IDENTITY & TRUST CONNECTORS
Best Practices / APIs & SDK / Next Steps
6 of 6Verify and link patients, professionals, organizations and trust frameworks while keeping authentication, identity proofing and authorization separate.
Architecture RecapBest PracticesIdentity APIsSDKsSecurityGo-LiveProduction
Secure by Design
Apply identity, privacy and regulatory controls from day one.
Interoperable
Use OIDC/SAML/eIDAS/FHIR/X.509 standards where appropriate.
Governed
Separate authentication, identity verification and authorization.
Future Ready
Design for revalidation, revocation and evolving national/EU frameworks.
Architecture Recap
1
External Providers & Registries
LuxTrust, PSC, eIDAS, RPPS, FINESS and other trusted sources
2
Identity & Trust Layer
Federation, certificates, identity linking and registry adapters
3
Entity Context
Patients, professionals, organizations and tenants
4
Authorization
Memberships, roles, scopes, consent and purpose
5
Applications
Mediloop and partner applications
Best Practices
Use trusted national/European identity providers and registries
Validate professional and organization status regularly
Never grant access based only on authentication
Enforce least privilege and tenant-aware authorization
Keep external and Mediloop identities linked, not merged
Human review for ambiguous patient matches
Check certificate revocation and expiry
Log all identity/linking/access events
Implement consent and purpose limitation
Support safe key/certificate rotation
APIs & SDK
typescriptCopy
import { MediloopIdentity } from '@mediloop/sdk';
// Illustrative SDK API.
const result = await identity.linkProfessional({
provider: 'pro-sante-connect',
externalId: 'RPPS12345678901',
tenantId: 'tenant_123',
autoLink: false,
});Illustrative until public Identity SDK contracts are frozen.
Security & Compliance
GDPR / eIDAS / national healthcare requirements
Secure secrets and certificates
Strong token/assertion validation
Role/membership/status revalidation
Consent/purpose limitation
Tamper-evident audit and incident response
Go-Live Checklist
Provider registration and production credentials complete
Redirects/endpoints/certificates validated
Identity-link policies peer reviewed
Authorization paths tested independently
Revocation, expiry and provider outage tested
Audit and alerts verified
Support/runbooks ready
Developer Integration Surface
| Surface | Operation / resource | Use | Status |
|---|---|---|---|
| Identity API | verify / resolve / link / unlink | Entity identity workflows | Versioned when frozen |
| OIDC/SAML | Federation flows | External authentication | Standards |
| FHIR | Patient / Practitioner / Organization | Interoperability representation | FHIR |
| PKI | mTLS / X.509 / OCSP / CRL | System/professional trust | Standard |
| SDK | Typed identity helpers | Developer productivity | Published versions only |
Next Steps
Start in sandbox
Implement one identity type end-to-end
Add authorization and consent
Test adverse identity/trust cases
Complete provider onboarding
Monitor revalidation and certificates continuously