Health CompaniesGuide
API clients and credentials
Sandbox self-issuance versus governed Production issuance.
On this page
Sandbox credentials
An authorized Health Company administrator or developer may issue a Sandbox credential only when all of these hold:
- Canonical, active organization membership
- The API client is active
- An approved, active Sandbox Program grant exists
- The requested scopes are permitted
Permitted Sandbox scopes: programs:read, catalog:read, serviceability:read, subjects:write, orders:write, orders:read, orders:cancel, results:read, events:read. webhooks:manage is never self-issued.
- The secret is displayed once and never again; only a prefix, hash and metadata are stored.
- Credentials are bound to one client and the Sandbox environment, carry no Production privilege, and can be revoked.
Production credentials
Important
The Health Company workspace cannot activate Production or issue a Production credential because a Program exists. Production issuance remains governed by laboratory/Solia readiness, approval and security requirements.