vitagroup · OAuth Scopes
vitagroup OAuth Scopes
OAuth 2.0
searched
vitagroup uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
CompanyHealthcareHealth ITElectronic Health RecordsopenEHRFHIRClinical Data RepositoryInteroperabilityGermanyOpen Source
Scopes: 0
Flows:
Method: searched
Scopes (0)
vitagroup implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
derive-oauth-scopes.py returned zero scopes because none of vitagroup's published OpenAPI documents declare an oauth2 securityScheme — the enterprise spec declares only http/bearer. OAuth 2.0 IS documented, but EHRbase does not model authorization as a scope catalogue. It reads a single role value out of the JWT's realm_access.roles or scope claim and maps it to one of two authorization levels. The role NAMES are operator-configurable, so what is recorded below is the vendor default and the claim path, not a fixed scope vocabulary.
derive-oauth-scopes.py returned zero scopes because none of vitagroup's published OpenAPI documents declare an oauth2 securityScheme — the enterprise spec declares only http/bearer. OAuth 2.0 IS documented, but EHRbase does not model authorization as a scope catalogue. It reads a single role value out of the JWT's realm_access.roles or scope claim and maps it to one of two authorization levels. The role NAMES are operator-configurable, so what is recorded below is the vendor default and the claim path, not a fixed scope vocabulary.
📄 Provider scope reference: https://docs.ehrbase.org/docs/EHRbase/Explore/Security
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.