Public surface / Payer Patient Access APIs
CMS Blue Button 2.0 (Medicare)
This endpoint declares a solid public surface with minor gaps.
Observed surface
- Base URL
https://api.bluebutton.cms.gov/v2/fhir- Category
- Payer Patient Access APIs
- Availability
- answered 58 of the last 58 daily checks (100%)
- Last answered
- 2026-10-03 (answered on this run)
- Vantage agreement
- reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks
What each vantage saw
| Vantage | Result | What it saw | Condition |
|---|---|---|---|
github-actions/macos-latest | reached | answered in 376 ms | HTTP 200 |
github-actions/ubuntu-latest | reached | answered in 306 ms | HTTP 200 |
github-actions/windows-latest | reached | answered in 1000 ms | HTTP 200 |
Vantages on one network are one network’s view sampled several times. A rule applied to that network’s address space reaches every one of them at once and reads exactly like agreement.
Interpretation
A grade describes two public discovery documents at one point in time. It does not inspect patient data, authenticated behavior, or clinical quality.
Read the scoring method →This endpoint's full report: what was observed, what was not, and what would change it →
What its CapabilityStatement declares, resource by resource →
Findings
- Needs attention: 3 profile canonical(s) declared in rest.resource.profile, none of them US Core, CARIN, or Da Vinci; also checked rest.resource.supportedProfile, instantiates, imports, meta.profileI1Spec ↗
- Pass: SMART discovery document present and completeI2Spec ↗
- Pass: OAuth/SMART security service declared in CapabilityStatementI3Spec ↗
Declared capability changes
- 2026-08-07: software_version: '2.259.0' -> '2.260.0'
- 2026-08-12: software_version: '2.260.0' -> '2.262.0'
- 2026-08-19: software_version: '2.262.0' -> '2.264.0'
- 2026-08-28: software_version: '2.264.0' -> '2.265.0'
- 2026-08-29: software_version: '2.265.0' -> '2.266.0'
- 2026-09-04: software_version: '2.266.0' -> '2.267.0'
- 2026-09-11: software_version: '2.267.0' -> '2.268.0'
- 2026-09-22: software_version: '2.268.0' -> '2.269.0'
- 2026-09-29: software_version: '2.269.0' -> '2.270.0'
- 2026-09-30: software_version: '2.270.0' -> '2.271.0'
- 2026-10-01: software_version: '2.271.0' -> '2.272.0'
Declared app-to-server access
What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded. An absent field is reported as absent, not as a refusal: a document that does not mention a field has not said anything about it.
| Question | Answer | What the document says | Where it is declared |
|---|---|---|---|
| Declares private_key_jwt client authentication at the token endpoint | not declared: the field is absent | the document has no token_endpoint_auth_methods_supported | SMART discovery: token_endpoint_auth_methods_supported |
| Declares the client_credentials grant, which SMART Backend Services uses | not listed | grant_types_supported lists 1 and not client_credentials | SMART discovery: grant_types_supported |
| Declares the client-confidential-asymmetric capability | not listed | capabilities lists 8 and not client-confidential-asymmetric | SMART discovery: capabilities |
| Declares system-level scopes | not listed | none of 9 scopes_supported is a system/ scope | SMART discovery: scopes_supported |
| Declares an export operation | not listed | 0 operations are declared and none is named export | CapabilityStatement: rest.operation and rest.resource.operation |
| Instantiates the Bulk Data Access implementation guide | not listed | 0 canonicals are instantiated and none is Bulk Data's | CapabilityStatement: instantiates |
Registry provenance
How this entry was verified
live CapabilityStatement fetch; publisher confirmed via implementation description 'gov.cms.bfd:bfd-server-war' and software 'Blue Button API' (recorded 2026-08-04). Re-checked 2026-08-19: live CapabilityStatement re-fetch from the davis-ca residential vantage; fhirVersion 4.0.1, 3 resource types, publisher 'Centers for Medicare & Medicaid Services', software 'Blue Button API: Direct 2.264.0'.
This is an observational snapshot of a public, unauthenticated surface. It is not an audit, a ranking of care quality, or a statement about anyone's regulatory compliance. See how we grade.
Every observation on record for this endpoint, with the dates it answered and the dates it did not.