This section walks you through the setup needed when Smile CDR is playing the role of the Requesting payer (Target), meaning it's the one reaching out to other payers to get member data. Getting this setup right means Smile can securely connect to other payers, find the right member records, and bring that data into your system.
Following the Smile CDR documentation for setting up OIDC server definitions, create a server definition for each Source Payer you'll be connecting to.
system_to_system_data_exchange Target module for P2PConfigure the server definition with the following key fields:
| Field | Description | Example/Value |
|---|---|---|
| Server Name | Identifier for the server | p2p-server |
| Issuer | Exact Issuer URL of Source Payer's OIDC | https://source-payer.com/ |
| Client ID | Client ID Smile will use to auth to the server | p2p-client-jwt |
| Authentication Method | How Smile authenticates to the server | CLIENT_SECRET_BASIC or PRIVATE_KEY_JWT |
| Client Secret | Client Secret presented to the server | *** |
| Client Auth Keystore ID | Used when using PRIVATE_KEY_JWT | default-keystore |
| Well-Known Configuration URl | Optional. OpenID Connect configuration URL | https://source-payer/smartauth_p2p/.well-known/openid-configuration |
| Request Scopes | Scopes to request | openid cdr_all_user_authorities |
| FHIR Base URL | Source Payer's FHIR endpoint | https://source-payer.com/fhir |
| Token Endpoint | Optional. OAuth2 token endpoint | https://source-payer.com/oauth/token |
| Custom Token Parameters | Customized token parameters for this OIDC server | Patient |
| Response Type | Expected response format | code id_token token |
| Organization ID | Identification code to specify an org or business | Organizaton/org1 |
{
"nodeId" : "Master",
"moduleId" : "system_to_system_data_exchange_target",
"issuer" : "http://localhost:9300/smartauth_p2p",
"name" : "p2p-server",
"audience" : "",
"authWellKnownConfigUrl" : "http://localhost:9300/smartauth_p2p/.well-known/openid-configuration",
"clientAuthenticationKeystoreId" : "default-keystore",
"clientAuthenticationMethod" : "PRIVATE_KEY_JWT",
"customTokenParams" : "Patient",
"federationRegistrationId" : "4754414d-b0d5-46c1-810a-bd52e3f0892c",
"federationRequestScopes" : "openid cdr_all_user_authorities",
"federationTokenUrl" : "http://localhost:9300/smartauth_p2p/oauth/token",
"fhirEndpointUrl" : "http://localhost:8004/payer-source-fhir",
"notes" : "",
"organizationId" : "Organization/org1",
"responseType" : "code id_token token",
"tokenIntrospectionClientId" : "p2p-client-jwt",
"tokenIntrospectionClientSecret" : "",
"validationJwkFile" : "",
"validationJwkText" : ""
}
The example above populates both federationTokenUrl (Token Endpoint) and authWellKnownConfigUrl (Well-Known Configuration URl), but only one of them is needed. Smile CDR resolves the token endpoint for outbound requests in this order:
federationTokenUrl, when set, is used as the token endpoint directly, and no .well-known discovery request is made.authWellKnownConfigUrl, when set, is fetched exactly as configured, including any query string, and its token_endpoint is used.{fhirEndpointUrl}/.well-known/smart-configuration is fetched and its token_endpoint is used. fhirEndpointUrl (FHIR Base URL) is always required.Create an authorization script as per Smile CDR's federated OAuth2/OIDC documentation:
/**
* P2P Target Payer Authorization Script
* Handles authorization for outbound P2P requests
*/
function onAuthenticateSuccess(theOutcome) {
// Extract user information from the token
// Set the user ID from the token
}
For more details on executing P2P exchanges, see P2P Execute Exchange.
Before invoking P2P operations, ensure:
You are about to leave the Smile Digital Health documentation and navigate to the Open Source HAPI-FHIR Documentation.