Rhapsody · Authentication Profile

Rhapsody Authentication

Authentication

Rhapsody secures its APIs with oauth2 and openIdConnect across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

HealthcareUnited StatesInteroperabilityIntegration EngineFHIRHL7EMPITerminologyHealth DataMCPAPI Gateway
Methods: oauth2, openIdConnect Schemes: 2 OAuth flows: authorizationCode API key in:

Security Schemes

docs-portal-sso oauth2
axon-agent-sso openIdConnect

Source

Authentication Profile

rhapsody-authentication.yml Raw ↑
generated: '2026-08-14'
method: searched
source: >-
  Observed 307 redirect from https://docs.rhapsody.health/ to the AWS Cognito
  hosted UI (lyniate-docs.auth.us-east-1.amazoncognito.com/oauth2/authorize);
  https://rhapsody.health/solutions/rhapsody-axon/ ;
  https://rhapsody.health/solutions/guardian/
note: >-
  Rhapsody's product REST/administration and FHIR API reference is gated behind
  docs.rhapsody.health, so the product APIs' own security schemes are not
  publicly observable and are NOT asserted here (no public OpenAPI to derive
  from). What IS observable is the authentication fronting the developer surface:
  the documentation portal and the Axon agent both sit behind enterprise SSO.
  This profile records that observed surface honestly; it is not a claim about
  the product API token model.
summary:
  types: [oauth2, openIdConnect]
  oauth2_flows: [authorizationCode]
  gated: true
schemes:
- name: docs-portal-sso
  surface: Developer documentation portal (docs.rhapsody.health)
  type: oauth2
  flow: authorizationCode
  pkce: S256
  provider: AWS Cognito (user pool "lyniate-docs", us-east-1)
  authorizationUrl: https://lyniate-docs.auth.us-east-1.amazoncognito.com/oauth2/authorize
  scopes: [openid, email, profile]
  evidence: 307 redirect from docs host to Cognito /oauth2/authorize with response_type=code
- name: axon-agent-sso
  surface: Rhapsody Axon AI agent (chat.axon.rhapsody.health)
  type: openIdConnect
  provider: OneLogin
  access: Existing Rhapsody / Corepoint customers only
  evidence: Axon solution page states access via OneLogin for existing customers
gateway_supported_schemes:
  product: Rhapsody Guardian
  url: https://rhapsody.health/solutions/guardian/
  note: >-
    These are the authentication protocols Rhapsody's healthcare API gateway
    supports for the APIs a CUSTOMER publishes through it — quoted from the
    Guardian product page ("Guardian supports OAuth 2.0, SMART on FHIR, and Basic
    Auth"). They describe what the product can enforce, not the token model of a
    Rhapsody-operated public endpoint, which remains gated.
  schemes:
  - oauth2
  - smart-on-fhir
  - http-basic
product_api_auth:
  status: gated
  detail: >-
    Rhapsody and Corepoint expose REST administration APIs (Corepoint 7.5.3
    Administration REST API) and FHIR APIs whose authentication is documented in
    the gated developer portal; not verifiable from a public specification.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/rhapsody-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.