openapi: 3.0.3 info: title: SMART Health IT Sandbox FHIR APIs Bulk Data Clinical Records API description: Public, free sandbox APIs operated by SMART Health IT (Computational Health Informatics Program, Boston Children's Hospital / Harvard Medical School) for building and testing SMART on FHIR apps. Three surfaces are described here. (1) The open FHIR R4 sandbox at https://r4.smarthealthit.org - synthetic patient records served over plain FHIR REST with no authentication (DSTU2 and STU3 variants exist at r2/r3.smarthealthit.org). (2) The SMART App Launcher's protected FHIR R4 proxy at https://launch.smarthealthit.org/v/r4/fhir, which requires an OAuth 2.0 access token obtained through the HL7 SMART App Launch flow at /v/r4/auth/authorize and /v/r4/auth/token (no client registration needed). (3) The reference Bulk Data server at https://bulk-data.smarthealthit.org/fhir, which implements FHIR Bulk Data $export with SMART Backend Services JWT authentication. All data is synthetic; these servers are for development and testing, never real PHI. version: '1.0' contact: name: SMART Health IT url: https://smarthealthit.org license: name: Apache 2.0 url: https://github.com/smart-on-fhir/smart-launcher-v2/blob/main/LICENSE servers: - url: https://r4.smarthealthit.org description: Open FHIR R4 sandbox (no authentication required) - url: https://launch.smarthealthit.org/v/r4/fhir description: SMART App Launcher protected FHIR R4 proxy (SMART App Launch OAuth 2.0) - url: https://bulk-data.smarthealthit.org/fhir description: Reference Bulk Data server (SMART Backend Services authentication) security: - smartOnFhir: [] - {} tags: - name: Clinical Records description: Observations, conditions, medications, encounters, allergies, and immunizations. paths: /Observation: get: operationId: searchObservations tags: - Clinical Records summary: Search observations description: Searches Observation resources - vital signs, lab results, and other measurements - typically scoped to a patient with the patient search parameter and filtered by category or code. parameters: - $ref: '#/components/parameters/Patient' - $ref: '#/components/parameters/Count' - name: category in: query description: Observation category (for example vital-signs or laboratory). schema: type: string - name: code in: query description: LOINC or other code identifying the observation. schema: type: string responses: '200': description: A searchset Bundle of Observation resources. content: application/fhir+json: schema: $ref: '#/components/schemas/Bundle' /Condition: get: operationId: searchConditions tags: - Clinical Records summary: Search conditions description: Searches Condition resources (problems and diagnoses) for a patient. parameters: - $ref: '#/components/parameters/Patient' - $ref: '#/components/parameters/Count' responses: '200': description: A searchset Bundle of Condition resources. content: application/fhir+json: schema: $ref: '#/components/schemas/Bundle' /MedicationRequest: get: operationId: searchMedicationRequests tags: - Clinical Records summary: Search medication requests description: Searches MedicationRequest resources (prescriptions and medication orders) for a patient. parameters: - $ref: '#/components/parameters/Patient' - $ref: '#/components/parameters/Count' responses: '200': description: A searchset Bundle of MedicationRequest resources. content: application/fhir+json: schema: $ref: '#/components/schemas/Bundle' /Encounter: get: operationId: searchEncounters tags: - Clinical Records summary: Search encounters description: Searches Encounter resources (visits and admissions) for a patient. parameters: - $ref: '#/components/parameters/Patient' - $ref: '#/components/parameters/Count' responses: '200': description: A searchset Bundle of Encounter resources. content: application/fhir+json: schema: $ref: '#/components/schemas/Bundle' /AllergyIntolerance: get: operationId: searchAllergyIntolerances tags: - Clinical Records summary: Search allergies and intolerances description: Searches AllergyIntolerance resources for a patient. parameters: - $ref: '#/components/parameters/Patient' - $ref: '#/components/parameters/Count' responses: '200': description: A searchset Bundle of AllergyIntolerance resources. content: application/fhir+json: schema: $ref: '#/components/schemas/Bundle' /Immunization: get: operationId: searchImmunizations tags: - Clinical Records summary: Search immunizations description: Searches Immunization resources (vaccination history) for a patient. parameters: - $ref: '#/components/parameters/Patient' - $ref: '#/components/parameters/Count' responses: '200': description: A searchset Bundle of Immunization resources. content: application/fhir+json: schema: $ref: '#/components/schemas/Bundle' /DocumentReference: get: operationId: searchDocumentReferences tags: - Clinical Records summary: Search document references description: Searches DocumentReference resources (clinical notes and documents) for a patient. parameters: - $ref: '#/components/parameters/Patient' - $ref: '#/components/parameters/Count' responses: '200': description: A searchset Bundle of DocumentReference resources. content: application/fhir+json: schema: $ref: '#/components/schemas/Bundle' components: schemas: Bundle: type: object description: A FHIR R4 searchset Bundle. properties: resourceType: type: string enum: - Bundle type: type: string total: type: integer link: type: array items: type: object properties: relation: type: string url: type: string entry: type: array items: type: object properties: fullUrl: type: string resource: $ref: '#/components/schemas/FhirResource' FhirResource: type: object description: Any FHIR R4 resource, identified by its resourceType element. properties: resourceType: type: string id: type: string additionalProperties: true parameters: Patient: name: patient in: query description: Scope the search to a patient, for example "Patient/123" or "123". schema: type: string Count: name: _count in: query description: Maximum number of entries per page of the returned Bundle. schema: type: integer securitySchemes: smartOnFhir: type: oauth2 description: HL7 SMART App Launch OAuth 2.0 profile, used by the launcher's protected FHIR proxy. The open r4.smarthealthit.org sandbox requires no authentication; the Bulk Data server uses SMART Backend Services (client_credentials with a signed JWT assertion). flows: authorizationCode: authorizationUrl: https://launch.smarthealthit.org/v/r4/auth/authorize tokenUrl: https://launch.smarthealthit.org/v/r4/auth/token scopes: openid: OpenID Connect identity. fhirUser: Identity of the launching user as a FHIR resource. launch/patient: Request a patient in context at launch. patient/*.read: Read all resources for the patient in context. user/*.read: Read all resources the user can access. system/*.read: Backend services system-level read access. clientCredentials: tokenUrl: https://launch.smarthealthit.org/v/r4/auth/token scopes: system/*.read: Backend services system-level read access. externalDocs: description: SMART on FHIR developer documentation url: https://docs.smarthealthit.org