VOA Health · Authentication Profile
Voa Health Authentication
Authentication
Voa uses a two-token model. A long-lived Auth Token identifies the integrating partner (dev convenience, sent as the x-voa-token header). For production, that Auth Token is exchanged per-consultation for a short-lived Bearer JWT (POST /integration/identify/) which authorizes iFrame/plugin embedding and all Voa integration API calls, including RNDS. Voa's own server-to-RNDS leg additionally uses ICP-Brasil A1 mutual-TLS (not exposed to API clients).
VOA Health declares 3 security scheme(s) across its OpenAPI definitions.
CompanyHealthHealthcareClinical DocumentationEHRFHIRRNDSArtificial IntelligenceBrazil
Methods:
Schemes: 3
OAuth flows:
API key in:
Security Schemes
x-voa-token apiKey
http
mutualTLS