Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

DEVELOPER

Quick Start

Complete one synthetic end-to-end Observation flow while preserving identity, scope, FHIR semantics, idempotency and correlation.

01 / CONCEPT

Integration contract

01

Prerequisites

Registered sandbox application, OAuth client, approved Observation scope and synthetic subject.

02

Authentication

Use the client type and OAuth 2.1/OIDC flow assigned to the application; user-facing clients use Authorization Code + PKCE.

03

Request

Send a FHIR R4 Observation with synthetic identifiers and an idempotency key.

04

Verify

Inspect status, correlation ID and integration logs; deliberately repeat the request to validate idempotency.

02 / WORKFLOW

From sandbox to evidence

  1. 01Obtain sandbox token
  2. 02Create synthetic Observation payload
  3. 03POST with FHIR media type and idempotency key
  4. 04Validate response and OperationOutcome on failure
  5. 05Inspect correlation in Integration Logs
  6. 06Repeat using an error case
03 / CODE

Submit Observation — synthetic data only

curl
curl -X POST https://sandbox.example.invalid/fhir/Observation \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/fhir+json" \
  -H "Idempotency-Key: demo-obs-001" \
  --data '{"resourceType":"Observation","status":"final","subject":{"reference":"Patient/synthetic-001"},"code":{"text":"Synthetic systolic blood pressure"},"valueQuantity":{"value":120,"unit":"mmHg"}}' 
Java
var req = HttpRequest.newBuilder(URI.create(base + "/fhir/Observation"))
  .header("Authorization", "Bearer " + token)
  .header("Content-Type", "application/fhir+json")
  .header("Idempotency-Key", "demo-obs-001")
  .POST(HttpRequest.BodyPublishers.ofString(syntheticObservationJson))
  .build();
var res = HttpClient.newHttpClient().send(req, HttpResponse.BodyHandlers.ofString());
JavaScript
const res = await fetch(`${base}/fhir/Observation`, {
  method: "POST",
  headers: { Authorization: `Bearer ${token}`, "Content-Type": "application/fhir+json", "Idempotency-Key": "demo-obs-001" },
  body: JSON.stringify(syntheticObservation)
});
if (!res.ok) throw await res.json();
Kotlin
val request = Request.Builder()
  .url("$base/fhir/Observation")
  .header("Authorization", "Bearer $token")
  .header("Content-Type", "application/fhir+json")
  .header("Idempotency-Key", "demo-obs-001")
  .post(syntheticObservationJson.toRequestBody("application/fhir+json".toMediaType()))
  .build()
Swift
var request = URLRequest(url: URL(string: base + "/fhir/Observation")!)
request.httpMethod = "POST"
request.setValue("Bearer \(token)", forHTTPHeaderField: "Authorization")
request.setValue("application/fhir+json", forHTTPHeaderField: "Content-Type")
request.setValue("demo-obs-001", forHTTPHeaderField: "Idempotency-Key")
request.httpBody = syntheticObservationData
04 / SECURITY & PRODUCTION

Production is an evidence decision

Quick Start proves only a synthetic Observation path. Production requires real integration ownership, approved scopes, credential protection, error/retry tests, monitoring and recovery evidence.

Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access