# Permissions

**Portal version:** 0.1.0  
**Updated:** 2026-08-28  
**Source menu item:** Permissions  
**Availability:** Private preview · default-OFF

> The source foundation exists, but no general production activation or public self-service program is claimed.

Permissions are exact certified context fields, FHIR resources/operations, webhook topics, and browser capabilities.

## What you can use now

- Request the minimum read/search scope and list every browser capability.
- Certification and activation must match the same immutable scope set.

## Current limits

- Wildcards, write supersets, and hidden scope expansion are denied for remote app v1.

## Next step

Start with the [medOS Developer overview](/developers/platform/overview) and confirm the target hospital’s enabled contracts before production work.

## Canonical references

- [FHIR R4 integration](/integrations/fhir)
- [Public API](/backend/public-api)
- [Security and compliance](/architecture/security-and-compliance)
- [Developer portal status and coverage](/developers/platform/changelog)

