Oracle Health (Cerner) · OAuth Scopes

Oracle Health (Cerner) OAuth Scopes

OAuth 2.0 probed

Oracle Health (Cerner) publishes 303 OAuth 2.0 scopes via the authorizationCode and clientCredentials flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Oracle Health (Cerner) API on a user’s behalf.

Tokens are issued from https://authorization.cerner.com/tenants/{tenant}/hosts/fhir-ehr-code.cerner.com/protocols/oauth2/profiles/smart-v1/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

Bulk FHIRCapabilityStatementCareAwareCerner MillenniumClinical DataCode ConsoleEHRElectronic Health RecordsFHIRFortune 1000HL7HL7v2HealthcareInteroperabilityMillennium PlatformMulti-TenantAuthenticationOracleOracle HealthPatient AccessProvider DirectorySMART Backend ServicesSMART on FHIRUS Core
Scopes: 303 Flows: authorizationCode, clientCredentials Method: probed

OAuth endpoints

Authorization URL
https://authorization.cerner.com/tenants/{tenant}/protocols/oauth2/profiles/smart-v1/personas/provider/authorize
Token URL
https://authorization.cerner.com/tenants/{tenant}/hosts/fhir-ehr-code.cerner.com/protocols/oauth2/profiles/smart-v1/token
Flows
authorizationCodeclientCredentials

Scopes (303)

ScopeDescriptionFlows
fhirUser Returns the FHIR resource (Practitioner/Patient/RelatedPerson) representing the authorizing user. authorizationCode
launch EHR launch context — the app is launched from inside PowerChart and inherits patient/encounter context. authorizationCode
offline_access Issues a refresh token that outlives the user session. authorizationCode
online_access Issues a refresh token bound to the user session. authorizationCode
openid OpenID Connect authentication; returns an id_token identifying the authorizing user. authorizationCode
patient/Account.read Allows read (search + read) on the Account resource for the patient in context. authorizationCode
patient/Account.rs Allows SMART v2 permissions: read, search on the Account resource for the patient in context. authorizationCode
patient/AllergyIntolerance.crus Allows SMART v2 permissions: create, read, update, search on the AllergyIntolerance resource for the patient in context. authorizationCode
patient/AllergyIntolerance.read Allows read (search + read) on the AllergyIntolerance resource for the patient in context. authorizationCode
patient/AllergyIntolerance.write Allows write (create + update) on the AllergyIntolerance resource for the patient in context. authorizationCode
patient/Appointment.crus Allows SMART v2 permissions: create, read, update, search on the Appointment resource for the patient in context. authorizationCode
patient/Appointment.read Allows read (search + read) on the Appointment resource for the patient in context. authorizationCode
patient/Appointment.write Allows write (create + update) on the Appointment resource for the patient in context. authorizationCode
patient/Basic.c Allows SMART v2 permissions: create on the Basic resource for the patient in context. authorizationCode
patient/Basic.write Allows write (create + update) on the Basic resource for the patient in context. authorizationCode
patient/Binary.r Allows SMART v2 permissions: read on the Binary resource for the patient in context. authorizationCode
patient/Binary.read Allows read (search + read) on the Binary resource for the patient in context. authorizationCode
patient/CarePlan.read Allows read (search + read) on the CarePlan resource for the patient in context. authorizationCode
patient/CarePlan.rs Allows SMART v2 permissions: read, search on the CarePlan resource for the patient in context. authorizationCode
patient/CareTeam.read Allows read (search + read) on the CareTeam resource for the patient in context. authorizationCode
patient/CareTeam.rs Allows SMART v2 permissions: read, search on the CareTeam resource for the patient in context. authorizationCode
patient/ChargeItem.crs Allows SMART v2 permissions: create, read, search on the ChargeItem resource for the patient in context. authorizationCode
patient/ChargeItem.read Allows read (search + read) on the ChargeItem resource for the patient in context. authorizationCode
patient/ChargeItem.write Allows write (create + update) on the ChargeItem resource for the patient in context. authorizationCode
patient/Communication.crus Allows SMART v2 permissions: create, read, update, search on the Communication resource for the patient in context. authorizationCode
patient/Communication.read Allows read (search + read) on the Communication resource for the patient in context. authorizationCode
patient/Communication.write Allows write (create + update) on the Communication resource for the patient in context. authorizationCode
patient/Condition.crus Allows SMART v2 permissions: create, read, update, search on the Condition resource for the patient in context. authorizationCode
patient/Condition.read Allows read (search + read) on the Condition resource for the patient in context. authorizationCode
patient/Condition.write Allows write (create + update) on the Condition resource for the patient in context. authorizationCode
patient/Consent.read Allows read (search + read) on the Consent resource for the patient in context. authorizationCode
patient/Consent.rs Allows SMART v2 permissions: read, search on the Consent resource for the patient in context. authorizationCode
patient/Coverage.cruds Allows SMART v2 permissions: create, read, update, delete, search on the Coverage resource for the patient in context. authorizationCode
patient/Coverage.read Allows read (search + read) on the Coverage resource for the patient in context. authorizationCode
patient/Coverage.write Allows write (create + update) on the Coverage resource for the patient in context. authorizationCode
patient/Device.read Allows read (search + read) on the Device resource for the patient in context. authorizationCode
patient/Device.rs Allows SMART v2 permissions: read, search on the Device resource for the patient in context. authorizationCode
patient/DiagnosticReport.crs Allows SMART v2 permissions: create, read, search on the DiagnosticReport resource for the patient in context. authorizationCode
patient/DiagnosticReport.read Allows read (search + read) on the DiagnosticReport resource for the patient in context. authorizationCode
patient/DiagnosticReport.write Allows write (create + update) on the DiagnosticReport resource for the patient in context. authorizationCode
patient/DocumentReference.crus Allows SMART v2 permissions: create, read, update, search on the DocumentReference resource for the patient in context. authorizationCode
patient/DocumentReference.read Allows read (search + read) on the DocumentReference resource for the patient in context. authorizationCode
patient/DocumentReference.write Allows write (create + update) on the DocumentReference resource for the patient in context. authorizationCode
patient/Encounter.crus Allows SMART v2 permissions: create, read, update, search on the Encounter resource for the patient in context. authorizationCode
patient/Encounter.read Allows read (search + read) on the Encounter resource for the patient in context. authorizationCode
patient/Encounter.write Allows write (create + update) on the Encounter resource for the patient in context. authorizationCode
patient/FamilyMemberHistory.crus Allows SMART v2 permissions: create, read, update, search on the FamilyMemberHistory resource for the patient in context. authorizationCode
patient/FamilyMemberHistory.read Allows read (search + read) on the FamilyMemberHistory resource for the patient in context. authorizationCode
patient/FamilyMemberHistory.write Allows write (create + update) on the FamilyMemberHistory resource for the patient in context. authorizationCode
patient/Goal.read Allows read (search + read) on the Goal resource for the patient in context. authorizationCode
patient/Goal.rs Allows SMART v2 permissions: read, search on the Goal resource for the patient in context. authorizationCode
patient/Immunization.crus Allows SMART v2 permissions: create, read, update, search on the Immunization resource for the patient in context. authorizationCode
patient/Immunization.read Allows read (search + read) on the Immunization resource for the patient in context. authorizationCode
patient/Immunization.write Allows write (create + update) on the Immunization resource for the patient in context. authorizationCode
patient/InsurancePlan.read Allows read (search + read) on the InsurancePlan resource for the patient in context. authorizationCode
patient/InsurancePlan.rs Allows SMART v2 permissions: read, search on the InsurancePlan resource for the patient in context. authorizationCode
patient/Media.r Allows SMART v2 permissions: read on the Media resource for the patient in context. authorizationCode
patient/Media.read Allows read (search + read) on the Media resource for the patient in context. authorizationCode
patient/MedicationAdministration.read Allows read (search + read) on the MedicationAdministration resource for the patient in context. authorizationCode
patient/MedicationAdministration.rs Allows SMART v2 permissions: read, search on the MedicationAdministration resource for the patient in context. authorizationCode
patient/MedicationDispense.read Allows read (search + read) on the MedicationDispense resource for the patient in context. authorizationCode
patient/MedicationDispense.rs Allows SMART v2 permissions: read, search on the MedicationDispense resource for the patient in context. authorizationCode
patient/MedicationRequest.crus Allows SMART v2 permissions: create, read, update, search on the MedicationRequest resource for the patient in context. authorizationCode
patient/MedicationRequest.read Allows read (search + read) on the MedicationRequest resource for the patient in context. authorizationCode
patient/MedicationRequest.write Allows write (create + update) on the MedicationRequest resource for the patient in context. authorizationCode
patient/NutritionOrder.read Allows read (search + read) on the NutritionOrder resource for the patient in context. authorizationCode
patient/NutritionOrder.rs Allows SMART v2 permissions: read, search on the NutritionOrder resource for the patient in context. authorizationCode
patient/Observation.crus Allows SMART v2 permissions: create, read, update, search on the Observation resource for the patient in context. authorizationCode
patient/Observation.read Allows read (search + read) on the Observation resource for the patient in context. authorizationCode
patient/Observation.write Allows write (create + update) on the Observation resource for the patient in context. authorizationCode
patient/Patient.crus Allows SMART v2 permissions: create, read, update, search on the Patient resource for the patient in context. authorizationCode
patient/Patient.read Allows read (search + read) on the Patient resource for the patient in context. authorizationCode
patient/Patient.write Allows write (create + update) on the Patient resource for the patient in context. authorizationCode
patient/Person.read Allows read (search + read) on the Person resource for the patient in context. authorizationCode
patient/Person.rs Allows SMART v2 permissions: read, search on the Person resource for the patient in context. authorizationCode
patient/Procedure.crs Allows SMART v2 permissions: create, read, search on the Procedure resource for the patient in context. authorizationCode
patient/Procedure.read Allows read (search + read) on the Procedure resource for the patient in context. authorizationCode
patient/Procedure.write Allows write (create + update) on the Procedure resource for the patient in context. authorizationCode
patient/Provenance.crs Allows SMART v2 permissions: create, read, search on the Provenance resource for the patient in context. authorizationCode
patient/Provenance.read Allows read (search + read) on the Provenance resource for the patient in context. authorizationCode
patient/Provenance.write Allows write (create + update) on the Provenance resource for the patient in context. authorizationCode
patient/Questionnaire.read Allows read (search + read) on the Questionnaire resource for the patient in context. authorizationCode
patient/Questionnaire.rs Allows SMART v2 permissions: read, search on the Questionnaire resource for the patient in context. authorizationCode
patient/QuestionnaireResponse.read Allows read (search + read) on the QuestionnaireResponse resource for the patient in context. authorizationCode
patient/QuestionnaireResponse.rus Allows SMART v2 permissions: read, update, search on the QuestionnaireResponse resource for the patient in context. authorizationCode
patient/QuestionnaireResponse.write Allows write (create + update) on the QuestionnaireResponse resource for the patient in context. authorizationCode
patient/RelatedPerson.crus Allows SMART v2 permissions: create, read, update, search on the RelatedPerson resource for the patient in context. authorizationCode
patient/RelatedPerson.read Allows read (search + read) on the RelatedPerson resource for the patient in context. authorizationCode
patient/RelatedPerson.write Allows write (create + update) on the RelatedPerson resource for the patient in context. authorizationCode
patient/Schedule.read Allows read (search + read) on the Schedule resource for the patient in context. authorizationCode
patient/Schedule.rs Allows SMART v2 permissions: read, search on the Schedule resource for the patient in context. authorizationCode
patient/ServiceRequest.read Allows read (search + read) on the ServiceRequest resource for the patient in context. authorizationCode
patient/ServiceRequest.rs Allows SMART v2 permissions: read, search on the ServiceRequest resource for the patient in context. authorizationCode
patient/Slot.read Allows read (search + read) on the Slot resource for the patient in context. authorizationCode
patient/Slot.rus Allows SMART v2 permissions: read, update, search on the Slot resource for the patient in context. authorizationCode
patient/Slot.write Allows write (create + update) on the Slot resource for the patient in context. authorizationCode
patient/Specimen.read Allows read (search + read) on the Specimen resource for the patient in context. authorizationCode
patient/Specimen.rs Allows SMART v2 permissions: read, search on the Specimen resource for the patient in context. authorizationCode
profile SMART on FHIR scope advertised by the tenant: profile authorizationCode
system/Account.read Allows read (search + read) on the Account resource for the backend service (no user). clientCredentials
system/Account.rs Allows SMART v2 permissions: read, search on the Account resource for the backend service (no user). clientCredentials
system/AllergyIntolerance.crus Allows SMART v2 permissions: create, read, update, search on the AllergyIntolerance resource for the backend service (no user). clientCredentials
system/AllergyIntolerance.read Allows read (search + read) on the AllergyIntolerance resource for the backend service (no user). clientCredentials
system/AllergyIntolerance.write Allows write (create + update) on the AllergyIntolerance resource for the backend service (no user). clientCredentials
system/Appointment.crus Allows SMART v2 permissions: create, read, update, search on the Appointment resource for the backend service (no user). clientCredentials
system/Appointment.read Allows read (search + read) on the Appointment resource for the backend service (no user). clientCredentials
system/Appointment.write Allows write (create + update) on the Appointment resource for the backend service (no user). clientCredentials
system/Basic.c Allows SMART v2 permissions: create on the Basic resource for the backend service (no user). clientCredentials
system/Basic.write Allows write (create + update) on the Basic resource for the backend service (no user). clientCredentials
system/Binary.r Allows SMART v2 permissions: read on the Binary resource for the backend service (no user). clientCredentials
system/Binary.read Allows read (search + read) on the Binary resource for the backend service (no user). clientCredentials
system/CarePlan.read Allows read (search + read) on the CarePlan resource for the backend service (no user). clientCredentials
system/CarePlan.rs Allows SMART v2 permissions: read, search on the CarePlan resource for the backend service (no user). clientCredentials
system/CareTeam.read Allows read (search + read) on the CareTeam resource for the backend service (no user). clientCredentials
system/CareTeam.rs Allows SMART v2 permissions: read, search on the CareTeam resource for the backend service (no user). clientCredentials
system/ChargeItem.crs Allows SMART v2 permissions: create, read, search on the ChargeItem resource for the backend service (no user). clientCredentials
system/ChargeItem.read Allows read (search + read) on the ChargeItem resource for the backend service (no user). clientCredentials
system/ChargeItem.write Allows write (create + update) on the ChargeItem resource for the backend service (no user). clientCredentials
system/Communication.crus Allows SMART v2 permissions: create, read, update, search on the Communication resource for the backend service (no user). clientCredentials
system/Communication.read Allows read (search + read) on the Communication resource for the backend service (no user). clientCredentials
system/Communication.write Allows write (create + update) on the Communication resource for the backend service (no user). clientCredentials
system/Condition.crus Allows SMART v2 permissions: create, read, update, search on the Condition resource for the backend service (no user). clientCredentials
system/Condition.read Allows read (search + read) on the Condition resource for the backend service (no user). clientCredentials
system/Condition.write Allows write (create + update) on the Condition resource for the backend service (no user). clientCredentials
system/Consent.read Allows read (search + read) on the Consent resource for the backend service (no user). clientCredentials
system/Consent.rs Allows SMART v2 permissions: read, search on the Consent resource for the backend service (no user). clientCredentials
system/Coverage.cruds Allows SMART v2 permissions: create, read, update, delete, search on the Coverage resource for the backend service (no user). clientCredentials
system/Coverage.read Allows read (search + read) on the Coverage resource for the backend service (no user). clientCredentials
system/Coverage.write Allows write (create + update) on the Coverage resource for the backend service (no user). clientCredentials
system/Device.read Allows read (search + read) on the Device resource for the backend service (no user). clientCredentials
system/Device.rs Allows SMART v2 permissions: read, search on the Device resource for the backend service (no user). clientCredentials
system/DiagnosticReport.crs Allows SMART v2 permissions: create, read, search on the DiagnosticReport resource for the backend service (no user). clientCredentials
system/DiagnosticReport.read Allows read (search + read) on the DiagnosticReport resource for the backend service (no user). clientCredentials
system/DiagnosticReport.write Allows write (create + update) on the DiagnosticReport resource for the backend service (no user). clientCredentials
system/DocumentReference.crus Allows SMART v2 permissions: create, read, update, search on the DocumentReference resource for the backend service (no user). clientCredentials
system/DocumentReference.read Allows read (search + read) on the DocumentReference resource for the backend service (no user). clientCredentials
system/DocumentReference.write Allows write (create + update) on the DocumentReference resource for the backend service (no user). clientCredentials
system/Encounter.crus Allows SMART v2 permissions: create, read, update, search on the Encounter resource for the backend service (no user). clientCredentials
system/Encounter.read Allows read (search + read) on the Encounter resource for the backend service (no user). clientCredentials
system/Encounter.write Allows write (create + update) on the Encounter resource for the backend service (no user). clientCredentials
system/FamilyMemberHistory.crus Allows SMART v2 permissions: create, read, update, search on the FamilyMemberHistory resource for the backend service (no user). clientCredentials
system/FamilyMemberHistory.read Allows read (search + read) on the FamilyMemberHistory resource for the backend service (no user). clientCredentials
system/FamilyMemberHistory.write Allows write (create + update) on the FamilyMemberHistory resource for the backend service (no user). clientCredentials
system/FinancialTransaction.c Allows SMART v2 permissions: create on the FinancialTransaction resource for the backend service (no user). clientCredentials
system/FinancialTransaction.write Allows write (create + update) on the FinancialTransaction resource for the backend service (no user). clientCredentials
system/Goal.read Allows read (search + read) on the Goal resource for the backend service (no user). clientCredentials
system/Goal.rs Allows SMART v2 permissions: read, search on the Goal resource for the backend service (no user). clientCredentials
system/Immunization.crus Allows SMART v2 permissions: create, read, update, search on the Immunization resource for the backend service (no user). clientCredentials
system/Immunization.read Allows read (search + read) on the Immunization resource for the backend service (no user). clientCredentials
system/Immunization.write Allows write (create + update) on the Immunization resource for the backend service (no user). clientCredentials
system/InsurancePlan.read Allows read (search + read) on the InsurancePlan resource for the backend service (no user). clientCredentials
system/InsurancePlan.rs Allows SMART v2 permissions: read, search on the InsurancePlan resource for the backend service (no user). clientCredentials
system/Location.read Allows read (search + read) on the Location resource for the backend service (no user). clientCredentials
system/Location.rs Allows SMART v2 permissions: read, search on the Location resource for the backend service (no user). clientCredentials
system/Media.r Allows SMART v2 permissions: read on the Media resource for the backend service (no user). clientCredentials
system/Media.read Allows read (search + read) on the Media resource for the backend service (no user). clientCredentials
system/MedicationAdministration.read Allows read (search + read) on the MedicationAdministration resource for the backend service (no user). clientCredentials
system/MedicationAdministration.rs Allows SMART v2 permissions: read, search on the MedicationAdministration resource for the backend service (no user). clientCredentials
system/MedicationDispense.read Allows read (search + read) on the MedicationDispense resource for the backend service (no user). clientCredentials
system/MedicationDispense.rs Allows SMART v2 permissions: read, search on the MedicationDispense resource for the backend service (no user). clientCredentials
system/MedicationRequest.crus Allows SMART v2 permissions: create, read, update, search on the MedicationRequest resource for the backend service (no user). clientCredentials
system/MedicationRequest.read Allows read (search + read) on the MedicationRequest resource for the backend service (no user). clientCredentials
system/MedicationRequest.write Allows write (create + update) on the MedicationRequest resource for the backend service (no user). clientCredentials
system/NutritionOrder.read Allows read (search + read) on the NutritionOrder resource for the backend service (no user). clientCredentials
system/NutritionOrder.rs Allows SMART v2 permissions: read, search on the NutritionOrder resource for the backend service (no user). clientCredentials
system/Observation.crus Allows SMART v2 permissions: create, read, update, search on the Observation resource for the backend service (no user). clientCredentials
system/Observation.read Allows read (search + read) on the Observation resource for the backend service (no user). clientCredentials
system/Observation.write Allows write (create + update) on the Observation resource for the backend service (no user). clientCredentials
system/Organization.crs Allows SMART v2 permissions: create, read, search on the Organization resource for the backend service (no user). clientCredentials
system/Organization.read Allows read (search + read) on the Organization resource for the backend service (no user). clientCredentials
system/Organization.write Allows write (create + update) on the Organization resource for the backend service (no user). clientCredentials
system/Patient.crus Allows SMART v2 permissions: create, read, update, search on the Patient resource for the backend service (no user). clientCredentials
system/Patient.read Allows read (search + read) on the Patient resource for the backend service (no user). clientCredentials
system/Patient.write Allows write (create + update) on the Patient resource for the backend service (no user). clientCredentials
system/Person.read Allows read (search + read) on the Person resource for the backend service (no user). clientCredentials
system/Person.rs Allows SMART v2 permissions: read, search on the Person resource for the backend service (no user). clientCredentials
system/Practitioner.crs Allows SMART v2 permissions: create, read, search on the Practitioner resource for the backend service (no user). clientCredentials
system/Practitioner.read Allows read (search + read) on the Practitioner resource for the backend service (no user). clientCredentials
system/Practitioner.write Allows write (create + update) on the Practitioner resource for the backend service (no user). clientCredentials
system/Procedure.crs Allows SMART v2 permissions: create, read, search on the Procedure resource for the backend service (no user). clientCredentials
system/Procedure.read Allows read (search + read) on the Procedure resource for the backend service (no user). clientCredentials
system/Procedure.write Allows write (create + update) on the Procedure resource for the backend service (no user). clientCredentials
system/Provenance.crs Allows SMART v2 permissions: create, read, search on the Provenance resource for the backend service (no user). clientCredentials
system/Provenance.read Allows read (search + read) on the Provenance resource for the backend service (no user). clientCredentials
system/Provenance.write Allows write (create + update) on the Provenance resource for the backend service (no user). clientCredentials
system/Questionnaire.read Allows read (search + read) on the Questionnaire resource for the backend service (no user). clientCredentials
system/Questionnaire.rs Allows SMART v2 permissions: read, search on the Questionnaire resource for the backend service (no user). clientCredentials
system/QuestionnaireResponse.read Allows read (search + read) on the QuestionnaireResponse resource for the backend service (no user). clientCredentials
system/QuestionnaireResponse.rus Allows SMART v2 permissions: read, update, search on the QuestionnaireResponse resource for the backend service (no user). clientCredentials
system/QuestionnaireResponse.write Allows write (create + update) on the QuestionnaireResponse resource for the backend service (no user). clientCredentials
system/RelatedPerson.crus Allows SMART v2 permissions: create, read, update, search on the RelatedPerson resource for the backend service (no user). clientCredentials
system/RelatedPerson.read Allows read (search + read) on the RelatedPerson resource for the backend service (no user). clientCredentials
system/RelatedPerson.write Allows write (create + update) on the RelatedPerson resource for the backend service (no user). clientCredentials
system/Schedule.read Allows read (search + read) on the Schedule resource for the backend service (no user). clientCredentials
system/Schedule.rs Allows SMART v2 permissions: read, search on the Schedule resource for the backend service (no user). clientCredentials
system/ServiceRequest.read Allows read (search + read) on the ServiceRequest resource for the backend service (no user). clientCredentials
system/ServiceRequest.rs Allows SMART v2 permissions: read, search on the ServiceRequest resource for the backend service (no user). clientCredentials
system/Slot.read Allows read (search + read) on the Slot resource for the backend service (no user). clientCredentials
system/Slot.rus Allows SMART v2 permissions: read, update, search on the Slot resource for the backend service (no user). clientCredentials
system/Slot.write Allows write (create + update) on the Slot resource for the backend service (no user). clientCredentials
system/Specimen.read Allows read (search + read) on the Specimen resource for the backend service (no user). clientCredentials
system/Specimen.rs Allows SMART v2 permissions: read, search on the Specimen resource for the backend service (no user). clientCredentials
user/Account.read Allows read (search + read) on the Account resource for the authorizing user. authorizationCode
user/Account.rs Allows SMART v2 permissions: read, search on the Account resource for the authorizing user. authorizationCode
user/AllergyIntolerance.crus Allows SMART v2 permissions: create, read, update, search on the AllergyIntolerance resource for the authorizing user. authorizationCode
user/AllergyIntolerance.read Allows read (search + read) on the AllergyIntolerance resource for the authorizing user. authorizationCode
user/AllergyIntolerance.write Allows write (create + update) on the AllergyIntolerance resource for the authorizing user. authorizationCode
user/Appointment.crus Allows SMART v2 permissions: create, read, update, search on the Appointment resource for the authorizing user. authorizationCode
user/Appointment.read Allows read (search + read) on the Appointment resource for the authorizing user. authorizationCode
user/Appointment.write Allows write (create + update) on the Appointment resource for the authorizing user. authorizationCode
user/Basic.c Allows SMART v2 permissions: create on the Basic resource for the authorizing user. authorizationCode
user/Basic.write Allows write (create + update) on the Basic resource for the authorizing user. authorizationCode
user/Binary.r Allows SMART v2 permissions: read on the Binary resource for the authorizing user. authorizationCode
user/Binary.read Allows read (search + read) on the Binary resource for the authorizing user. authorizationCode
user/CarePlan.read Allows read (search + read) on the CarePlan resource for the authorizing user. authorizationCode
user/CarePlan.rs Allows SMART v2 permissions: read, search on the CarePlan resource for the authorizing user. authorizationCode
user/CareTeam.read Allows read (search + read) on the CareTeam resource for the authorizing user. authorizationCode
user/CareTeam.rs Allows SMART v2 permissions: read, search on the CareTeam resource for the authorizing user. authorizationCode
user/ChargeItem.crs Allows SMART v2 permissions: create, read, search on the ChargeItem resource for the authorizing user. authorizationCode
user/ChargeItem.read Allows read (search + read) on the ChargeItem resource for the authorizing user. authorizationCode
user/ChargeItem.write Allows write (create + update) on the ChargeItem resource for the authorizing user. authorizationCode
user/Communication.crus Allows SMART v2 permissions: create, read, update, search on the Communication resource for the authorizing user. authorizationCode
user/Communication.read Allows read (search + read) on the Communication resource for the authorizing user. authorizationCode
user/Communication.write Allows write (create + update) on the Communication resource for the authorizing user. authorizationCode
user/Condition.crus Allows SMART v2 permissions: create, read, update, search on the Condition resource for the authorizing user. authorizationCode
user/Condition.read Allows read (search + read) on the Condition resource for the authorizing user. authorizationCode
user/Condition.write Allows write (create + update) on the Condition resource for the authorizing user. authorizationCode
user/Consent.read Allows read (search + read) on the Consent resource for the authorizing user. authorizationCode
user/Consent.rs Allows SMART v2 permissions: read, search on the Consent resource for the authorizing user. authorizationCode
user/Coverage.cruds Allows SMART v2 permissions: create, read, update, delete, search on the Coverage resource for the authorizing user. authorizationCode
user/Coverage.read Allows read (search + read) on the Coverage resource for the authorizing user. authorizationCode
user/Coverage.write Allows write (create + update) on the Coverage resource for the authorizing user. authorizationCode
user/Device.read Allows read (search + read) on the Device resource for the authorizing user. authorizationCode
user/Device.rs Allows SMART v2 permissions: read, search on the Device resource for the authorizing user. authorizationCode
user/DiagnosticReport.crs Allows SMART v2 permissions: create, read, search on the DiagnosticReport resource for the authorizing user. authorizationCode
user/DiagnosticReport.read Allows read (search + read) on the DiagnosticReport resource for the authorizing user. authorizationCode
user/DiagnosticReport.write Allows write (create + update) on the DiagnosticReport resource for the authorizing user. authorizationCode
user/DocumentReference.crus Allows SMART v2 permissions: create, read, update, search on the DocumentReference resource for the authorizing user. authorizationCode
user/DocumentReference.read Allows read (search + read) on the DocumentReference resource for the authorizing user. authorizationCode
user/DocumentReference.write Allows write (create + update) on the DocumentReference resource for the authorizing user. authorizationCode
user/Encounter.crus Allows SMART v2 permissions: create, read, update, search on the Encounter resource for the authorizing user. authorizationCode
user/Encounter.read Allows read (search + read) on the Encounter resource for the authorizing user. authorizationCode
user/Encounter.write Allows write (create + update) on the Encounter resource for the authorizing user. authorizationCode
user/FamilyMemberHistory.crus Allows SMART v2 permissions: create, read, update, search on the FamilyMemberHistory resource for the authorizing user. authorizationCode
user/FamilyMemberHistory.read Allows read (search + read) on the FamilyMemberHistory resource for the authorizing user. authorizationCode
user/FamilyMemberHistory.write Allows write (create + update) on the FamilyMemberHistory resource for the authorizing user. authorizationCode
user/Goal.read Allows read (search + read) on the Goal resource for the authorizing user. authorizationCode
user/Goal.rs Allows SMART v2 permissions: read, search on the Goal resource for the authorizing user. authorizationCode
user/Immunization.crus Allows SMART v2 permissions: create, read, update, search on the Immunization resource for the authorizing user. authorizationCode
user/Immunization.read Allows read (search + read) on the Immunization resource for the authorizing user. authorizationCode
user/Immunization.write Allows write (create + update) on the Immunization resource for the authorizing user. authorizationCode
user/InsurancePlan.read Allows read (search + read) on the InsurancePlan resource for the authorizing user. authorizationCode
user/InsurancePlan.rs Allows SMART v2 permissions: read, search on the InsurancePlan resource for the authorizing user. authorizationCode
user/Location.read Allows read (search + read) on the Location resource for the authorizing user. authorizationCode
user/Location.rs Allows SMART v2 permissions: read, search on the Location resource for the authorizing user. authorizationCode
user/Media.r Allows SMART v2 permissions: read on the Media resource for the authorizing user. authorizationCode
user/Media.read Allows read (search + read) on the Media resource for the authorizing user. authorizationCode
user/MedicationAdministration.read Allows read (search + read) on the MedicationAdministration resource for the authorizing user. authorizationCode
user/MedicationAdministration.rs Allows SMART v2 permissions: read, search on the MedicationAdministration resource for the authorizing user. authorizationCode
user/MedicationDispense.read Allows read (search + read) on the MedicationDispense resource for the authorizing user. authorizationCode
user/MedicationDispense.rs Allows SMART v2 permissions: read, search on the MedicationDispense resource for the authorizing user. authorizationCode
user/MedicationRequest.crus Allows SMART v2 permissions: create, read, update, search on the MedicationRequest resource for the authorizing user. authorizationCode
user/MedicationRequest.read Allows read (search + read) on the MedicationRequest resource for the authorizing user. authorizationCode
user/MedicationRequest.write Allows write (create + update) on the MedicationRequest resource for the authorizing user. authorizationCode
user/NutritionOrder.read Allows read (search + read) on the NutritionOrder resource for the authorizing user. authorizationCode
user/NutritionOrder.rs Allows SMART v2 permissions: read, search on the NutritionOrder resource for the authorizing user. authorizationCode
user/Observation.crus Allows SMART v2 permissions: create, read, update, search on the Observation resource for the authorizing user. authorizationCode
user/Observation.read Allows read (search + read) on the Observation resource for the authorizing user. authorizationCode
user/Observation.write Allows write (create + update) on the Observation resource for the authorizing user. authorizationCode
user/Organization.crs Allows SMART v2 permissions: create, read, search on the Organization resource for the authorizing user. authorizationCode
user/Organization.read Allows read (search + read) on the Organization resource for the authorizing user. authorizationCode
user/Organization.write Allows write (create + update) on the Organization resource for the authorizing user. authorizationCode
user/Patient.crus Allows SMART v2 permissions: create, read, update, search on the Patient resource for the authorizing user. authorizationCode
user/Patient.read Allows read (search + read) on the Patient resource for the authorizing user. authorizationCode
user/Patient.write Allows write (create + update) on the Patient resource for the authorizing user. authorizationCode
user/Person.read Allows read (search + read) on the Person resource for the authorizing user. authorizationCode
user/Person.rs Allows SMART v2 permissions: read, search on the Person resource for the authorizing user. authorizationCode
user/Practitioner.crs Allows SMART v2 permissions: create, read, search on the Practitioner resource for the authorizing user. authorizationCode
user/Practitioner.read Allows read (search + read) on the Practitioner resource for the authorizing user. authorizationCode
user/Practitioner.write Allows write (create + update) on the Practitioner resource for the authorizing user. authorizationCode
user/Procedure.crs Allows SMART v2 permissions: create, read, search on the Procedure resource for the authorizing user. authorizationCode
user/Procedure.read Allows read (search + read) on the Procedure resource for the authorizing user. authorizationCode
user/Procedure.write Allows write (create + update) on the Procedure resource for the authorizing user. authorizationCode
user/Provenance.crs Allows SMART v2 permissions: create, read, search on the Provenance resource for the authorizing user. authorizationCode
user/Provenance.read Allows read (search + read) on the Provenance resource for the authorizing user. authorizationCode
user/Provenance.write Allows write (create + update) on the Provenance resource for the authorizing user. authorizationCode
user/Questionnaire.read Allows read (search + read) on the Questionnaire resource for the authorizing user. authorizationCode
user/Questionnaire.rs Allows SMART v2 permissions: read, search on the Questionnaire resource for the authorizing user. authorizationCode
user/QuestionnaireResponse.read Allows read (search + read) on the QuestionnaireResponse resource for the authorizing user. authorizationCode
user/QuestionnaireResponse.rus Allows SMART v2 permissions: read, update, search on the QuestionnaireResponse resource for the authorizing user. authorizationCode
user/QuestionnaireResponse.write Allows write (create + update) on the QuestionnaireResponse resource for the authorizing user. authorizationCode
user/RelatedPerson.crus Allows SMART v2 permissions: create, read, update, search on the RelatedPerson resource for the authorizing user. authorizationCode
user/RelatedPerson.read Allows read (search + read) on the RelatedPerson resource for the authorizing user. authorizationCode
user/RelatedPerson.write Allows write (create + update) on the RelatedPerson resource for the authorizing user. authorizationCode
user/Schedule.read Allows read (search + read) on the Schedule resource for the authorizing user. authorizationCode
user/Schedule.rs Allows SMART v2 permissions: read, search on the Schedule resource for the authorizing user. authorizationCode
user/ServiceRequest.read Allows read (search + read) on the ServiceRequest resource for the authorizing user. authorizationCode
user/ServiceRequest.rs Allows SMART v2 permissions: read, search on the ServiceRequest resource for the authorizing user. authorizationCode
user/Slot.read Allows read (search + read) on the Slot resource for the authorizing user. authorizationCode
user/Slot.rus Allows SMART v2 permissions: read, update, search on the Slot resource for the authorizing user. authorizationCode
user/Slot.write Allows write (create + update) on the Slot resource for the authorizing user. authorizationCode
user/Specimen.read Allows read (search + read) on the Specimen resource for the authorizing user. authorizationCode
user/Specimen.rs Allows SMART v2 permissions: read, search on the Specimen resource for the authorizing user. authorizationCode

Source

OAuth Scopes

Raw ↑
generated: '2026-08-14'
method: probed
source: https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
docs: https://docs.oracle.com/en/industries/health/millennium-platform-apis/mfrap/index.html
note: 'The full scope set is read live from the SMART on FHIR discovery document Oracle Health serves at the tenant
  service root. It is tenant-scoped: this capture is the public sandbox tenant (ec2458f2-1e24-41c8-b71b-0e701af7583d),
  and a production tenant advertises its own — always re-read /.well-known/smart-configuration for the tenant you
  are integrating with. Scope prefixes follow SMART App Launch: patient/ and user/ scopes are only obtainable through
  the authorization-code flow, system/ scopes only through client-credentials (backend services). The tenant advertises
  both SMART v1 (.read/.write) and SMART v2 (.crus granular) permission forms.'
capabilities:
- authorize-post
- launch-ehr
- launch-standalone
- client-public
- client-confidential-asymmetric
- client-confidential-symmetric
- sso-openid-connect
- context-banner
- context-style
- context-ehr-patient
- context-ehr-encounter
- permission-patient
- permission-user
- permission-offline
- permission-online
- permission-v1
- permission-v2
- health-cards
summary:
  scope_count: 303
  by_persona:
    context: 6
    patient: 93
    system: 103
    user: 101
  smart_version: SMART App Launch v1 and v2 (permission-v1, permission-v2 both advertised)
schemes:
- name: smartOnFhir
  source: https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
  issuer: https://authorization.cerner.com/tenants/{tenant}
  flows:
  - flow: authorizationCode
    authorizationUrl: https://authorization.cerner.com/tenants/{tenant}/protocols/oauth2/profiles/smart-v1/personas/provider/authorize
    tokenUrl: https://authorization.cerner.com/tenants/{tenant}/hosts/fhir-ehr-code.cerner.com/protocols/oauth2/profiles/smart-v1/token
    revocationUrl: https://authorization.cerner.com/tenants/{tenant}/protocols/oauth2/profiles/smart-v1/token/revoke
  - flow: clientCredentials
    tokenUrl: https://authorization.cerner.com/tenants/{tenant}/hosts/fhir-ehr-code.cerner.com/protocols/oauth2/profiles/smart-v1/token
  description: SMART on FHIR OAuth 2.0 as implemented by Oracle Health Millennium Platform.
scopes:
- scope: fhirUser
  description: Returns the FHIR resource (Practitioner/Patient/RelatedPerson) representing the authorizing user.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: launch
  description: EHR launch context — the app is launched from inside PowerChart and inherits patient/encounter context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: offline_access
  description: Issues a refresh token that outlives the user session.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: online_access
  description: Issues a refresh token bound to the user session.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: openid
  description: OpenID Connect authentication; returns an id_token identifying the authorizing user.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Account.read
  description: Allows read (search + read) on the Account resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Account.rs
  description: 'Allows SMART v2 permissions: read, search on the Account resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/AllergyIntolerance.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the AllergyIntolerance resource for
    the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/AllergyIntolerance.read
  description: Allows read (search + read) on the AllergyIntolerance resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/AllergyIntolerance.write
  description: Allows write (create + update) on the AllergyIntolerance resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Appointment.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the Appointment resource for the patient
    in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Appointment.read
  description: Allows read (search + read) on the Appointment resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Appointment.write
  description: Allows write (create + update) on the Appointment resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Basic.c
  description: 'Allows SMART v2 permissions: create on the Basic resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Basic.write
  description: Allows write (create + update) on the Basic resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Binary.r
  description: 'Allows SMART v2 permissions: read on the Binary resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Binary.read
  description: Allows read (search + read) on the Binary resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/CarePlan.read
  description: Allows read (search + read) on the CarePlan resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/CarePlan.rs
  description: 'Allows SMART v2 permissions: read, search on the CarePlan resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/CareTeam.read
  description: Allows read (search + read) on the CareTeam resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/CareTeam.rs
  description: 'Allows SMART v2 permissions: read, search on the CareTeam resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/ChargeItem.crs
  description: 'Allows SMART v2 permissions: create, read, search on the ChargeItem resource for the patient in
    context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/ChargeItem.read
  description: Allows read (search + read) on the ChargeItem resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/ChargeItem.write
  description: Allows write (create + update) on the ChargeItem resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Communication.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the Communication resource for the
    patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Communication.read
  description: Allows read (search + read) on the Communication resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Communication.write
  description: Allows write (create + update) on the Communication resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Condition.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the Condition resource for the patient
    in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Condition.read
  description: Allows read (search + read) on the Condition resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Condition.write
  description: Allows write (create + update) on the Condition resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Consent.read
  description: Allows read (search + read) on the Consent resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Consent.rs
  description: 'Allows SMART v2 permissions: read, search on the Consent resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Coverage.cruds
  description: 'Allows SMART v2 permissions: create, read, update, delete, search on the Coverage resource for the
    patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Coverage.read
  description: Allows read (search + read) on the Coverage resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Coverage.write
  description: Allows write (create + update) on the Coverage resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Device.read
  description: Allows read (search + read) on the Device resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Device.rs
  description: 'Allows SMART v2 permissions: read, search on the Device resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/DiagnosticReport.crs
  description: 'Allows SMART v2 permissions: create, read, search on the DiagnosticReport resource for the patient
    in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/DiagnosticReport.read
  description: Allows read (search + read) on the DiagnosticReport resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/DiagnosticReport.write
  description: Allows write (create + update) on the DiagnosticReport resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/DocumentReference.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the DocumentReference resource for
    the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/DocumentReference.read
  description: Allows read (search + read) on the DocumentReference resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/DocumentReference.write
  description: Allows write (create + update) on the DocumentReference resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Encounter.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the Encounter resource for the patient
    in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Encounter.read
  description: Allows read (search + read) on the Encounter resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Encounter.write
  description: Allows write (create + update) on the Encounter resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/FamilyMemberHistory.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the FamilyMemberHistory resource for
    the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/FamilyMemberHistory.read
  description: Allows read (search + read) on the FamilyMemberHistory resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/FamilyMemberHistory.write
  description: Allows write (create + update) on the FamilyMemberHistory resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Goal.read
  description: Allows read (search + read) on the Goal resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Goal.rs
  description: 'Allows SMART v2 permissions: read, search on the Goal resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Immunization.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the Immunization resource for the patient
    in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Immunization.read
  description: Allows read (search + read) on the Immunization resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Immunization.write
  description: Allows write (create + update) on the Immunization resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/InsurancePlan.read
  description: Allows read (search + read) on the InsurancePlan resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/InsurancePlan.rs
  description: 'Allows SMART v2 permissions: read, search on the InsurancePlan resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Media.r
  description: 'Allows SMART v2 permissions: read on the Media resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Media.read
  description: Allows read (search + read) on the Media resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/MedicationAdministration.read
  description: Allows read (search + read) on the MedicationAdministration resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/MedicationAdministration.rs
  description: 'Allows SMART v2 permissions: read, search on the MedicationAdministration resource for the patient
    in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/MedicationDispense.read
  description: Allows read (search + read) on the MedicationDispense resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/MedicationDispense.rs
  description: 'Allows SMART v2 permissions: read, search on the MedicationDispense resource for the patient in
    context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/MedicationRequest.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the MedicationRequest resource for
    the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/MedicationRequest.read
  description: Allows read (search + read) on the MedicationRequest resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/MedicationRequest.write
  description: Allows write (create + update) on the MedicationRequest resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/NutritionOrder.read
  description: Allows read (search + read) on the NutritionOrder resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/NutritionOrder.rs
  description: 'Allows SMART v2 permissions: read, search on the NutritionOrder resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Observation.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the Observation resource for the patient
    in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Observation.read
  description: Allows read (search + read) on the Observation resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Observation.write
  description: Allows write (create + update) on the Observation resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Patient.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the Patient resource for the patient
    in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Patient.read
  description: Allows read (search + read) on the Patient resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Patient.write
  description: Allows write (create + update) on the Patient resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Person.read
  description: Allows read (search + read) on the Person resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Person.rs
  description: 'Allows SMART v2 permissions: read, search on the Person resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Procedure.crs
  description: 'Allows SMART v2 permissions: create, read, search on the Procedure resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Procedure.read
  description: Allows read (search + read) on the Procedure resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Procedure.write
  description: Allows write (create + update) on the Procedure resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Provenance.crs
  description: 'Allows SMART v2 permissions: create, read, search on the Provenance resource for the patient in
    context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Provenance.read
  description: Allows read (search + read) on the Provenance resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Provenance.write
  description: Allows write (create + update) on the Provenance resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Questionnaire.read
  description: Allows read (search + read) on the Questionnaire resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Questionnaire.rs
  description: 'Allows SMART v2 permissions: read, search on the Questionnaire resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/QuestionnaireResponse.read
  description: Allows read (search + read) on the QuestionnaireResponse resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/QuestionnaireResponse.rus
  description: 'Allows SMART v2 permissions: read, update, search on the QuestionnaireResponse resource for the
    patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/QuestionnaireResponse.write
  description: Allows write (create + update) on the QuestionnaireResponse resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/RelatedPerson.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the RelatedPerson resource for the
    patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/RelatedPerson.read
  description: Allows read (search + read) on the RelatedPerson resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/RelatedPerson.write
  description: Allows write (create + update) on the RelatedPerson resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Schedule.read
  description: Allows read (search + read) on the Schedule resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Schedule.rs
  description: 'Allows SMART v2 permissions: read, search on the Schedule resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/ServiceRequest.read
  description: Allows read (search + read) on the ServiceRequest resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/ServiceRequest.rs
  description: 'Allows SMART v2 permissions: read, search on the ServiceRequest resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Slot.read
  description: Allows read (search + read) on the Slot resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Slot.rus
  description: 'Allows SMART v2 permissions: read, update, search on the Slot resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Slot.write
  description: Allows write (create + update) on the Slot resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Specimen.read
  description: Allows read (search + read) on the Specimen resource for the patient in context.
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: patient/Specimen.rs
  description: 'Allows SMART v2 permissions: read, search on the Specimen resource for the patient in context.'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: profile
  description: 'SMART on FHIR scope advertised by the tenant: profile'
  flows:
  - authorizationCode
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: system/Account.read
  description: Allows read (search + read) on the Account resource for the backend service (no user).
  flows:
  - clientCredentials
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: system/Account.rs
  description: 'Allows SMART v2 permissions: read, search on the Account resource for the backend service (no user).'
  flows:
  - clientCredentials
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: system/AllergyIntolerance.crus
  description: 'Allows SMART v2 permissions: create, read, update, search on the AllergyIntolerance resource for
    the backend service (no user).'
  flows:
  - clientCredentials
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: system/AllergyIntolerance.read
  description: Allows read (search + read) on the AllergyIntolerance resource for the backend service (no user).
  flows:
  - clientCredentials
  sources:
  - https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration
- scope: system/AllergyIntolerance.write
  description: Allows write (create + update) on the AllergyIntolerance resource for the backend service (no user).
  flows:
  - clientCredentials
  sources:
  

# --- truncated at 32 KB (89 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cerner/refs/heads/main/scopes/cerner-scopes.yml

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/cerner-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.