# API authentication methods

**Portal version:** 0.1.0  
**Updated:** 2026-08-28  
**Source menu item:** API authentication methods  
**Availability:** Private preview · default-OFF

> The source foundation exists, but no general production activation or public self-service program is claimed.

Supported patterns include scoped FHIR integration keys and verified SMART/system-context JWTs when the target deployment enables them.

## What you can use now

- Select the narrowest server-to-server method supported by the hospital.
- Pin audience, issuer, resource type, operation, and tenant context.

## Current limits

- Credential issuance remains an administrator ceremony, not public self-service.

## Next step

Start with the [medOS Developer overview](/developers/platform/overview) and confirm the target hospital’s enabled contracts before production work.

## Canonical references

- [FHIR R4 integration](/integrations/fhir)
- [Public API](/backend/public-api)
- [Security and compliance](/architecture/security-and-compliance)
- [Developer portal status and coverage](/developers/platform/changelog)

