Body of POST /v1/physicians/{id}/session — mint a short-lived PHYSICIAN
SESSION token, the credential a clinician's browser uses to call the
physician-side routes directly (no API key in the page, no relay through
your server on every poll).
Requires the tenant API key: a session may not mint another (403 forbidden), which is what keeps a leaked browser token from renewing
itself. Mint it from your backend after YOUR authentication of the user —
this is the token-exchange half of single sign-on. If you also sent a
physician header on this call it must name the same physician (400).
The token is invalidated by an API-key rotation (like embed sessions):
re-mint on 401 unauthorized.
Body of
POST /v1/physicians/{id}/session— mint a short-lived PHYSICIAN SESSION token, the credential a clinician's browser uses to call the physician-side routes directly (no API key in the page, no relay through your server on every poll).Requires the tenant API key: a session may not mint another (
403 forbidden), which is what keeps a leaked browser token from renewing itself. Mint it from your backend after YOUR authentication of the user — this is the token-exchange half of single sign-on. If you also sent a physician header on this call it must name the same physician (400).The token is invalidated by an API-key rotation (like embed sessions): re-mint on
401 unauthorized.