Future Perfect (Healthcare) · Authentication Profile

Future Perfect Healthcare Authentication

Authentication

Future Perfect (Healthcare) declares 3 security scheme(s) across its OpenAPI definitions.

CompanyHealthcareHealth ITElectronic Health RecordsopenEHRInteroperabilityClinical Decision SupportGenomicsArtificial IntelligenceNHSUnited Kingdom
Methods: Schemes: 3 OAuth flows: API key in:

Security Schemes

OAuth 2.0 / OpenID Connect single sign-on oauth2
· flows:
Public key authentication including TLS client certificate mutualTLS
Username and password with 2-factor authentication http

Source

Authentication Profile

future-perfect-healthcare-authentication.yml Raw ↑
generated: '2026-09-02'
method: searched
source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/557090777176539
docs: null
note: >-
  There is no public authentication reference and no securitySchemes block to derive from —
  Future Perfect publishes no OpenAPI. Everything below is taken verbatim from the
  supplier-authored identity/authentication fields of the G-Cloud 14 PANACEA service entry,
  which is the only public description of how the platform authenticates. Scheme details
  (token endpoints, issuer, scopes, header names) are NOT published anywhere public.

api: PANACEA (no public base URL published)
public_reference: false

schemes:
- type: oauth2
  name: OAuth 2.0 / OpenID Connect single sign-on
  description: >-
    "Open security standards (OAuth2/OpenIdConnect) providing Single-Sign-On with the
    customer's systems." Deployed as identity federation against the buying organisation's
    existing identity provider.
  flows: unpublished
  issuer: unpublished
  scopes_published: false
  source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/557090777176539
- type: mutualTLS
  name: Public key authentication including TLS client certificate
  description: >-
    G-Cloud 14 "User authentication" field lists "Public key authentication (including by
    TLS client certificate)" among supported user authentication methods.
  source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/557090777176539
- type: http
  name: Username and password with 2-factor authentication
  description: >-
    G-Cloud 14 "User authentication" field lists "2-factor authentication" and "Username or
    password". Management access authentication is declared as 2-factor; the web
    administration portal is additionally restricted to whitelisted IP addresses.
  source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/557090777176539

identity_federation: true
mfa: true
ip_allowlisting:
  present: true
  scope: web administration portal
  source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/557090777176539

transport:
  tls: 'TLS 1.2 or above between buyer and supplier networks and within the supplier network'
  caveat: >-
    The same G-Cloud field also declares "Legacy SSL and TLS (under version 1.2)" as a
    supported data-in-transit protection option, alongside IPsec/TLS VPN gateway.
  source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/557090777176539

audit:
  user_audit: 'Users have access to real-time audit information; retention is user-defined.'
  supplier_audit: 'Users contact the support team to get audit information.'
  source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/557090777176539

gaps:
- No public OAuth metadata document (/.well-known/openid-configuration returned 404).
- No published scope or permission reference, so scopes/ is not written for this provider.
- No public token endpoint, client registration flow, or key-issuance documentation.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/future-perfect-healthcare-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.