Skip to content

Healthcare Users ​

Manage Keycloak users that participate in SMART on FHIR flows. Users created here get Keycloak accounts and can optionally be linked to FHIR Person/Practitioner resources and external identity providers.

API Endpoints ​

MethodPathDescription
GET/admin/healthcare-users/List users (paginated, searchable)
POST/admin/healthcare-users/Create a new user
GET/admin/healthcare-users/:userIdGet user details
PUT/admin/healthcare-users/:userIdUpdate user
DELETE/admin/healthcare-users/:userIdDelete user
GET/admin/healthcare-users/:userId/federated-identitiesList linked IdPs
POST/admin/healthcare-users/:userId/federated-identities/:providerLink external IdP
DELETE/admin/healthcare-users/:userId/federated-identities/:providerUnlink external IdP

Creating a User ​

Required fields:

  • Username -- Keycloak login name
  • First name / Last name
  • Email -- used for password resets and notifications
  • Enabled -- whether the account is active immediately
  • Credentials -- initial password (can be marked temporary)

Optional fields:

  • Attributes -- key-value pairs stored on the Keycloak user (e.g., fhirUser, department)
  • Realm roles -- assign roles like clinician, admin, etc.
  • Groups -- Keycloak group membership

A user can be linked to external identity providers (SAML, OIDC, LDAP). This allows them to log in via those providers while maintaining a single Keycloak identity.

Use the federated-identities endpoints to:

  • List which providers a user is linked to
  • Link a new provider (requires the external user ID and username)
  • Unlink a provider

Launch Contexts ​

Per-user SMART launch context is managed via the Launch Contexts API. This controls what patient, encounter, fhirUser, and other context values are injected into tokens for that user.

Roles ​

Roles are managed separately via /admin/roles/:

MethodPathDescription
GET/admin/roles/List all realm roles
POST/admin/roles/Create role
GET/admin/roles/:roleNameGet role details
PUT/admin/roles/:roleNameUpdate role
DELETE/admin/roles/:roleNameDelete role
GET/admin/roles/clients/:clientIdList client-specific roles

Organizations ​

Users can be members of organizations (Keycloak Organizations feature):

MethodPathDescription
GET/admin/organizations/List organizations
POST/admin/organizations/Create organization
GET/admin/organizations/:orgId/membersList members
POST/admin/organizations/:orgId/membersAdd member
DELETE/admin/organizations/:orgId/members/:userIdRemove member

Organizations support per-org branding overrides via the /:orgId/branding endpoints.

User Federation (LDAP) ​

The Users page carries a User Federation sub-tab for LDAP directory connections, which imports and synchronizes users from an enterprise directory (Active Directory, OpenLDAP, and similar) into Keycloak rather than managing them here.

See User Federation for provider configuration, sync operations, and attribute mapping.

Proxy Smart — Healthcare Interoperability Platform