Token scopes are generally available. Practice admins can assign scopes on self-managed credentials from the Elation UI. For credentials that are not self-managed, contact Support to enable token scopes.
Overview
Token scopes allow you to restrict an access token’s permissions to only the API resources it needs. When requesting a token via the Get Token endpoint, you can specify one or more scopes using thescope parameter.
If no scope is specified, the token defaults to the apiv2 global scope, which grants access to all API resources.
Practice admins can also assign scopes directly to a set of credentials when generating them from the Elation UI. See Self-service API credential management for details.
Scope Format
Scopes follow the pattern:- resource: The API resource name (e.g.,
patients,allergies,lab_orders). - permission: Either
readorwrite.
Permissions
readgrants access to the resource’sGETendpoints.writegrants access to the resource’sPOST,PUT,PATCH, andDELETEendpoints.
Nested resources
Nested endpoints are controlled by their parent resource’s scope. For example,system/patients.read and system/patients.write control access to the patient insurance card image endpoint at /api/2.0/patients/{patient_id}/policies/{policy_id}/card-images.
Visit note and document signing are governed by a separate opt-in mechanism, but are permissioned under system/visit_notes.write.
Requesting Scopes
Pass a space-separated list of scopes in thescope parameter when requesting a token. Because the body is application/x-www-form-urlencoded, spaces between scopes must be URL-encoded (typically as %20 or +):
Combining Scopes
Scopes can be combined to grant a token access to multiple resources. For example, a token withsystem/patients.read system/medications.read system/medications.write can read patients and both read and write medications.
Impersonation Scope
Theact_as_user scope allows a token to make requests on behalf of a user in your practice. It grants no data access on its own and must be combined with at least one resource scope. See User Impersonation for details. On self-managed APIv2 credentials, practice admins enable it with the Allow API Impersonation checkbox.