FHIR Debugger
Paste SMART on FHIR scopes and see per-resource permissions (create, read, update, delete, search), launch context and identity scopes, with warnings.
How to analyze SMART scopes
- Paste scopes separated by spaces or new lines, exactly as they appear in an authorization request or in a token response's
scope. - See, per resource type, which operations each scope allows (create, read, update, delete, search), for which context (
patient/,user/,system/), and which launch-context and identity scopes are present. - Read the warnings: wildcards, mixed v1 and v2 syntax, identity scopes without
openid, and similar issues.
Scopes are analyzed locally in your browser.
Worked example
launch openid fhirUser offline_access patient/Patient.r patient/Observation.rs user/*.read
The analyzer reports:
launch— EHR launch: the app receives the launch context from the EHR session.openid fhirUser— an id_token identifying the user, with afhirUserclaim.offline_access— a refresh token that keeps working after the user logs out.patient/Patient.r— read the current patient's Patient resource.patient/Observation.rs— read and search the current patient's Observations.user/*.read— warning: a wildcard granting read access to every resource type the user can see, and a warning for mixing SMART v1 (.read) with v2 (.rs) syntax.
v1 and v2 at a glance
| v1 | v2 equivalent |
|---|---|
patient/Observation.read | patient/Observation.rs |
patient/Observation.write | patient/Observation.cud |
patient/Observation.* | patient/Observation.cruds |
SMART v2 also allows search-parameter restrictions, such as patient/Observation.rs?category=http://terminology.hl7.org/CodeSystem/observation-category|laboratory. Servers declare support with permission-v1 and permission-v2 in their smart-configuration.
Least privilege
Request the narrowest scopes your app needs. Reviewers of app registrations, and the people approving your app, see the scope list. patient/*.cruds or user/*.read invites rejection, and a token with broad scopes does more damage if it leaks. After authorization, compare the granted scope with what you asked for, and handle missing permissions gracefully.
FAQ
Why does the server grant fewer scopes than I asked for?
Servers and users can decline scopes: the user may untick permissions, the server may not support a resource type, or your registration may not allow it. The scope in the token response is the source of truth.
Are my scopes sent anywhere?
No. The analysis runs in this page.
Does it support SMART v2 granular scopes?
Yes for the resource and permission part. A scope with search parameters, such as patient/Observation.rs?category=...|laboratory, is read as Observation read and search for the patient. The query restriction itself is shown as part of the scope and isn't evaluated.
What's the difference between patient/, user/ and system/?
patient/ limits access to the patient in the launch context, user/ grants what the signed-in user can see, and system/ is for backend services with no user. SMART on FHIR Developer Guide covers each.
FHIR Toolbox is a free collection of HL7 FHIR tools by Omindra Labs. The tools process your data in your browser; it is not uploaded for normal tool operations.