Epic Systems · OAuth Scopes
Epic Systems OAuth Scopes
OAuth 2.0
searched
Epic Systems uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
Tokens are issued from https://fhir.epic.com/interconnect-fhir-oauth/oauth2/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
HealthcareUnited StatesEHREMRFHIRHL7InteroperabilitySMART on FHIRUS CoreClinical Data
Scopes: 0
Flows: authorizationCode, clientCredentials
Method: searched
OAuth endpoints
Authorization URL
https://fhir.epic.com/interconnect-fhir-oauth/oauth2/authorize
https://fhir.epic.com/interconnect-fhir-oauth/oauth2/authorize
Token URL
https://fhir.epic.com/interconnect-fhir-oauth/oauth2/token
https://fhir.epic.com/interconnect-fhir-oauth/oauth2/token
Flows
authorizationCodeclientCredentials
authorizationCodeclientCredentials
Scopes (0)
Epic Systems implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
Epic authorizes its FHIR APIs with SMART on FHIR scopes layered on OAuth 2.0. The five scopes below are the base scopes advertised anonymously in the live R4 smart-configuration / openid-configuration (scopes_supported). Clinical resource access is granted with SMART v1/v2 scope grammar (both permission-v1 and permission-v2 advertised), negotiated per registered client and per connected health system - these are not enumerated in the discovery document, so the grammar and per-context patterns are documented below rather than as fixed strings.
Epic authorizes its FHIR APIs with SMART on FHIR scopes layered on OAuth 2.0. The five scopes below are the base scopes advertised anonymously in the live R4 smart-configuration / openid-configuration (scopes_supported). Clinical resource access is granted with SMART v1/v2 scope grammar (both permission-v1 and permission-v2 advertised), negotiated per registered client and per connected health system - these are not enumerated in the discovery document, so the grammar and per-context patterns are documented below rather than as fixed strings.
📄 Provider scope reference: https://fhir.epic.com/Documentation?docId=oauth2