{
  "app_to_server": {
    "answers": [
      {
        "answer": "declared",
        "answer_text": "declared",
        "asks": "Declares private_key_jwt client authentication at the token endpoint",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "token_endpoint_auth_methods_supported lists private_key_jwt among 3",
        "key": "private_key_jwt",
        "source": "SMART discovery: token_endpoint_auth_methods_supported"
      },
      {
        "answer": "declared",
        "answer_text": "declared",
        "asks": "Declares the client_credentials grant, which SMART Backend Services uses",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "grant_types_supported lists client_credentials among 5",
        "key": "client_credentials",
        "source": "SMART discovery: grant_types_supported"
      },
      {
        "answer": "declared",
        "answer_text": "declared",
        "asks": "Declares the client-confidential-asymmetric capability",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "capabilities lists client-confidential-asymmetric among 19",
        "key": "client_confidential_asymmetric",
        "source": "SMART discovery: capabilities"
      },
      {
        "answer": "declared",
        "answer_text": "declared",
        "asks": "Declares system-level scopes",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "5508 of 16691 scopes_supported are system/ scopes",
        "key": "system_scopes",
        "source": "SMART discovery: scopes_supported"
      },
      {
        "answer": "declared",
        "answer_text": "declared",
        "asks": "Declares an export operation",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "export is declared on Group, the whole server",
        "key": "export_operation",
        "source": "CapabilityStatement: rest.operation and rest.resource.operation"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Instantiates the Bulk Data Access implementation guide",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "2 canonicals are instantiated and none is Bulk Data's",
        "key": "bulk_data_guide",
        "source": "CapabilityStatement: instantiates"
      }
    ],
    "note": "What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded."
  },
  "dimensions": [
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R1",
          "max_points": 60,
          "message": "/metadata answers with HTTP 2xx over HTTPS: reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks",
          "observed": true,
          "ok": true,
          "points": 60,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R2",
          "max_points": 40,
          "message": "/metadata responded in 343 ms (median across 3 reachable vantages on one network)",
          "observed": true,
          "ok": true,
          "points": 40,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "reachability",
      "score": 100,
      "title": "Reachability"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T1",
          "max_points": 30,
          "message": "fhirVersion declared: '4.0.1' (expected 4.x)",
          "observed": true,
          "ok": true,
          "points": 30,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T2",
          "max_points": 20,
          "message": "software name and version declared",
          "observed": true,
          "ok": true,
          "points": 20,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T3",
          "max_points": 25,
          "message": "33 resource types declared",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T4",
          "max_points": 25,
          "message": "33/33 declared resources document their interactions",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "transparency",
      "score": 100,
      "title": "Capability transparency"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/us/core/",
          "code": "I1",
          "max_points": 40,
          "message": "US Core / CARIN / Da Vinci profiles declared in CapabilityStatement.instantiates, rest.resource.supportedProfile",
          "observed": true,
          "ok": true,
          "points": 40,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I2",
          "max_points": 35,
          "message": "SMART discovery document present and complete",
          "observed": true,
          "ok": true,
          "points": 35,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I3",
          "max_points": 25,
          "message": "OAuth/SMART security service declared in CapabilityStatement",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "interop",
      "score": 100,
      "title": "Interop readiness"
    }
  ],
  "drift_alternations": [],
  "drift_events": [],
  "endpoint": {
    "availability": "answered 16 of the last 16 daily checks (100%)",
    "base_url": "https://opala.tech/patient-access/premera/v1/fhir-r4",
    "endpoint_id": "premera-patient-access",
    "expects_fhir": "r4",
    "failure_kinds": [],
    "grade": "A",
    "interop_score": 100,
    "kind": "payer",
    "last_answered": "2026-10-03",
    "name": "Premera Blue Cross Patient Access API",
    "observed_since": "2026-09-18",
    "reachability_score": 100,
    "reachable": "true",
    "reverified_date": "",
    "transparency_score": 100,
    "vantages_reached": 3,
    "vantages_reporting": 3,
    "verification_basis": "live_capability",
    "verified_date": "2026-09-13",
    "verified_method": "base URL printed as the 'Patient Access API Capability Statement' on the page docs.opala.com publishes as the 'Premera Dev Toolkit'. Live CapabilityStatement retrieved unauthenticated from the davis-ca residential vantage on 2026-09-13: fhirVersion 4.0.1, 33 resource types, 78 supportedProfile canonicals, implementation.url matching the requested base exactly; publisher and software 'Opala', which is Premera's vendor. Attributed to Premera by a link chain from Premera's own site, not by Premera printing this address: https://www.premera.com/visitor/developers, read on 2026-09-18 by a headless-browser render with its sections expanded because the page is built client-side, describes the Patient Access API (protected by the OpenID Connect flow of OAuth 2.0), names Opala as Premera's interoperability partner, and sends developers to https://www.opala.com/developer-toolkit-premera, which redirects to the toolkit page above, and to developersupport@opala.com. Premera's page does not print the Patient Access base URL itself"
  },
  "generated_at": "2026-10-03 15:21 UTC",
  "schema_version": 2,
  "vantage": "reconciled from github-actions/macos-latest, github-actions/ubuntu-latest, github-actions/windows-latest",
  "vantages": [
    {
      "elapsed_ms": 592,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/macos-latest"
    },
    {
      "elapsed_ms": 299,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/ubuntu-latest"
    },
    {
      "elapsed_ms": 343,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/windows-latest"
    }
  ]
}