Spruce Health · Authentication Profile
Spruce Health Authentication
Authentication
The Spruce Health API has exactly one credential: a long-lived organization Bearer token. There is no OAuth, no OIDC, no mTLS, no per-user credential and no scope system - a token carries the full permissions of the organization it belongs to. The interesting part of Spruce's auth posture is not the scheme but the gate in front of it: a token cannot be created at all until Spruce Support has enabled API access for the organization.
Spruce Health secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.
HealthcareHIPAACommunicationsSecure MessagingTelehealthPatient EngagementContactsConversationsMessagingSMSVoiceVoIPFaxVideoWebhookSchedulingTranscriptionEHR IntegrationCompliance
Methods: http
Schemes: 1
OAuth flows:
API key in:
Security Schemes
spruceAPIToken http
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.