Mediloop

Identity & SSO

Integrate secure authentication, single sign-on and healthcare professional identity with Mediloop.

Available in sandboxProduction approval required

Standards

OAuth 2.0 + OpenID Connect

Security

Authorization Code + PKCE

Healthcare identity

France + Luxembourg

Access

Sandbox public · production approved

Overview

Mediloop Identity provides a standards-based boundary for authentication and authorization. Public developers can build and test in sandbox; production access is controlled.

Architecture

France

Pro Santé Connect → CPS/e-CPS → RPPS

Luxembourg

LuxTrust → approved registry verification

Standard

Mediloop OIDC / OAuth 2.0

Identity surfaces

SurfacePurposeAudience
OIDCSign-in and identity claimsApplications
OAuth 2.0Delegated API accessApplications
Professional identityVerified healthcare identityHealthcare professionals
Citizen identityPatient/citizen sign-inPatient-facing apps

Environment access

EnvironmentAccessNotes
SandboxPublic developer accessTest identities and non-production data
ProductionApproved partners onlyOnboarding, review and explicit enablement

Regional identity

Professional verification and organization/tenant membership are separate concerns. A verified practitioner identity does not itself grant access to an organization.

Security notes

Use least-privilege scopes, exact redirect URI matching, PKCE for public clients, short-lived access tokens and secure server-side storage for confidential credentials. Do not infer authorization from identity claims alone.

Errors

ErrorMeaning
invalid_requestMalformed or incomplete protocol request
invalid_clientClient authentication or registration failed
invalid_grantAuthorization grant is invalid or expired
access_deniedUser, policy or approval denied access