{
  "app_to_server": {
    "answers": [
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares private_key_jwt client authentication at the token endpoint",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "private_key_jwt",
        "source": "SMART discovery: token_endpoint_auth_methods_supported"
      },
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares the client_credentials grant, which SMART Backend Services uses",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "client_credentials",
        "source": "SMART discovery: grant_types_supported"
      },
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares the client-confidential-asymmetric capability",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "client_confidential_asymmetric",
        "source": "SMART discovery: capabilities"
      },
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares system-level scopes",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "system_scopes",
        "source": "SMART discovery: scopes_supported"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Declares an export operation",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "0 operations are declared and none is named export",
        "key": "export_operation",
        "source": "CapabilityStatement: rest.operation and rest.resource.operation"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Instantiates the Bulk Data Access implementation guide",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "0 canonicals are instantiated and none is Bulk Data's",
        "key": "bulk_data_guide",
        "source": "CapabilityStatement: instantiates"
      }
    ],
    "note": "What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded."
  },
  "dimensions": [
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R1",
          "max_points": 60,
          "message": "/metadata answers with HTTP 2xx over HTTPS: reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks",
          "observed": true,
          "ok": true,
          "points": 60,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R2",
          "max_points": 40,
          "message": "/metadata responded in 286 ms (median across 3 reachable vantages on one network)",
          "observed": true,
          "ok": true,
          "points": 40,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "reachability",
      "score": 100,
      "title": "Reachability"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T1",
          "max_points": 30,
          "message": "fhirVersion declared: '4.0.1' (expected 4.x)",
          "observed": true,
          "ok": true,
          "points": 30,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T2",
          "max_points": 20,
          "message": "software name/version missing",
          "observed": true,
          "ok": false,
          "points": 0,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T3",
          "max_points": 25,
          "message": "6 resource types declared",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T4",
          "max_points": 25,
          "message": "6/6 declared resources document their interactions",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "transparency",
      "score": 80,
      "title": "Capability transparency"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/us/core/",
          "code": "I1",
          "max_points": 40,
          "message": "US Core / CARIN / Da Vinci profiles declared in rest.resource.supportedProfile",
          "observed": true,
          "ok": true,
          "points": 40,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I2",
          "max_points": 35,
          "message": "SMART .well-known/smart-configuration absent or incomplete",
          "observed": true,
          "ok": false,
          "points": 0,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I3",
          "max_points": 25,
          "message": "OAuth/SMART security service declared in CapabilityStatement",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "interop",
      "score": 65,
      "title": "Interop readiness"
    }
  ],
  "drift_alternations": [],
  "drift_events": [],
  "endpoint": {
    "availability": "answered 16 of the last 16 daily checks (100%)",
    "base_url": "https://api-bcbsal-prd.safhir.io/v1/api/carin-bb",
    "endpoint_id": "bcbs-alabama-patient-access",
    "expects_fhir": "r4",
    "failure_kinds": [],
    "grade": "B",
    "interop_score": 65,
    "kind": "payer",
    "last_answered": "2026-10-03",
    "name": "Blue Cross and Blue Shield of Alabama Patient Access API",
    "observed_since": "2026-09-18",
    "reachability_score": 100,
    "reachable": "true",
    "reverified_date": "",
    "transparency_score": 80,
    "vantages_reached": 3,
    "vantages_reporting": 3,
    "verification_basis": "live_capability",
    "verified_date": "2026-09-13",
    "verified_method": "host and path printed in Blue Cross and Blue Shield of Alabama's own 'FHIR Documentation' PDF, published at bcbsal.org, under the heading 'Base URLs': 'The base url for each endpoint can be found on the website: https://api-bcbsal-prd.safhir.io/v1/api/', with the CARIN BB surface named on the next line as https://api-bcbsal-prd.safhir.io/v1/api/carin-bb/openapi.json. Live CapabilityStatement retrieved unauthenticated from the davis-ca residential vantage: fhirVersion 4.0.1, 6 resource types, 11 CARIN Blue Button supportedProfile canonicals. The document's publisher element reads 'HL7 Financial Management Working Group', which is the implementation guide's publisher and not the payer's, so attribution rests on BCBSAL printing the host in its own document"
  },
  "generated_at": "2026-10-03 15:21 UTC",
  "schema_version": 2,
  "vantage": "reconciled from github-actions/macos-latest, github-actions/ubuntu-latest, github-actions/windows-latest",
  "vantages": [
    {
      "elapsed_ms": 286,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/macos-latest"
    },
    {
      "elapsed_ms": 152,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/ubuntu-latest"
    },
    {
      "elapsed_ms": 500,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/windows-latest"
    }
  ]
}