Practice Fusion · Authentication Profile

Practice Fusion Authentication

Authentication

Practice Fusion secures its APIs with oauth2, openIdConnect, and mutualTLS across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, clientCredentials, and refreshToken flow(s).

CompanyHealthcareElectronic Health RecordsEHRFHIRInteroperabilityMedicalHealth ITSMART on FHIRClinical Data
Methods: oauth2, openIdConnect, mutualTLS Schemes: 3 OAuth flows: authorizationCode, clientCredentials, refreshToken API key in:

Security Schemes

SMART-on-FHIR OAuth2 oauth2
· flows: authorizationCode, clientCredentials, refreshToken
OpenID Connect openIdConnect
Mutual TLS (client certificate) mutualTLS

Source

Authentication Profile

practice-fusion-authentication.yml Raw ↑
generated: '2026-08-14'
method: searched
source: https://api.practicefusion.com/fhir/r4/v1/{organizationId}/.well-known/smart-configuration
docs: https://www.practicefusion.com/fhir/api-specifications/
docs_additional:
- https://www.practicefusion.com/pds-api/developer-guide/
summary:
  types: [oauth2, openIdConnect, mutualTLS]
  standard: SMART App Launch 2.0.0 (SMART-on-FHIR)
  oauth2_flows: [authorizationCode, clientCredentials, refreshToken]
  pkce: S256
  client_authentication:
  - client-confidential-symmetric   # shared secret
  - client-confidential-asymmetric  # private key JWT (JWKS)
  - client-public                   # public standalone launch with PKCE
schemes:
- name: SMART-on-FHIR OAuth2
  type: oauth2
  standard: SMART App Launch 2.0.0
  flows:
  - flow: authorizationCode
    authorizationUrl: https://api.practicefusion.com/fhir/r4/v1/{organizationId}/authorize
    tokenUrl: https://api.practicefusion.com/fhir/r4/v1/{organizationId}/token
    pkce: S256
  - flow: clientCredentials
    tokenUrl: https://api.practicefusion.com/fhir/r4/v1/{organizationId}/token
  - flow: refreshToken
    tokenUrl: https://api.practicefusion.com/fhir/r4/v1/{organizationId}/token
  introspection_endpoint: https://api.practicefusion.com/fhir/r4/v1/{organizationId}/introspect
  jwks_uri: https://api.practicefusion.com/fhir/r4/v1/{organizationId}/.well-known/jwk
- name: OpenID Connect
  type: openIdConnect
  note: >-
    sso-openid-connect capability advertised in the SMART configuration; id_token
    issued for the fhirUser / user identity.
- name: Mutual TLS (client certificate)
  type: mutualTLS
  note: >-
    The CapabilityStatement security service advertises "Certificates: SSL where
    client must have a certificate registered with the server" in addition to
    SMART-on-FHIR.
capabilities:
- launch-ehr
- launch-standalone
- client-public
- client-confidential-symmetric
- client-confidential-asymmetric
- sso-openid-connect
- context-ehr-patient
- context-ehr-encounter
- context-standalone-patient
- context-standalone-encounter
- permission-offline
- permission-patient
- permission-user
- permission-v1
- permission-v2
- authorize-post
- name: SMART-on-FHIR OAuth2 (patient / FollowMyHealth surface)
  type: oauth2
  standard: SMART App Launch 2.0.0
  service_base: https://api.practicefusion.com/fhir/fmh/r4/v1/{organizationId}
  issuer: https://muauthentication.followmyhealth.com/api/v1/practicefusion/{organizationId}
  flows:
  - flow: authorizationCode
    authorizationUrl: https://muauthentication.followmyhealth.com/api/v1/practicefusion/{organizationId}/authorize
    tokenUrl: https://muauthentication.followmyhealth.com/api/v1/practicefusion/{organizationId}/token
    pkce: S256
  - flow: clientCredentials
    tokenUrl: https://muauthentication.followmyhealth.com/api/v1/practicefusion/{organizationId}/token
  introspection_endpoint: https://muauthentication.followmyhealth.com/api/v1/practicefusion/{organizationId}/introspect
  jwks_uri: https://muauthentication.followmyhealth.com/api/jwks
  source: well-known/practice-fusion-fmh-smart-configuration.json
  note: >-
    Patient-access (FMH) endpoints are delegated to FollowMyHealth, the
    patient-engagement platform of Veradigm — Practice Fusion's parent company —
    which is why this SMART configuration, served from api.practicefusion.com,
    names muauthentication.followmyhealth.com as its issuer. Capabilities and
    grant types are identical to the provider surface.
- name: Patient Fusion consumer identity (OIDC)
  type: openIdConnect
  issuer: https://auth.patientfusion.com/
  discovery: https://auth.patientfusion.com/.well-known/openid-configuration
  authorizationUrl: https://auth.patientfusion.com/authorize
  tokenUrl: https://auth.patientfusion.com/oauth/token
  userinfo_endpoint: https://auth.patientfusion.com/userinfo
  jwks_uri: https://auth.patientfusion.com/.well-known/jwks.json
  revocation_endpoint: https://auth.patientfusion.com/oauth/revoke
  registration_endpoint: https://auth.patientfusion.com/oidc/register
  device_authorization_endpoint: https://auth.patientfusion.com/oauth/device/code
  token_endpoint_auth_methods_supported: [client_secret_basic, client_secret_post, private_key_jwt, none]
  code_challenge_methods_supported: [S256, plain]
  scopes_supported: [openid, profile, offline_access, name, given_name, family_name, nickname, email, email_verified, picture, created_at, identities, phone, address]
  protected_api: https://api2.practicefusion.com/phr/patient/v1
  source: well-known/practice-fusion-patientfusion-openid-configuration.json
  note: >-
    Full RFC 8414 / OIDC Discovery document served anonymously and identically at
    both /.well-known/openid-configuration and /.well-known/oauth-authorization-server.
    This is the identity provider for the Patient Fusion personal health record
    API documented in the PDS API Developer Guide.
registration:
  process: PDS API Partner Registration -> approval -> PDS API Portal application
  url: https://pfpds.practicefusion.com/s/Registration
  terms: https://www.practicefusion.com/pds-api/termsofservice/
  application_inputs: [application name, description, privacy policy, JWKS URL, redirect URLs, launch URL, requested scopes]
  self_serve: false
  sandbox: false
  note: Credentials are issued by email after manual approval; there is no self-serve key and no test environment.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/practice-fusion-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.