⌘K

Health CompaniesGuide

API clients and credentials

Sandbox self-issuance versus governed Production issuance.

On this page

Sandbox credentials

An authorized Health Company administrator or developer may issue a Sandbox credential only when all of these hold:

  • Canonical, active organization membership
  • The API client is active
  • An approved, active Sandbox Program grant exists
  • The requested scopes are permitted

Permitted Sandbox scopes: programs:read, catalog:read, serviceability:read, subjects:write, orders:write, orders:read, orders:cancel, results:read, events:read. webhooks:manage is never self-issued.

  • The secret is displayed once and never again; only a prefix, hash and metadata are stored.
  • Credentials are bound to one client and the Sandbox environment, carry no Production privilege, and can be revoked.

Production credentials

Important

The Health Company workspace cannot activate Production or issue a Production credential because a Program exists. Production issuance remains governed by laboratory/Solia readiness, approval and security requirements.

Related resources