generated: '2026-08-14' method: searched source: https://docs.metriport.com/medical-api/getting-started/embedding description: >- Metriport's client-side embeddable surface. It is not a component library — there is no npm loader, no web component and no React binding. It is a hosted application that you either redirect the user to or render in an iframe, authorised by a short-lived embed token minted server-side with your API key. Distinct from the SDKs in packages/metriport-packages.yml, which are server-side. docs: - https://docs.metriport.com/medical-api/getting-started/embedding - https://docs.metriport.com/medical-api/api-reference/token/create-embed-token libraries: [] libraries_note: >- None. Integration is by URL, not by script tag or package install. The former Connect Widget (packages/connect-widget in the monorepo) belonged to the Devices API, which is no longer documented — see lifecycle/metriport-lifecycle.yml. families: embedded_app: description: >- Hosted Metriport views rendered inside your product. Two delivery modes — full-page redirect, or iframe — both loading the same embedded app URL with the embed token passed as the access_token query parameter. hosts: production: https://ehr.metriport.com/embed/app sandbox: https://ehr.sandbox.metriport.com/embed/app host_note: >- Tokens are environment-bound: a sandbox token must be used against the sandbox embedded app URL and a production token against the production one. components: - name: Patient View description: Displays a patient's medical data inside your application. - name: Transitions of Care (TCM) description: Monitors patient admissions, transfers and discharges. auth: mechanism: embed token minting_operation: Create Embed Token (POST https://api.metriport.com/medical/v1/token/embed) minting_requirement: >- Must be generated by your backend — creating an embed token requires the Metriport API key, which must never be exposed in browser code. request_field: expirationInSeconds max_expiration_seconds: 36000 max_expiration_human: 10 hours transport: Passed in the embedded app URL as the access_token parameter. guidance: Metriport recommends shorter expirations than the maximum. maintainers: - FN: Kin Lane email: kin@apievangelist.com