FHIR Debugger

Paste a SMART on FHIR smart-configuration document and check endpoints, PKCE, grant types and capabilities, with warnings for missing or inconsistent fields.

How to check a SMART configuration

  1. Open [your FHIR base URL]/.well-known/smart-configuration in your browser or with curl, and copy the JSON.
  2. Paste it here. The inspector lists the endpoints, supported grant types, PKCE methods, authentication methods, scopes and capabilities.
  3. Fix the warnings: missing required fields, or values that contradict each other.

This tool only inspects the text you paste. It doesn't fetch anything from your server.

What it checks

FieldWhy it matters
authorization_endpoint, token_endpointRequired. Clients can't launch without them
capabilitiesClients use it to discover launch modes (launch-ehr, launch-standalone), client types and context support. Missing it is a warning
code_challenge_methods_supportedMust include S256. SMART v2 doesn't permit plain
grant_types_supportedShould include authorization_code, plus client_credentials for backend services
issuer, jwks_uriRequired when sso-openid-connect is declared, and expected for asymmetric client authentication
scopes_supportedRecommended, so clients know which scopes they can request
permission-v1 / permission-v2Tells clients which scope syntax the server understands

A minimal, valid example

{
  "issuer": "https://auth.example.org",
  "authorization_endpoint": "https://auth.example.org/authorize",
  "token_endpoint": "https://auth.example.org/token",
  "jwks_uri": "https://auth.example.org/.well-known/jwks.json",
  "grant_types_supported": ["authorization_code"],
  "code_challenge_methods_supported": ["S256"],
  "scopes_supported": ["openid", "fhirUser", "launch", "launch/patient", "patient/*.rs", "offline_access"],
  "capabilities": ["launch-ehr", "launch-standalone", "client-public", "context-ehr-patient", "context-standalone-patient", "sso-openid-connect", "permission-v2"]
}

Common problems

  • Endpoints on a different host than expected — fine if intended, but double-check proxies didn't rewrite them to internal hostnames.
  • plain listed as a PKCE method — remove it. Only S256 is allowed in SMART v2.
  • sso-openid-connect declared but no issuer or jwks_uri — clients can't validate id_tokens.
  • No capabilities — clients have to guess which launch modes work.
  • Configuration served only at the legacy location — older servers put SMART endpoints in the CapabilityStatement's security extension. SMART v2 requires .well-known/smart-configuration.

SMART on FHIR Developer Guide explains how clients use each field during discovery and launch.

FAQ

Why doesn't the inspector fetch the URL for me?

Fetching from the browser would need your server to allow cross-origin requests, and keeping the tool paste-only means it never contacts your systems. Copy the JSON with a browser tab or curl -s [base]/.well-known/smart-configuration.

Is the configuration sent anywhere?

No. The JSON you paste is parsed and checked in this page.

Which SMART version are the checks based on?

SMART App Launch 2.x. Several checks, such as requiring S256 for PKCE and flagging plain, are v2 rules. Servers that only implement v1 may legitimately miss some recommended fields.

Where do I find my server's configuration?

At [FHIR base URL]/.well-known/smart-configuration, for example https://fhir.example.org/r4/.well-known/smart-configuration. It must be served without authentication so clients can discover endpoints.

FHIR Toolbox is a free collection of HL7 FHIR tools by Omindra Labs. The tools process your data in your browser; it is not uploaded for normal tool operations.