# Authorization flows

**Portal version:** 0.1.0  
**Updated:** 2026-08-28  
**Source menu item:** Authorization flows  
**Availability:** Private preview · default-OFF

> The source foundation exists, but no general production activation or public self-service program is claimed.

Authorization joins publisher release proof, independent certification, hospital activation, current user access, and exact FHIR scope.

## What you can use now

- A certifier chooses exact scopes; a different hospital admin activates that exact event.
- Recheck authorization before each PHI context disclosure.

## Current limits

- No generic public OAuth install flow is available.

## Next step

Start with the [medOS Developer overview](/developers/platform/overview) and confirm the target hospital’s enabled contracts before production work.

## Canonical references

- [FHIR R4 integration](/integrations/fhir)
- [Public API](/backend/public-api)
- [Security and compliance](/architecture/security-and-compliance)
- [Developer portal status and coverage](/developers/platform/changelog)

