Implement SMART App Launch v2 granular scopes for patient-specific Observation access

domain: hl7.org/fhir/smart-app-launch · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Register the application with the authorization server declaring granular v2 scopes such as 'patient/Observation.rs' to request read and search on Observation
  2. Initiate the authorization code flow, requesting the necessary granular scopes in the scope parameter
  3. After token exchange, inspect the token response to confirm which scopes were actually granted, as the server may downscope the request
  4. Use the access token to query the FHIR server; expect the server to enforce the granted scopes and return only resources within scope
  5. Handle scope denial gracefully by prompting the user to re-authorize with adjusted scope requests if critical scopes were denied

Known gotchas

Related routes

Use SMART App Launch v2 granular scopes (e.g., patient/Observation.rs, user/MedicationRequest.cruds) to request fine-grained access to specific FHIR resource types and operations
smarthealthit.org · 5 steps · unrated
implement a SMART on FHIR standalone launch flow with OAuth2 and patient/*.read scopes
fhir · 6 steps · unrated
Implement SMART App Launch v2 token introspection to validate an access token issued by an authorization server and extract the scopes and patient context at a resource server
hl7.org/fhir/smart-app-launch · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans