Patients Know Best · Authentication Profile

Patientsknowbest Authentication

Authentication

Patients Know Best secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CompanyHealthcareHealth RecordsFHIRInteroperabilityPatient DataNHSHL7
Methods: oauth2 Schemes: 1 OAuth flows: authorizationCode API key in:

Security Schemes

SMARTonFHIR oauth2
scheme: bearer

Source

Authentication Profile

patientsknowbest-authentication.yml Raw ↑
generated: '2026-07-20'
method: searched
source: https://wiki.patientsknowbest.com/space/api
docs: https://wiki.patientsknowbest.com/space/api
notes: >-
  Patients Know Best exposes a HL7 FHIR API (see the published FHIR Conformance /
  CapabilityStatement at https://fhir.patientsknowbest.com/metadata). FHIR access is
  secured with OAuth 2.0 following the SMART on FHIR pattern that is standard for
  patient/provider FHIR access. Exact scope strings, authorization/token endpoints
  and grant types are documented in the developer wiki (client-rendered) and issued
  to onboarded integration partners; they are not machine-harvestable from a public,
  unauthenticated endpoint, so only the confirmed auth model is recorded here — no
  scope values are invented.
summary:
  types:
  - oauth2
  oauth2_flows:
  - authorizationCode
  smart_on_fhir: true
schemes:
- name: SMARTonFHIR
  type: oauth2
  scheme: bearer
  description: >-
    OAuth 2.0 bearer access tokens obtained via the SMART on FHIR authorization
    flow. Tokens are presented on FHIR resource requests to fhir.patientsknowbest.com.
  smart_on_fhir: true
  sources:
  - https://wiki.patientsknowbest.com/space/api