Use the UDAP security framework for B2B FHIR access to dynamically register a client application with a health system's UDAP-enabled authorization server

domain: hl7.org/fhir/us/udap-security · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Fetch the server's UDAP metadata from .well-known/udap on the FHIR base URL to discover udap_versions_supported, registration_endpoint, and grant_types_supported
  2. Build a signed software statement JWT containing client_name, redirect_uris, grant_types, scope, and iss equal to the client's UDAP subject alternative name (SAN) from its X.509 certificate
  3. Sign the software statement with the client's private key; include the full X.509 certificate chain in the x5c header
  4. POST to the registration_endpoint with the software statement; receive a client_id in the response — store it for subsequent token requests
  5. Use the registered client_id with a signed client_assertion JWT to authenticate at the token endpoint in subsequent access token requests

Known gotchas

Related routes

Implement SMART on FHIR standalone launch with authorization code flow and PKCE
smart-on-fhir · 6 steps · unrated
Authenticate a backend service for FHIR Bulk Data access using SMART Backend Services client credentials flow
hl7.org/fhir · 5 steps · unrated
Implement IHE PMIR (Patient Master Identity Registry) Mobile Patient Identity Feed to publish patient identity create/update/merge events using FHIR
healthcare · 6 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans