ClientApplication | Medplum

On this page

Medplum client application for automated access.

Schema

Elements

Name Required Type Description
status code active | error | off
Details
The client application status. The status is active by default. The status can be set to error to indicate that the client application is not working properly. The status can be set to off to indicate that the client application is no longer in use.
name string Details
A name associated with the ClientApplication.
description string Details
A summary, characterization or explanation of the ClientApplication.
signInForm ClientApplicationSignInForm Details
Custom values for the Log In form.
welcomeString string Details
Welcome string for the Log In Form.
logo Attachment Details
Logo for the Log In Form.
secret string Details
Client secret string used to verify the identity of a client.
retiringSecret string Details
Old version of the client secret that is being rotated out. Instances of the client using this value should update to use the value in ClientApplication.secret
jwksUri uri Details
Optional JWKS URI for public key verification of JWTs issued by the authorization server (client_secret_jwt).
redirectUris uri[] Details
Optional redirect URI array used when redirecting a client back to the client application.
launchUri uri Details
Optional launch URI for SMART EHR launch sequence.
launchIdentifierSystems ClientApplicationLaunchIdentifierSystems[] Details
Optional array of identifier systems to use in SMART launch context. When specified, the resource's identifier with the matching system will be included in the SmartAppLaunch resource's reference and returned to the SMART app in the token response.
resourceType code Details
The resource type for which to use the identifier system (e.g., 'Patient', 'Encounter').
system uri Details
The identifier system URI to use for the specified resource type.
pkceOptional boolean Details
Flag to make PKCE optional for this client application. PKCE is required by default for compliance with Smart App Launch. It can be disabled for compatibility with legacy client applications.
identityProvider IdentityProvider Details
Optional external Identity Provider (IdP) for the client application.
accessTokenLifetime string Details
Optional configuration to set the access token duration
refreshTokenLifetime string Details
Optional configuration to set the refresh token duration
allowedOrigin string[] Details
Optional CORS allowed origin for the client application. By default, all origins are allowed.
defaultScope string[] Details
Optional default OAuth scope for the client application. This scope is used when the client application does not specify a scope in the authorization request.
certificateTrustStore string Details
Optional PEM-formatted certificates that are allowed to authenticate to this service via mutual TLS. Supports both Certificate Authorities (CAs) and self-signed certificates. Multiple certificates can be included.
redirectUri uri Details
@deprecated This field is deprecated. Use redirectUris instead.

Search Parameters

Name Type Description Expression
name string The name of the client application ClientApplication.name

Inherited Elements

Name Required Type Description
id string Logical id of this artifact
Details
The logical id of the resource, as used in the URL for the resource. Once assigned, this value never changes.
meta Meta Details
The metadata about the resource. This is content that is maintained by the infrastructure. Changes to the content might not always be associated with version changes to the resource.
implicitRules uri Details
A reference to a set of rules that were followed when the resource was constructed, and which must be understood when processing the content. Often, this is a reference to an implementation guide that defines the special rules along with other profiles etc.
language code Details
The base language in which the resource is written.
text Narrative Text summary of the resource, for human interpretation
Details
A human-readable narrative that contains a summary of the resource and can be used to represent the content of the resource to a human. The narrative need not encode all the structured data, but is required to contain sufficient detail to make it "clinically safe" for a human to just read the narrative. Resource definitions may define what content should be represented in the narrative to ensure clinical safety.
contained Resource[] Contained, inline Resources
Details
These resources do not have an independent existence apart from the resource that contains them - they cannot be identified independently, and nor can they have their own independent transaction scope.
extension Extension[] Additional content defined by implementations
Details
May be used to represent additional information that is not part of the basic definition of the resource.
modifierExtension Extension[] Extensions that cannot be ignored
Details
May be used to represent additional information that is not part of the basic definition of the resource and that modifies the understanding of the element that contains it and/or the understanding of the containing element's descendants.