Documentation
Registering the backend app with your EHR once.
Clinical Extract is registered with your EHR vendor as a backend app: a signed-JWT client authentication, read-only system scopes, the study Group. Your organization enables it once, and later studies reuse the connection. This page covers the registration as the specification defines it, then each vendor's version.
1 The three steps
Register, activate, export.
- Register at the vendor's app registration, outside your environment. Clinical Extract is a backend app with system access; its client authentication is a signed JWT (RS384) with its public key as a JWKS, and its scopes are one
system/<Resource>.readper exported type. The vendor issues the client ID. - Activate at your organization's EHR: the client is enabled, the FHIR base URL is given and the study Group is named.
- Export from Clinical Extract in your environment: the token request, the Group kickoff, the status poll, the NDJSON downloads and the two files it writes.
2 What the vendor asks for
What every EHR vendor asks for at registration.
- App type
- Backend, system-level: no user launch, no patient login. Some vendors call it a System app or a Backend Systems app.
- Client authentication
- A signed JWT (
private_key_jwt, RS384); the public key at Clinical Extract's JWKS URL, or as an uploaded certificate. - Scopes
- Read-only system scopes, one per resource type the study reads, plus Group (Listing 1).
- Redirect URI
- None. A backend app has no browser flow.
system/Group.read the study cohort, where the export starts system/Patient.read system/Encounter.read system/Condition.read system/Observation.read system/MedicationRequest.read system/Procedure.read
3 Your organization
Enable the client, give the base URL, name the Group.
Activation is your organization's side of the registration: enable the client ID for your instance, tenant or practice; hand Clinical Extract the FHIR base URL (and the token endpoint, when the vendor issues one rather than publishing it in the SMART configuration); and name the study Group, the FHIR Group resource the export runs against. The cohort builder gives your EHR team the criteria and the count for it.
4 By EHR
The same steps in each vendor's terms.
5 Questions
Questions about registration
What kind of app is Clinical Extract to the EHR?
A backend app with system access: no user launches it, no patient signs in. It authenticates with a signed JWT (SMART Backend Services) and asks for read-only system scopes, one per resource type the study reads.
Which scopes does it request?
system/Group.read for the cohort and one system/<Resource>.read per exported type: Patient, Encounter, Condition, Observation, MedicationRequest, Procedure for the example breast cancer study in Listing 1. A study that reads fewer types carries fewer scopes.
Does the vendor need our public key?
Once: as the JWKS URL Clinical Extract serves at /.well-known/jwks.json, or as an uploaded certificate where the vendor takes that. The private key stays in your environment.
What does our organization do after the vendor registration?
Enable the client for your organization, give Clinical Extract your FHIR base URL (and the token endpoint when the vendor issues one), and name the study Group. The EHR pages give each vendor’s exact steps.
How long does registration take?
The registration is a form. Most of the elapsed time is the vendor’s key sync and your organization’s activation, both one-time steps.
Next
See Clinical Extract run on one of your studies.
Tell us which EHR you run and what the study or registry needs. We reply within one business day to set a meeting time.