Mediloop
PlatformIdentity & SSOIdentity & SSO API Reference

Identity & SSO API Reference

Reference for public Identity & SSO protocols and endpoints. Internal verification and security operations are intentionally not exposed.

Available in sandboxProduction approval required

Standards

OAuth 2.0 + OpenID Connect

Security

Authorization Code + PKCE

Healthcare identity

France + Luxembourg

Access

Sandbox public · production approved

Overview

Mediloop Identity provides a standards-based boundary for authentication and authorization. Public developers can build and test in sandbox; production access is controlled.

Authorization

CapabilityUseStatus
Authorization Code + PKCEBrowser, mobile and native appsRecommended
OIDCAuthentication and identity claimsSupported
OAuth 2.0Delegated API authorizationSupported
Client credentialsApproved server-to-server integrationsPartner access

Token

OIDC scopes
openid profile email
# Additional healthcare or organization claims require explicit approval.

Security notes

Use least-privilege scopes, exact redirect URI matching, PKCE for public clients, short-lived access tokens and secure server-side storage for confidential credentials. Do not infer authorization from identity claims alone.

Errors

ErrorMeaning
invalid_requestMalformed or incomplete protocol request
invalid_clientClient authentication or registration failed
invalid_grantAuthorization grant is invalid or expired
access_deniedUser, policy or approval denied access