CMS Blue Button 2.0
Blue Button 2.0 is the Centers for Medicare & Medicaid Services (CMS) API that lets Medicare beneficiaries share their Parts A, B, and D claims data with applications they trust. It is a FHIR R4 API conforming to the CARIN Blue Button Implementation Guide (CARIN Consumer Directed Payer Data Exchange), serving ExplanationOfBenefit, Patient, and Coverage resources for 60+ million people with Medicare. Access is patient-facing - each beneficiary authorizes an app through an OAuth 2.0 authorization-code flow (with mandatory PKCE) on Medicare.gov, choosing whether to share demographic data. A self-serve sandbox with synthetic enrollee data is open to everyone; production credentials are free but require CMS approval of the application.
CMS Blue Button 2.0 publishes 5 APIs on the APIs.io network, including Coverage API, ExplanationOfBenefit API, Metadata API, and 2 more. Tagged areas include Blue Button, CARIN, Medicare, FHIR, and Claims Data.
CMS Blue Button 2.0’s developer surface includes authentication, documentation, sandbox, getting-started guide, and 8 more developer resources.
Kin Score
APIs 5
Individual APIs this provider publishes, each with its own machine-readable definition.
CMS Blue Button 2.0 Coverage API
Medicare coverage resources, one per coverage type.
CMS Blue Button 2.0 ExplanationOfBenefit API
Medicare Parts A, B, and D claims as CARIN Blue Button EOB profiles.
CMS Blue Button 2.0 Metadata API
FHIR capability statement.
CMS Blue Button 2.0 Patient API
Beneficiary demographic and administrative data.
CMS Blue Button 2.0 UserInfo API
OpenID Connect userinfo for the authorizing beneficiary.
Open Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
CMS Blue Button 2.0 API
OPEN COLLECTIONPricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Cms Blue Button Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Cms Blue Button Finops
FINOPSSecurity Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 2
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 1
The organization behind the API
Source (apis.yml)
This is an independent, third-party profile of CMS Blue Button 2.0, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.