Authorization header. A token belongs to one organization. There are two kinds:
That’s why Photon ships Prescribe. It signs the prescriber in, holds their token, and runs the signing and sending, so your frontend never handles a token or calls GraphQL itself. We don’t recommend calling the API directly from a frontend. When you need lower-level control in the browser, use the JavaScript client: it handles sign-in, tokens and the workflow rules for you.
Permissions
read: covers drafting. write: covers the step that commits: changing a patient, signing a prescription, sending an order.
A user token carries the permissions of the person’s role. Prescribers have all of them. Other roles, such as medical operations, have everything except write:prescription.
A machine token can send an order once a prescriber has signed every prescription on it.
Credentials
Find both kinds in your dashboard under Settings → Developers.- Application credentials are a public
client_idand a list of allowed URLs. The list must include every domain your app runs on. Use them with Prescribe’s React components or the JavaScript client. - Backend credentials are a
client_idand aclient_secret. Keep the secret on your server, out of client-side code and version control.
User tokens
With Prescribe, you don’t handle user tokens:
Behind each of these, the prescriber signs in at
auth.neutron.health with Auth0’s authorization code flow (with PKCE), for the audience https://api.neutron.health, and picks their organization. The token they get can do whatever their role allows, including signing.
Machine tokens
Use a machine token from your backend to sync patients, draft prescriptions and draft orders. Exchange your Backend credentials for one:Response
expires_in: 86400). Cache it and request a new one shortly before it expires. Don’t request one for every call.
Calling the API
Send either kind of token as a bearer token to the GraphQL endpoint:ping is a health check that touches no records. Use it to test a token.
When a token is refused
A missing, invalid or expired token fails the whole request. The response has a top-levelerrors array and no data:
UnauthorizedError in the mutation’s result. For example, a machine token that tries to sign gets one:
requiredPermission. Retrying with the same token gets the same error. See Errors.