed serving-openmed-rest-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/serving-openmed-rest-api .claude/skills/serving-openmed-rest-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
serving-openmed-rest-api
GitHub stars
5.5k
Token cost
~2.1k tokens
SKILL.md length
672 words
Files
1
Skills in repo
74
Repo updated
First seen
Licence
Apache-2.0

At a glance

Stand up OpenMed's FastAPI REST service for clinical NER, PII extraction, and de-identification, with health checks, model keep-alive/unload, optional dynamic batching, and no-PHI logging.

  • Works in 6 steps: Install + launch. pip install… → Configure the runtime via env vars… → Front it with auth/TLS. Place a reverse… → …
  • The user wants to serve OpenMed over HTTP
  • SKILL.md covers When to use this skill, Quick start, Endpoints (confirmed in… and Configuring the runtime (env…, plus 5 more sections
  • Calls uvicorn, curl and pip

What it does

Serving Openmed REST API is an agent skill from maziyarpanahi/openmed. Stand up OpenMed's FastAPI REST service for clinical NER, PII extraction, and de-identification, with health checks, model keep-alive/unload, optional dynamic batching, and no-PHI logging. Use when the user wants to serve OpenMed over HTTP, deploy a de-id/NER REST API, run an inference endpoint for clinical text, add a /analyze or /pii/deidentify route, or containerize OpenMed as a service. Covers the service extra, launching createapp with uvicorn, the real endpoints (/health, /analyze, /pii/extract…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering REST APIs, Backend development and Meeting notes and agendas. It works with FastAPI. The repository describes itself as: Local-first healthcare AI: clinical NER & HIPAA PII de-identification that runs 100% on-device. 2,200+ medical models, 21 languages, Apple MLX + Python, no cloud, no patient data…. The licence is Apache-2.0.

When your agent uses it

  • The user wants to serve OpenMed over HTTP
  • Deploy a de-id/NER REST API
  • Run an inference endpoint for clinical text
  • /pii/deidentify route

Example prompts

  • “/serving-openmed-rest-api”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Install + launch. pip install "openmed[service]", then run
  2. Configure the runtime via env vars before start: set
  3. Front it with auth/TLS. Place a reverse proxy or gateway (API keys/mTLS,
  4. Health-check + warm. Poll GET /health; preloaded models warm during
  5. Call the endpoints (/analyze, /pii/extract, /pii/deidentify) with
  6. Manage memory with GET /models/loaded and POST /models/unload as

What it can do on your machine

Read from SKILL.md and the folder at commit 6b1bb2c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uvicorn
    • curl
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • fastapi.tiangolo.com
    • uvicorn.org
    • openapis.org
    • hhs.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Serving Openmed REST API loads about 2.1k tokens when it runs. Until then it costs about 171 tokens; SKILL.md has 672 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~171
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from maziyarpanahi/openmed at commit 6b1bb2c, republished under its Apache-2.0 licence (© maziyarpanahi). 672 words, ~2,123 tokens.

Download SKILL.mdSave it as .claude/skills/serving-openmed-rest-api/SKILL.md (or your agent's skills folder).
name
serving-openmed-rest-api
description
Stand up OpenMed's FastAPI REST service for clinical NER, PII extraction, and de-identification, with health checks, model keep-alive/unload, optional dynamic batching, and no-PHI logging. Use when the user wants to serve OpenMed over HTTP, deploy a de-id/NER REST API, run an inference endpoint for clinical text, add a /analyze or /pii/deidentify route, or containerize OpenMed as a service. Covers the service extra, launching create_app with uvicorn, the real endpoints (/health, /analyze, /pii/extract, /pii/deidentify, /models/loaded, /models/unload), request/response shapes, ServiceRuntime env-var configuration, and self-hosted auth/CORS/TLS notes.
license
Apache-2.0
metadata.project
OpenMed
metadata.category
deployment-ops
metadata.pairs
adjacent
metadata.version
1.0

Serving OpenMed over REST

openmed.service is a hardened FastAPI app exposing OpenMed's NER, PII extraction, and de-identification over HTTP. It is built to be self-hosted: models run on-device, there's no telemetry, and the request schemas reject raw PHI from spilling into errors. Use it when callers need request/response inference; use batch-processing-clinical-text for corpora.

When to use this skill

To put OpenMed behind an HTTP endpoint your own apps call — an internal de-id microservice, an NER backend, a containerized inference tier. For agent/tool integration prefer the MCP server (deploying-openmed-mcp); for offline bulk work use batch processing.

Quick start

bash
pip install "openmed[service]"          # FastAPI + uvicorn + pydantic

# Launch the ASGI app (factory create_app, or the module-level `app`)
uvicorn openmed.service.app:app --host 127.0.0.1 --port 8000
python
# Or build it in-process (e.g. to mount under a parent app / add middleware):
from openmed.service import create_app
app = create_app()
bash
curl -s localhost:8000/health
# {"status":"ok","service":"openmed-rest","version":"...","profile":"prod"}

curl -s localhost:8000/analyze -H 'content-type: application/json' -d '{
  "text": "Patient received 75mg clopidogrel for NSTEMI.",
  "model_name": "disease_detection_superclinical"
}'

curl -s localhost:8000/pii/deidentify -H 'content-type: application/json' -d '{
  "text": "John Doe called 555-123-4567 on 01/15/2020.",
  "method": "mask"
}'

Endpoints (confirmed in openmed/service/app.py)

Method & pathPurposeRequest schema
GET /healthliveness + version + active profile—
GET /models/loadedcache/keep-alive status of resident models—
POST /models/unloadunload one model or all inactive modelsModelUnloadRequest (model_name or all=true)
POST /analyzeclinical NERAnalyzeRequest
POST /pii/extractdetect PII/PHI spansPIIExtractRequest
POST /pii/deidentifymask/remove/replace/hash/shift-dates PHIPIIDeidentifyRequest

Request fields (from openmed/service/schemas.py, strict — unknown fields are rejected):

  • AnalyzeRequest: text (required), model_name ("disease_detection_superclinical"), confidence_threshold (0.0), group_entities, aggregation_strategy (simple|first|average|max), sentence_detection, sentence_language, sentence_clean, use_fast_tokenizer, keep_alive.
  • PIIExtractRequest: text, model_name (default OpenMed/OpenMed-PII-SuperClinical-Small-44M-v1), confidence_threshold (0.5), use_smart_merging, lang (en/fr/de/it/es/nl/hi/te/pt/ar/ja/tr), normalize_accents, keep_alive.
  • PIIDeidentifyRequest: same base plus method (mask|remove|replace|hash|shift_dates, default mask), confidence_threshold (0.7), keep_year, shift_dates, date_shift_days, keep_mapping, policy, use_smart_merging, use_safety_sweep.

Responses are the OpenMed result to_dict() (e.g. {text, entities[...], ...}). Errors use a stable envelope: {"error": {"code", "message", "details"}} with 422 validation_error, 400 bad_request, 504 timeout, 500 internal_error.

Configuring the runtime (env vars)

ServiceRuntime.from_env() reads the process environment at startup (openmed/service/runtime.py):

Env varEffect
OPENMED_PROFILEconfig profile (prod default)
OPENMED_SERVICE_PRELOAD_MODELScomma list of models to warm at startup
OPENMED_SERVICE_KEEP_ALIVEdefault idle keep-alive before unload
OPENMED_SERVICE_MAX_RESIDENT_MODELScap resident models (warm pool)
OPENMED_SERVICE_BATCHING_ENABLEDenable dynamic request batching
OPENMED_SERVICE_BATCH_MAX_SIZEmax dynamic batch size (default 8)
OPENMED_SERVICE_BATCH_MAX_WAIT_MSbatch-collection window (default 5ms)
bash
OPENMED_SERVICE_PRELOAD_MODELS="disease_detection_superclinical" \
OPENMED_SERVICE_BATCHING_ENABLED=true \
uvicorn openmed.service.app:app --host 0.0.0.0 --port 8000

Preloading avoids first-request latency; the warm pool keeps hot models resident and idle-unloads the rest. /analyze and /pii/extract coalesce concurrent requests when batching is enabled.

Workflow

  1. Install + launch. pip install "openmed[service]", then run uvicorn openmed.service.app:app (or build with create_app()).
  2. Configure the runtime via env vars before start: set OPENMED_PROFILE, preload your hot models, and decide keep-alive / max resident / batching to fit the box.
  3. Front it with auth/TLS. Place a reverse proxy or gateway (API keys/mTLS, CORS allow-list) ahead of the app — it has none built in.
  4. Health-check + warm. Poll GET /health; preloaded models warm during the lifespan startup so the first real request isn't cold.
  5. Call the endpoints (/analyze, /pii/extract, /pii/deidentify) with the strict JSON schemas; handle the {"error": {...}} envelope.
  6. Manage memory with GET /models/loaded and POST /models/unload as traffic shifts between models.
Show full SKILL.md (246 more words)Show less

Containerizing

dockerfile
FROM python:3.11-slim
RUN pip install --no-cache-dir "openmed[service]"
ENV OPENMED_SERVICE_PRELOAD_MODELS="disease_detection_superclinical"
EXPOSE 8000
CMD ["uvicorn", "openmed.service.app:app", "--host", "0.0.0.0", "--port", "8000"]

Bake/mount the model cache so containers don't re-download on every start; the service runs offline after that.

Hand-off to / from OpenMed

  • Same engine, different surface: /analyze → openmed.analyze_text, /pii/extract → openmed.extract_pii, /pii/deidentify → openmed.deidentify. Results match the library exactly.
  • Agents/tools: for Claude Code / Codex / chat clients, expose the same capabilities as MCP tools instead (deploying-openmed-mcp).
  • Bulk: for corpora, call batch-processing-clinical-text in a worker, not per-request HTTP.

Edge cases & gotchas

  • No built-in auth/CORS/TLS. The app ships hardened input validation but no authentication. Put it behind your own reverse proxy / API gateway (mTLS, API keys, CORS allow-list) before any real traffic. Bind 127.0.0.1 for local use; only expose 0.0.0.0 behind that proxy.
  • No-PHI logging. Don't add request/response body logging — that's PHI. The error envelope is designed to avoid echoing input; keep it that way. Log status codes, timings, and model names only.
  • Strict schemas. Unknown JSON fields are rejected (extra="forbid"); a bad lang/method/model_name returns 422/400 with a field-level reason.
  • Cold start vs memory. Preloading + a high MAX_RESIDENT_MODELS trades RAM for latency; tune to the box.
  • Timeouts return 504 per the profile's configured timeout; long inputs may need a larger profile or pre-chunking.
  • keep_mapping/policy outputs are sensitive. A de-id response with a mapping re-identifies patients — only enable it for trusted callers and store the mapping securely, never in service logs.

Standards & references

© maziyarpanahi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/serving-openmed-rest-api of maziyarpanahi/openmed.

Open the folder on GitHubat commit 6b1bb2c

Compare with similar skills

Serving Openmed REST API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Serving Openmed REST API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Serving Openmed REST API this skillmaziyarpanahi/openmed5.5k—~2.1kAutomated safety check: PassApache-2.0
Fastcrudbenavlabs/fastcrud1.6k—~5kAutomated safety check: PassMIT
Readme Generator Probeizhi23/README-Generator-Pro113—~472Automated safety check: NotesNone
FastAPI Project Templateswshobson/agents40k11 repos~901Automated safety check: PassMIT
Fastapi REST API Designopen-edge-platform/anomalib6.2k—~838Automated safety check: PassApache-2.0
FastAPI ExpertJeffallan/claude-skills12k—~1.8kAutomated safety check: PassMIT

Similar skills

  • Fastcrud

    benavlabs/fastcrud

    A skill your agent uses when building or modifying CRUD endpoints with FastCRUD (the fastcrud PyPI package) in a FastAPI project — covers FastCRUD, crudrouter, EndpointCreator, FilterConfig…

    1.6k GitHub stars~5k tokensUpdated 14 days ago
    Backend & APIsAuto-check passed
  • Readme Generator Pro

    beizhi23/README-Generator-Pro

    Generate, modify, and render professional README.md files and project introduction HTML pages using the bundled README Generator Pro FastAPI application.

    113 GitHub stars~472 tokensUpdated 3 mo ago
    Backend & APIsAuto-check: notes
  • Scaffolds FastAPI projects with a layered app layout, dependency injection through Depends, async handlers and database access, middleware and pytest setup.

    40k GitHub starsUsed in 11 repos~901 tokens
    Backend & APIsAuto-check passed
  • Fastapi REST API Design

    open-edge-platform/anomalib

    Designs and reviews REST APIs for FastAPI services using consistent resource naming, HTTP semantics, validation, security, and error handling patterns.

    6.2k GitHub stars~838 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • FastAPI Expert

    Jeffallan/claude-skills

    Builds async Python APIs with FastAPI and Pydantic V2, covering endpoints, JWT authentication, async SQLAlchemy, WebSockets and pytest checks against the OpenAPI docs.

    12k GitHub stars~1.8k tokensUpdated 6 days ago
    Backend & APIsAuto-check passed
  • Python Fastapi Patterns

    aiskillstore/marketplace

    FastAPI web framework patterns. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~1.3k tokens
    Backend & APIsAuto-check: notes

More from maziyarpanahi/openmed

All 74 skills in this repo
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • OpenMed Model Card Writer

    maziyarpanahi/openmed

    Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.

    5.5k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • ICD-10 Coding Assistant

    maziyarpanahi/openmed

    Suggests candidate ICD-10-CM diagnosis and ICD-10-PCS procedure codes for clinical text extracted by OpenMed, with rationale for a certified coder to review.

    5.5k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • OpenMed ETL to OMOP CDM

    maziyarpanahi/openmed

    Maps OpenMed-extracted, terminology-coded conditions, drugs and measurements into OMOP CDM v5.4 tables for OHDSI and ATLAS analytics.

    5.5k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Extracting SDOH and Z-Codes

    maziyarpanahi/openmed

    Finds social risks such as housing instability or food insecurity in clinical notes and proposes matching ICD-10-CM Z-codes for a coder to confirm.

    5.5k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Serving Openmed REST API

What does Serving Openmed REST API do?

Stand up OpenMed's FastAPI REST service for clinical NER, PII extraction, and de-identification, with health checks, model keep-alive/unload, optional dynamic batching, and no-PHI logging. Serving Openmed REST API is an agent skill from maziyarpanahi/openmed. Stand up OpenMed's FastAPI REST service for clinical NER, PII extraction, and de-identification, with health checks, model keep-alive/unload, optional dynamic batching, and no-PHI logging.

When should I use Serving Openmed REST API?

Serving Openmed REST API fits situations like: the user wants to serve OpenMed over HTTP; deploy a de-id/NER REST API; run an inference endpoint for clinical text; /pii/deidentify route.

How do I install Serving Openmed REST API in Claude Code?

Run `npx skills add maziyarpanahi/openmed --skill serving-openmed-rest-api -a claude-code`. Or copy the skill folder (skills/serving-openmed-rest-api in maziyarpanahi/openmed) into .claude/skills/serving-openmed-rest-api in your project. Claude Code loads it when a task matches its description.

How do I install Serving Openmed REST API in Codex?

Run `npx skills add maziyarpanahi/openmed --skill serving-openmed-rest-api -a codex`. Or copy the skill folder (skills/serving-openmed-rest-api in maziyarpanahi/openmed) into .agents/skills/serving-openmed-rest-api in your project. Codex loads it when a task matches its description.

Can I use Serving Openmed REST API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maziyarpanahi/openmed --skill serving-openmed-rest-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/serving-openmed-rest-api, .gemini/skills/serving-openmed-rest-api, .github/skills/serving-openmed-rest-api and .opencode/skills/serving-openmed-rest-api in your project.

What does Serving Openmed REST API need to run?

Going by SKILL.md and its folder, Serving Openmed REST API needs the command-line tools its instructions call (uvicorn, curl and pip). Our summary lists: Python 3.

Does Serving Openmed REST API access the network?

SKILL.md names 4 domains. As links in the text: fastapi.tiangolo.com, uvicorn.org, openapis.org and hhs.gov. This is read from the text; nothing was executed.

Is Serving Openmed REST API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Serving Openmed REST API use?

Serving Openmed REST API is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Serving Openmed REST API use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Serving Openmed REST API?

Skills that share tags, products or a category with Serving Openmed REST API: Fastcrud (benavlabs/fastcrud, 1.6k stars), Readme Generator Pro (beizhi23/README-Generator-Pro, 113 stars), FastAPI Project Templates (wshobson/agents, 40k stars) and Fastapi REST API Design (open-edge-platform/anomalib, 6.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Serving Openmed REST API?

maziyarpanahi (a GitHub user) maintains it in maziyarpanahi/openmed, which has 5,493 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on October 9, 2026.

Source: maziyarpanahi/openmed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.