Health1st AI Logo
All termsSecurity & identity

SMART on FHIR

SMART App Launch

SMART on FHIR is the OAuth 2.0 / OpenID Connect authorization framework that lets third-party apps securely launch against a FHIR API with scoped access.

SMART on FHIR (SMART App Launch) is the standard that governs how an application authenticates and is authorized to access a FHIR API. It layers OAuth 2.0 and OpenID Connect on top of FHIR, defining scopes that limit exactly which resources and operations an app may use and on whose behalf.

SMART App Launch 1.0.0 is part of the CMS-0057-F mandated stack and underpins the patient-access and provider-access APIs: it is what allows a patient's chosen third-party app, or a provider-facing app, to connect to a payer or EHR FHIR endpoint securely and with consent.

For implementers, SMART is the difference between a FHIR API that is technically present and one that is safely usable by outside apps at scale, with auditable, scoped access.

How this relates to Health1st

Health1st's Compliance & Consent Agent enforces SMART / OAuth2 / OIDC policy, scope, and consent on the APIs it helps expose, so access to translated FHIR data is authorized, provenance-tracked, and auditable.

Ready to turn months of interface work into days?

See a live HL7 v2 ↔ FHIR translation on your own message types. No obligation.

Back to the glossary