Public surface / Payer Provider Directory APIs
Group Health Cooperative-SCW Provider Directory API
This endpoint could not be reached from any vantage on this run, so nothing about what it publishes was observed.
Observed surface
- Base URL
https://publicfhir.ghcscw.com- Category
- Payer Provider Directory APIs
- Availability
- answered 0 of the last 30 daily checks (0%)
- Last answered
- not in the recorded window
- Vantage agreement
- answered HTTP 502 from 3 of 3 vantages but returned no usable document: the endpoint is running and refusing this request, which is not the same as being unreachable: HTTP 502
What each vantage saw
| Vantage | Result | What it saw | Condition |
|---|---|---|---|
github-actions/macos-latest | not reached | HTTP 502 | HTTP 502, server_error |
github-actions/ubuntu-latest | not reached | HTTP 502 | HTTP 502, server_error |
github-actions/windows-latest | not reached | HTTP 502 | HTTP 502, server_error |
Vantages on one network are one network’s view sampled several times. A rule applied to that network’s address space reaches every one of them at once and reads exactly like agreement.
Interpretation
A grade describes two public discovery documents at one point in time. It does not inspect patient data, authenticated behavior, or clinical quality.
Read the scoring method →This endpoint's full report: what was observed, what was not, and what would change it →
What its CapabilityStatement declares, resource by resource →
Findings
- No answer: /metadata answered HTTP 502 from 3 of 3 vantages but returned no usable document: the endpoint is running and refusing this request, which is not the same as being unreachable: HTTP 502 (observed 2026-10-03)R1Spec ↗
- No answer: latency not measured: no vantage was answered (observed 2026-10-03)R2Spec ↗
Observed since 2026-09-04; no changes to declared capability recorded.
Declared app-to-server access
What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded. An absent field is reported as absent, not as a refusal: a document that does not mention a field has not said anything about it.
| Question | Answer | What the document says | Where it is declared |
|---|---|---|---|
| Declares private_key_jwt client authentication at the token endpoint | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: token_endpoint_auth_methods_supported |
| Declares the client_credentials grant, which SMART Backend Services uses | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: grant_types_supported |
| Declares the client-confidential-asymmetric capability | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: capabilities |
| Declares system-level scopes | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: scopes_supported |
| Declares an export operation | not retrieved on this run | no vantage retrieved the CapabilityStatement | CapabilityStatement: rest.operation and rest.resource.operation |
| Instantiates the Bulk Data Access implementation guide | not retrieved on this run | no vantage retrieved the CapabilityStatement | CapabilityStatement: instantiates |
Registry provenance
How this entry was verified
Listed on the organization's own publication of this base URL, not on a retrieved conformance document: base URL printed in running prose at https://ghcscw.com/developer-resources/, section 'Provider Directory API': 'The Provider Directory API is publicly available and does not require application registration or authentication. The endpoint for this API is: https://publicfhir.ghcscw.com', followed by the resources it serves. The published string carries zero-width spaces, evidently to defeat autolinking; they were stripped (recorded 2026-09-04). Published at https://ghcscw.com/developer-resources/. On the verification date this probe observed: no answer to an unauthenticated GET of /metadata on 2026-09-04. Not a dead name: the host resolves via CNAME to a live Azure Application Gateway (ghc-publicfhir-nc-agw.northcentralus.cloudapp.azure.com). A directory the publisher states requires no authentication was not readable on the date checked. No later re-check is recorded, so the date above is the last time anyone checked this entry against the live endpoint.
This is an observational snapshot of a public, unauthenticated surface. It is not an audit, a ranking of care quality, or a statement about anyone's regulatory compliance. See how we grade.
Every observation on record for this endpoint, with the dates it answered and the dates it did not.