Notes

EHR launch and standalone launch

SMART on FHIR has two launch modes. Both end in the same place: an OAuth 2.0 access token for a FHIR R4 server. The difference is who starts the session.

In an EHR launch, the EHR opens the app and passes two values: the FHIR base URL (iss) and a launch token (launch). The app reads the EHR’s SMART configuration, sends the user to the authorization server, and exchanges the authorization code for a token. The launch token lets the EHR attach context, such as the current patient or encounter, when the granted scopes allow it.

In a standalone launch, the app starts on its own. There is no launch token from the EHR. The app still uses the FHIR base URL and the same authorization-code flow. If the workflow needs a patient and the app does not already have one, a launch/patient scope asks the EHR to let the user pick a patient.

Lynx Labs builds both. An EHR launch fits a workflow that starts inside the chart. A standalone launch fits a workflow that starts outside it, such as a scheduling desk or a voice assistant. The source system has to support the mode. Lynx Labs requests non-production access through that system’s developer program. The client organization enables production access.