Jefferson Health · Authentication Profile

Jefferson Health Authentication

Authentication

Jefferson Health secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

Academic Medical CenterCARIN Blue ButtonCMS InteroperabilityCures ActDa Vinci Plan-NetEpicFHIRHL7HealthcareHospital SystemMyChartOAuth 2.0Patient AccessProvider DirectorySMART on FHIRUS CoreUSCDI
Methods: oauth2 Schemes: 1 OAuth flows: authorizationCode API key in:

Security Schemes

smartOnFhir oauth2
· flows: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-07-11'
method: derived
source: openapi/jefferson-health-tjuh-fhir-r4-api-openapi.yml
summary:
  types:
  - oauth2
  oauth2_flows:
  - authorizationCode
schemes:
- name: smartOnFhir
  type: oauth2
  flows:
  - flow: authorizationCode
    authorizationUrl: https://fhir.jefferson.edu/FHIRProxy/oauth2/authorize
    tokenUrl: https://fhir.jefferson.edu/FHIRProxy/oauth2/token
    scopes: 13
  description: SMART on FHIR / OAuth 2.0 with PKCE for patient-facing and provider-facing app
    launches.
  sources:
  - openapi/jefferson-health-tjuh-fhir-r4-api-openapi.yml