# eClinicalWorks > eClinicalWorks is a cloud-based EHR and practice-management platform used by more than 180,000 physicians > and 850,000 medical professionals. Its API surface is standards-based rather than proprietary: FHIR R4 > served by the "eCW FHIR Facade 1.6" behind SMART on FHIR / OAuth 2.0, split across a provider-facing > facade (fhir4.eclinicalworks.com) and a patient-facing healow facade (fhir4.healow.com). There is no > OpenAPI document — the machine-readable contract is the FHIR CapabilityStatement at each tenant's > /metadata, plus the SMART configuration at each tenant's /.well-known/smart-configuration. ## Key facts for an agent - **There is no global base URL.** Every base URL is tenant-scoped: `https://{facade}/fhir/r4/{practice_code}`. Resolve the practice's base URL from the published endpoint directory before calling anything. - **Discovery is per tenant too.** `/.well-known/smart-configuration` and `/metadata` only answer under a practice-code path; the host roots return 400. - **Nothing is callable anonymously.** All clinical reads require a SMART on FHIR bearer token; an unauthenticated GET returns 401 with a FHIR OperationOutcome. - **Rate limit: 250 requests/minute per practice code**, covering FHIR calls, /authorize and /token together. 429 on exhaustion, no Retry-After, resets on the wall-clock minute. - **No idempotency key** on any surface. - **No first-party SDK, no CLI, no GitHub organization, no Postman collection, no security.txt, no agent card.** ## Endpoint directories (ONC service base URL lists) - Provider-facing practices (17,229 endpoints on fhir4.eclinicalworks.com): https://fhir.eclinicalworks.com/ecwopendev/external/practiceList - healow patient-facing practices (17,291 endpoints on fhir4.healow.com): https://connect4.healow.com/apps/api/v1/fhir/activated_clinical_endpoints Both are live FHIR Bundles of Organization + Endpoint resources, roughly 15 MB each. ## APIs - [eClinicalWorks FHIR API (provider, backend, bulk)](https://fhir.eclinicalworks.com/ecwopendev/): SMART on FHIR EHR Launch, Standalone Launch, Backend Services, CDS Hooks, Group/$export bulk data. Base: https://fhir4.eclinicalworks.com/fhir/r4/{practice_code} - [healow Clinical API (patient-facing)](https://connect4.healow.com/apps/jsp/dev/r4/fhirClinicalDocumentation.jsp): patient-facing FHIR R4 reads. Base: https://fhir4.healow.com/fhir/r4/{practice_code} - [healow Scheduling API](https://connect4.healow.com/apps/jsp/dev/r4/fhirSchedulingDocumentation.jsp): FHIR Schedule, Slot and Appointment. Contract-gated. - [healow RPM Vendor (Tracker) API](https://connect4.healow.com/apps/jsp/dev/r4/fhirRpmVendorDocumentation.jsp): bidirectional device-order and observation ingestion. Base: https://connect4.healow.com/apps/api/v1/fhir/tracker ## Machine-readable contracts - FHIR R4 CapabilityStatement (provider facade): https://fhir4.eclinicalworks.com/fhir/r4/{practice_code}/metadata - FHIR R4 CapabilityStatement (healow facade): https://fhir4.healow.com/fhir/r4/{practice_code}/metadata - SMART configuration (486 scopes): https://fhir4.eclinicalworks.com/fhir/r4/{practice_code}/.well-known/smart-configuration - JWKS: https://oauthserver.eclinicalworks.com/oauth/oauth2/jwks ## Authorization - Authorize: https://oauthserver.eclinicalworks.com/oauth/oauth2/authorize - Token: https://oauthserver.eclinicalworks.com/oauth/oauth2/token - Grants: authorization_code, client_credentials, refresh_token. PKCE S256. private_key_jwt is RS384 only. - Client auth: client_secret_basic, client_secret_post, private_key_jwt, client_secret_jwt ## Docs - [Developer portal](https://fhir.eclinicalworks.com/ecwopendev/) - [Getting started](https://fhir.eclinicalworks.com/ecwopendev/documentation/getting-started) - [API documentation / supported scopes](https://fhir.eclinicalworks.com/ecwopendev/documentation) - [Backend authentication](https://fhir.eclinicalworks.com/ecwopendev/documentation/getting-started/backend/authentication) - [Bulk patient access specification](https://fhir.eclinicalworks.com/ecwopendev/documentation/getting-started/backend/patient-access) - [Token introspection](https://fhir.eclinicalworks.com/ecwopendev/documentation/getting-started/token-introspection) - [Error Code Reference Guide (PDF)](https://fhir.eclinicalworks.com/ecwopendev/documentation/fhirresources/create/Error%20Code%20Reference%20Guide.pdf) - [healow developer portal](https://connect4.healow.com/apps/jsp/dev/signIn.jsp) - [Certified EHR technology / ONC](https://www.eclinicalworks.com/resources/certified-ehr-technology/) - [Responsible disclosure policy](https://www.eclinicalworks.com/responsible-disclosure-policy/) - [Pricing](https://www.eclinicalworks.com/products-services/pricing/) - [Status](https://instatus.com/now/en/eclinicalworks.com) ## Support - Developer portal support: https://fhir.eclinicalworks.com/ecwopendev/documentation/contact-us - healow developer support: devsupport@healow.com - FHIR support: fhirfighters@eclinicalworks.com - Interoperability: interop@eclinicalworks.com - Security vulnerabilities: vulnerability@eclinicalworks.com ## API Evangelist artifacts - Authentication: https://raw.githubusercontent.com/api-evangelist/eclinicalworks/refs/heads/main/authentication/eclinicalworks-authentication.yml - OAuth scopes (486): https://raw.githubusercontent.com/api-evangelist/eclinicalworks/refs/heads/main/scopes/eclinicalworks-scopes.yml - Conventions: https://raw.githubusercontent.com/api-evangelist/eclinicalworks/refs/heads/main/conventions/eclinicalworks-conventions.yml - Error codes: https://raw.githubusercontent.com/api-evangelist/eclinicalworks/refs/heads/main/errors/eclinicalworks-error-codes.yml - Rate limits: https://raw.githubusercontent.com/api-evangelist/eclinicalworks/refs/heads/main/rate-limits/eclinicalworks-rate-limits.yml - Lifecycle: https://raw.githubusercontent.com/api-evangelist/eclinicalworks/refs/heads/main/lifecycle/eclinicalworks-lifecycle.yml - Conformance: https://raw.githubusercontent.com/api-evangelist/eclinicalworks/refs/heads/main/conformance/eclinicalworks-conformance.yml - Data model: https://raw.githubusercontent.com/api-evangelist/eclinicalworks/refs/heads/main/data-model/eclinicalworks-data-model.yml - Webhooks (healow RPM): https://raw.githubusercontent.com/api-evangelist/eclinicalworks/refs/heads/main/asyncapi/eclinicalworks-healow-rpm-webhooks.yml - Agent skills: https://raw.githubusercontent.com/api-evangelist/eclinicalworks/refs/heads/main/skills/_index.yml