Frequently Asked Questions

Common questions about connecting to the Patient Access API.

The API supports the Authorization Code grant with PKCE (response_type=code) as defined in the SMART App Launch 2.2.0 specification.

Refresh tokens (offline_access scope) are also supported for long-lived access without re-prompting the patient. The Implicit grant and Resource Owner Password Credentials grant are not supported.

Registration requests are typically reviewed within 3–5 business days. You will receive an email at the address you provided when a decision is made.

Per CMS Interoperability requirements, registrations cannot be denied without a specific documented security justification. If your registration is denied, the email will include the reason.

If you have not heard back after 5 business days, contact us using the details in the next question.

For technical questions or registration support, contact the developer support team:

Getting Started Guide Register an Application