Tebra · OAuth Scopes
Tebra OAuth Scopes
OAuth 2.0
derived
Tebra publishes 27 OAuth 2.0 scopes via the authorizationCode and clientCredentials flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Tebra API on a user’s behalf.
Tokens are issued from https://fhir.prd.cloud.tebra.com/smartauth/oauth/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
HealthcarePractice ManagementEHRMedical BillingPatient EngagementKareoPatientPop
Scopes: 27
Flows: authorizationCode, clientCredentials
Method: derived
OAuth endpoints
Authorization URL
https://fhir.prd.cloud.tebra.com/smartauth/oauth/authorize
https://fhir.prd.cloud.tebra.com/smartauth/oauth/authorize
Token URL
https://fhir.prd.cloud.tebra.com/smartauth/oauth/token
https://fhir.prd.cloud.tebra.com/smartauth/oauth/token
Flows
authorizationCodeclientCredentials
authorizationCodeclientCredentials
Scopes (27)
| Scope | Description | Flows |
|---|---|---|
| fhirUser | FHIR user identity claim. | authorizationCode |
| launch/patient | Identify the launch patient context. | authorizationCode |
| offline_access | Obtain a refresh token. | authorizationCode |
| openid | OpenID Connect identity claim. | authorizationCode |
| patient/AllergyIntolerance.read | Read the patient's allergies/intolerances. | authorizationCode |
| patient/CarePlan.read | Read the patient's care plans. | authorizationCode |
| patient/CareTeam.read | Read the patient's care team. | authorizationCode |
| patient/Condition.read | Read the patient's conditions/problems. | authorizationCode |
| patient/Device.read | Read the patient's implantable devices. | authorizationCode |
| patient/DiagnosticReport.read | Read the patient's diagnostic reports. | authorizationCode |
| patient/DocumentReference.read | Read the patient's documents/clinical notes. | authorizationCode |
| patient/Encounter.read | Read the patient's encounters. | authorizationCode |
| patient/Goal.read | Read the patient's goals. | authorizationCode |
| patient/Immunization.read | Read the patient's immunizations. | authorizationCode |
| patient/Location.read | Read location resources. | authorizationCode |
| patient/Medication.read | Read medication resources. | authorizationCode |
| patient/MedicationRequest.read | Read the patient's medication requests. | authorizationCode |
| patient/Observation.read | Read the patient's observations (vitals/labs/smoking status). | authorizationCode |
| patient/Organization.read | Read organization resources. | authorizationCode |
| patient/Patient.read | Read the patient's demographic record. | authorizationCode |
| patient/Practitioner.read | Read practitioner resources. | authorizationCode |
| patient/PractitionerRole.read | Read practitioner-role resources. | authorizationCode |
| patient/Procedure.read | Read the patient's procedures. | authorizationCode |
| patient/Provenance.read | Read provenance resources. | authorizationCode |
| system/DocumentReference.read | Read document reference resources. | clientCredentials |
| system/Observation.read | Read observation resources. | clientCredentials |
| system/Patient.read | Read patient demographic records. | clientCredentials |
📄 Provider scope reference: https://www.tebra.com/wp-content/uploads/2025/05/Tebra-FHIR-API-User-Guide.pdf
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.