Public surface / EHR vendor sandboxes
Medplum public API
This endpoint declares a complete, interoperable public surface.
Observed surface
- Base URL
https://api.medplum.com/fhir/R4- Category
- EHR vendor sandboxes
- Availability
- answered 58 of the last 58 daily checks (100%)
- Last answered
- 2026-10-03 (answered on this run)
- Vantage agreement
- reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks
What each vantage saw
| Vantage | Result | What it saw | Condition |
|---|---|---|---|
github-actions/macos-latest | reached | answered in 38 ms | HTTP 200 |
github-actions/ubuntu-latest | reached | answered in 605 ms | HTTP 200 |
github-actions/windows-latest | reached | answered in 421 ms | HTTP 200 |
Vantages on one network are one network’s view sampled several times. A rule applied to that network’s address space reaches every one of them at once and reads exactly like agreement.
Interpretation
A grade describes two public discovery documents at one point in time. It does not inspect patient data, authenticated behavior, or clinical quality.
Read the scoring method →This endpoint's full report: what was observed, what was not, and what would change it →
What its CapabilityStatement declares, resource by resource →
Findings
Declared capability changes
- 2026-09-09: software_version: '5.1.37-627079f' -> '5.1.37-0c4d54c'
- 2026-09-10: software_version: '5.1.37-0c4d54c' -> '5.1.37-a834432'
- 2026-09-11: software_version: '5.1.37-a834432' -> '5.1.37-2436608'
- 2026-09-12: software_version: '5.1.37-2436608' -> '5.1.37-a9b62fb'
- 2026-09-15: software_version: '5.1.37-a9b62fb' -> '5.1.38-148f059'
- 2026-09-16: software_version: '5.1.38-148f059' -> '5.1.39-a4523f7'
- 2026-09-17: software_version: '5.1.39-a4523f7' -> '5.1.39-6ffc6eb'
- 2026-09-18: software_version: '5.1.39-6ffc6eb' -> '5.1.39-830c511'
- 2026-09-18: software_version: '5.1.39-830c511' -> '5.1.39-6e99ae7'
- 2026-09-22: software_version: '5.1.39-6e99ae7' -> '5.1.39-2fe66c9'
- 2026-09-23: software_version: '5.1.39-2fe66c9' -> '5.1.39-ab2bf85'
- 2026-09-24: software_version: '5.1.39-ab2bf85' -> '5.1.40-c196169'
- 2026-09-25: software_version: '5.1.40-c196169' -> '5.1.42-89c6095'
- 2026-09-26: software_version: '5.1.42-89c6095' -> '5.1.42-298e653'
- 2026-09-28: software_version: '5.1.42-298e653' -> '5.1.42-890af94'
- 2026-09-29: software_version: '5.1.42-890af94' -> '5.1.42-2ec3843'
- 2026-09-30: software_version: '5.1.42-2ec3843' -> '5.1.43-dfbf43c'
- 2026-10-01: software_version: '5.1.43-dfbf43c' -> '5.2.0-30b2a62'
- 2026-10-02: software_version: '5.2.0-30b2a62' -> '5.2.0-4e9a937'
- 2026-10-03: software_version: '5.2.0-4e9a937' -> '5.2.1-e0db1fc'
Declared app-to-server access
What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded. An absent field is reported as absent, not as a refusal: a document that does not mention a field has not said anything about it.
| Question | Answer | What the document says | Where it is declared |
|---|---|---|---|
| Declares private_key_jwt client authentication at the token endpoint | declared | token_endpoint_auth_methods_supported lists private_key_jwt among 3 | SMART discovery: token_endpoint_auth_methods_supported |
| Declares the client_credentials grant, which SMART Backend Services uses | declared | grant_types_supported lists client_credentials among 4 | SMART discovery: grant_types_supported |
| Declares the client-confidential-asymmetric capability | declared | capabilities lists client-confidential-asymmetric among 17 | SMART discovery: capabilities |
| Declares system-level scopes | not listed | none of 8 scopes_supported is a system/ scope | SMART discovery: scopes_supported |
| Declares an export operation | declared | export is declared on Group | CapabilityStatement: rest.operation and rest.resource.operation |
| Instantiates the Bulk Data Access implementation guide | declared | instantiates http://hl7.org/fhir/uv/bulkdata/CapabilityStatement/bulk-data | CapabilityStatement: instantiates |
Registry provenance
How this entry was verified
live CapabilityStatement fetch; software identifies as 'medplum' (recorded 2026-08-05). Re-checked 2026-08-19: live CapabilityStatement re-fetch from the davis-ca residential vantage; fhirVersion 4.0.1, 146 resource types, publisher 'Medplum', software 'medplum 5.1.30-76fa156'.
This is an observational snapshot of a public, unauthenticated surface. It is not an audit, a ranking of care quality, or a statement about anyone's regulatory compliance. See how we grade.
Every observation on record for this endpoint, with the dates it answered and the dates it did not.