Public surface / Payer Patient Access APIs
Premera Blue Cross Patient Access API
This endpoint declares a complete, interoperable public surface.
Observed surface
- Base URL
https://opala.tech/patient-access/premera/v1/fhir-r4- Category
- Payer Patient Access APIs
- Availability
- answered 16 of the last 16 daily checks (100%)
- Last answered
- 2026-10-03 (answered on this run)
- Vantage agreement
- reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks
What each vantage saw
| Vantage | Result | What it saw | Condition |
|---|---|---|---|
github-actions/macos-latest | reached | answered in 592 ms | HTTP 200 |
github-actions/ubuntu-latest | reached | answered in 299 ms | HTTP 200 |
github-actions/windows-latest | reached | answered in 343 ms | HTTP 200 |
Vantages on one network are one network’s view sampled several times. A rule applied to that network’s address space reaches every one of them at once and reads exactly like agreement.
Interpretation
A grade describes two public discovery documents at one point in time. It does not inspect patient data, authenticated behavior, or clinical quality.
Read the scoring method →This endpoint's full report: what was observed, what was not, and what would change it →
What its CapabilityStatement declares, resource by resource →
Findings
Observed since 2026-09-18; no changes to declared capability recorded.
Declared app-to-server access
What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded. An absent field is reported as absent, not as a refusal: a document that does not mention a field has not said anything about it.
| Question | Answer | What the document says | Where it is declared |
|---|---|---|---|
| Declares private_key_jwt client authentication at the token endpoint | declared | token_endpoint_auth_methods_supported lists private_key_jwt among 3 | SMART discovery: token_endpoint_auth_methods_supported |
| Declares the client_credentials grant, which SMART Backend Services uses | declared | grant_types_supported lists client_credentials among 5 | SMART discovery: grant_types_supported |
| Declares the client-confidential-asymmetric capability | declared | capabilities lists client-confidential-asymmetric among 19 | SMART discovery: capabilities |
| Declares system-level scopes | declared | 5508 of 16691 scopes_supported are system/ scopes | SMART discovery: scopes_supported |
| Declares an export operation | declared | export is declared on Group, the whole server | CapabilityStatement: rest.operation and rest.resource.operation |
| Instantiates the Bulk Data Access implementation guide | not listed | 2 canonicals are instantiated and none is Bulk Data's | CapabilityStatement: instantiates |
Registry provenance
How this entry was verified
base URL printed as the 'Patient Access API Capability Statement' on the page docs.opala.com publishes as the 'Premera Dev Toolkit'. Live CapabilityStatement retrieved unauthenticated from the davis-ca residential vantage on 2026-09-13: fhirVersion 4.0.1, 33 resource types, 78 supportedProfile canonicals, implementation.url matching the requested base exactly; publisher and software 'Opala', which is Premera's vendor. Attributed to Premera by a link chain from Premera's own site, not by Premera printing this address: https://www.premera.com/visitor/developers, read on 2026-09-18 by a headless-browser render with its sections expanded because the page is built client-side, describes the Patient Access API (protected by the OpenID Connect flow of OAuth 2.0), names Opala as Premera's interoperability partner, and sends developers to https://www.opala.com/developer-toolkit-premera, which redirects to the toolkit page above, and to developersupport@opala.com. Premera's page does not print the Patient Access base URL itself (recorded 2026-09-13). No later re-check is recorded, so the date above is the last time anyone checked this entry against the live endpoint.
This is an observational snapshot of a public, unauthenticated surface. It is not an audit, a ranking of care quality, or a statement about anyone's regulatory compliance. See how we grade.
Every observation on record for this endpoint, with the dates it answered and the dates it did not.