Agent skill

Hapi Fhir Server

by aehrc in aehrc/pathling

Expert guidance for implementing FHIR servers using HAPI FHIR Plain Server framework.

Apache-2.0Auto-check passedResearch & Science

Install Hapi Fhir Server

skills CLI
$ npx skills add aehrc/pathling --skill hapi-fhir-server -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aehrc/pathling hapi-fhir-server --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aehrc/pathling.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/hapi-fhir-server .claude/skills/hapi-fhir-server && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hapi-fhir-server
GitHub stars
137
Token cost
~2.6k tokens
SKILL.md length
284 words
Files
6 (incl. references)
Skills in repo
25
Repo updated
First seen
Licence
Apache-2.0

At a glance

Expert guidance for implementing FHIR servers using HAPI FHIR Plain Server framework.

  • Creating RESTful FHIR server implementations
  • SKILL.md covers Quick Start, Server Architecture, Core Patterns and Search Implementation, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Implementing resource providers

What it does

Hapi Fhir Server is an agent skill from aehrc/pathling. Expert guidance for implementing FHIR servers using HAPI FHIR Plain Server framework. Use this skill when creating RESTful FHIR server implementations, implementing resource providers, adding FHIR operations (read, create, update, delete, search, $operations), implementing server interceptors for logging, security, and validation, setting up authentication and authorisation, or configuring FHIR server behaviour. Trigger keywords include "HAPI", "FHIR server", "RestfulServer", "resource provider"…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/interceptors.md`, `references/operations.md` and `references/resource-providers.md`).

It sits in Research & Science, covering Clinical and healthcare research. The repository describes itself as: Tools that make it easier to use FHIR and clinical terminology within data analytics, built on Apache Spark. The licence is Apache-2.0.

When your agent uses it

  • Creating RESTful FHIR server implementations
  • Implementing resource providers
  • Adding FHIR operations (read
  • Implementing server interceptors for logging

Example prompts

  • “FHIR server”
  • “RestfulServer”
  • “resource provider”
  • “/hapi-fhir-server”

What it can do on your machine

Read from SKILL.md and the folder at commit 56a3b4a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hapi Fhir Server loads about 2.6k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 164 tokens; SKILL.md has 284 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~164
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aehrc/pathling at commit 56a3b4a, republished under its Apache-2.0 licence (© aehrc). 284 words, ~2,646 tokens.

Download SKILL.mdSave it as .claude/skills/hapi-fhir-server/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
hapi-fhir-server
description
Expert guidance for implementing FHIR servers using HAPI FHIR Plain Server framework. Use this skill when creating RESTful FHIR server implementations, implementing resource providers, adding FHIR operations (read, create, update, delete, search, $operations), implementing server interceptors for logging, security, and validation, setting up authentication and authorisation, or configuring FHIR server behaviour. Trigger keywords include "HAPI", "FHIR server", "RestfulServer", "resource provider", "IResourceProvider", "FHIR interceptor", "AuthorizationInterceptor", "FhirContext", "FHIR validation", "FHIR search", "FHIR operation".

HAPI FHIR Plain Server Implementation

Quick Start

Basic Server Setup
java
public class MyFhirServer extends RestfulServer {
    @Override
    protected void initialize() throws ServletException {
        setFhirContext(FhirContext.forR4());
        setResourceProviders(List.of(
            new PatientResourceProvider(),
            new ObservationResourceProvider()
        ));
        registerInterceptor(new ResponseHighlighterInterceptor());
    }
}
Minimal Resource Provider
java
public class PatientResourceProvider implements IResourceProvider {
    @Override
    public Class<Patient> getResourceType() { return Patient.class; }

    @Read
    public Patient read(@IdParam IdType id) {
        return loadPatient(id.getIdPart());
    }

    @Search
    public List<Patient> search(
            @OptionalParam(name = Patient.SP_FAMILY) StringParam family) {
        return searchPatients(family);
    }
}

Server Architecture

Component Hierarchy
RestfulServer (Servlet)
├── FhirContext (version-specific, expensive to create - reuse)
├── Resource Providers (IResourceProvider per resource type)
├── Plain Providers (cross-resource operations)
├── Interceptors (request/response hooks)
└── Configuration (paging, address strategy, encoding)
Server vs Storage Distinction
  • SERVER_xxx pointcuts: Request/response lifecycle hooks
  • STORAGE_xxx pointcuts: Data persistence hooks (must be triggered manually in Plain Server)

Core Patterns

CRUD Operations
OperationAnnotationKey Parameters
Read@Read@IdParam IdType
VRead@Read(version=true)@IdParam IdType (with version)
Create@Create@ResourceParam Patient
Update@Update@IdParam, @ResourceParam
Delete@Delete@IdParam IdType
Patch@Patch@IdParam, PatchTypeEnum, @ResourceParam String
Conditional Operations

Add @ConditionalUrlParam String to support conditional create/update/delete:

java
@Update
public MethodOutcome update(
        @ResourceParam Patient patient,
        @IdParam IdType id,
        @ConditionalUrlParam String conditional) {
    if (conditional != null) {
        // Find by search criteria in conditional URL
    }
    // Perform update
}
MethodOutcome Return
java
MethodOutcome outcome = new MethodOutcome();
outcome.setId(new IdType("Patient", "123", "1"));
outcome.setCreated(true);  // For create operations
return outcome;

Search Implementation

Parameter Types
TypeClassExample URL
StringStringParam?family=Smith
TokenTokenParam?identifier=mrn|123
DateDateParam/DateRangeParam?date=ge2020-01-01
ReferenceReferenceParam?subject=Patient/123
QuantityQuantityParam?value-quantity=gt5||kg
Multi-Value Logic
java
// OR logic (comma-separated): ?family=Smith,Jones
@OptionalParam(name = "family") StringOrListParam families

// AND logic (repeated param): ?family=Smith&family=Jones
@OptionalParam(name = "family") StringAndListParam families
Paging with IBundleProvider

For large results, return IBundleProvider instead of List<IBaseResource>:

java
@Search
public IBundleProvider search(...) {
    List<String> ids = findMatchingIds();
    return new SimpleBundleProvider(ids) {
        @Override
        public List<IBaseResource> getResources(int from, int to) {
            return loadResources(ids.subList(from, Math.min(to, ids.size())));
        }
    };
}

Configure paging provider on server:

java
FifoMemoryPagingProvider paging = new FifoMemoryPagingProvider(10);
paging.setDefaultPageSize(20);
paging.setMaximumPageSize(100);
setPagingProvider(paging);

Extended Operations ($operations)

java
@Operation(name = "$everything", idempotent = true)
public Bundle everything(
        @IdParam IdType patientId,
        @OperationParam(name = "start") DateType start,
        @OperationParam(name = "end") DateType end) {
    // Return bundle with patient and related resources
}
  • Instance-level: Include @IdParam
  • Type-level: No @IdParam, register on resource provider
  • Server-level: Register on plain provider (no IResourceProvider)
  • idempotent = true: Allows HTTP GET (only for primitive params)

Interceptors

Registration
java
registerInterceptor(new LoggingInterceptor());
registerInterceptor(new ResponseHighlighterInterceptor());
Custom Interceptor
java
@Interceptor
public class MyInterceptor {
    @Hook(Pointcut.SERVER_INCOMING_REQUEST_PRE_HANDLED)
    public void preHandle(RequestDetails details, HttpServletRequest request) {
        // Before request processing
    }

    @Hook(Pointcut.SERVER_OUTGOING_RESPONSE)
    public void postHandle(RequestDetails details, IBaseResource resource) {
        // After response generated
    }
}
Key Pointcuts
  • SERVER_INCOMING_REQUEST_PRE_PROCESSED: Earliest hook
  • SERVER_INCOMING_REQUEST_PRE_HANDLED: After handler selected
  • SERVER_OUTGOING_RESPONSE: Before response sent
  • SERVER_HANDLE_EXCEPTION: On any exception
Essential Built-in Interceptors
InterceptorPurpose
LoggingInterceptorRequest/response logging
ResponseHighlighterInterceptorHTML view for browsers
RequestValidatingInterceptorValidate incoming resources
ResponseValidatingInterceptorValidate outgoing resources
CorsInterceptorCORS support
ExceptionHandlingInterceptorCustom error responses

Security

Authentication Pattern
java
@Interceptor
public class AuthInterceptor {
    @Hook(Pointcut.SERVER_INCOMING_REQUEST_PRE_HANDLED)
    public void authenticate(RequestDetails details, HttpServletRequest request) {
        String auth = request.getHeader("Authorization");
        if (!validateToken(auth)) {
            throw new AuthenticationException("Invalid credentials");
        }
        details.getUserData().put("user", extractUser(auth));
    }
}
Authorisation with AuthorizationInterceptor
java
public class MyAuthInterceptor extends AuthorizationInterceptor {
    @Override
    public List<IAuthRule> buildRuleList(RequestDetails details) {
        String userId = (String) details.getUserData().get("user");
        return new RuleBuilder()
            .allow().read().allResources()
                .inCompartment("Patient", new IdType("Patient", userId))
            .andThen()
            .allow().write().allResources()
                .inCompartment("Patient", new IdType("Patient", userId))
            .andThen()
            .denyAll()
            .build();
    }
}

Validation

Setup
java
ValidationSupportChain chain = new ValidationSupportChain(
    new DefaultProfileValidationSupport(ctx),
    new InMemoryTerminologyServerValidationSupport(ctx),
    new CommonCodeSystemsTerminologyService(ctx)
);
FhirInstanceValidator validator = new FhirInstanceValidator(chain);
RequestValidatingInterceptor interceptor = new RequestValidatingInterceptor();
interceptor.addValidatorModule(validator);
interceptor.setFailOnSeverity(ResultSeverityEnum.ERROR);
registerInterceptor(interceptor);
Profile Validation

Add NpmPackageValidationSupport for implementation guide validation:

java
NpmPackageValidationSupport npm = new NpmPackageValidationSupport(ctx);
npm.loadPackageFromClasspath("classpath:package/us.core.tgz");

Exception Handling

ExceptionHTTP StatusUse Case
ResourceNotFoundException404Resource not found
InvalidRequestException400Bad request parameters
UnprocessableEntityException422Validation failure
AuthenticationException401Auth required
ForbiddenOperationException403Access denied
ResourceVersionConflictException409Version mismatch
InternalErrorException500Server error

Configuration

Server Address Strategy
java
// For reverse proxy
setServerAddressStrategy(new HardcodedServerAddressStrategy("https://api.example.com/fhir"));

// For Apache mod_proxy
setServerAddressStrategy(new ApacheProxyAddressStrategy(true));
Response Defaults
java
setDefaultResponseEncoding(EncodingEnum.JSON);
setDefaultPrettyPrint(true);
Multitenancy
java
setTenantIdentificationStrategy(new UrlBaseTenantIdentificationStrategy());
// Access via: details.getTenantId()

Detailed References

© aehrc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in .claude/skills/hapi-fhir-server of aehrc/pathling.

  • SKILL.md
  • references/interceptors.md
  • references/operations.md
  • references/resource-providers.md
  • references/search.md
  • references/security.md

Open the folder on GitHubat commit 56a3b4a

Compare with similar skills

Hapi Fhir Server next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hapi Fhir Server compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hapi Fhir Server this skillaehrc/pathling137—~2.6kAutomated safety check: PassApache-2.0
Fhir Developer SkillFreedomIntelligence/OpenClaw-Medical-Skills3.1k1 repos~2.5kAutomated safety check: PassNone
Clinical Trials Databasegoogle-deepmind/science-skills3.2k2 repos~3.2kAutomated safety check: PassApache-2.0
CHARLS Paper Reproduction Guidexjtulyc/MedgeClaw6171 repos~1.8kAutomated safety check: PassNone
Biomedical Analysis Dispatchxjtulyc/MedgeClaw6171 repos~2kAutomated safety check: PassNone
Research Proposalluwill/research-skills858—~4.4kAutomated safety check: NotesNone

Similar skills

  • Fhir Developer Skill

    FreedomIntelligence/OpenClaw-Medical-Skills

    FHIR API development guide for building healthcare endpoints.

    3.1k GitHub starsUsed in 1 repo~2.5k tokens
    Research & ScienceAuto-check passed
  • Clinical Trials Database

    google-deepmind/science-skills

    Query ClinicalTrials.gov via APIv2. An agent skill from google-deepmind/science-skills.

    3.2k GitHub starsUsed in 2 repos~3.2k tokens
    Research & ScienceAuto-check passed
  • Guides an agent through reproducing papers built on the CHARLS health and retirement survey, from variable mapping to cognition, depression and isolation scores.

    617 GitHub starsUsed in 1 repo~1.8k tokens
    Research & ScienceAuto-check passed
  • Routes bioinformatics, drug discovery, clinical and multi-omics tasks from a chat interface to Claude Code sessions running K-Dense scientific skills, with a live dashboard per task.

    617 GitHub starsUsed in 1 repo~2k tokens
    Research & ScienceAuto-check passed
  • Research Proposal

    luwill/research-skills

    A skill your agent uses when the user asks to write or draft a PhD / doctoral research proposal, research plan, 研究计划书, or 开题报告 — a forward-looking plan of background, gap, research questions…

    858 GitHub stars~4.4k tokensUpdated 9 days ago
    Research & ScienceAuto-check: notes
  • Medical Imaging Review

    LeonChaoX/qinyan-academic-skills

    Write comprehensive literature reviews for medical imaging AI research.

    943 GitHub starsUsed in 3 repos~1.1k tokens
    Research & ScienceAuto-check: notes

More from aehrc/pathling

All 25 skills in this repo
  • Databricks CLI

    aehrc/pathling

    Expert guidance for using the Databricks CLI to manage Databricks workspaces, clusters, jobs, pipelines, Unity Catalog, SQL warehouses, serving endpoints, secrets, bundles, and all other Databricks…

    137 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • Fhir API

    aehrc/pathling

    Expert guidance for implementing FHIR RESTful API servers and clients following the HL7 FHIR specification.

    137 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Fhir Bulk Data

    aehrc/pathling

    Expert guidance for implementing FHIR Bulk Data Access (Flat FHIR) following the HL7 specification.

    137 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • Fhir Search Spec

    aehrc/pathling

    FHIR RESTful search specification expert with access to the official HL7 search specification text and the formal SearchParameter registry.

    137 GitHub stars~649 tokensUpdated 2 days ago
    Auto-check passed
  • Design and generate comprehensive FHIRPath test suites using input domain partitioning and Pathling's DSL test framework.

    137 GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • Playwright Testing

    aehrc/pathling

    Expert guidance for writing end-to-end tests with Playwright Test framework.

    137 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed

Questions about Hapi Fhir Server

What does Hapi Fhir Server do?

Expert guidance for implementing FHIR servers using HAPI FHIR Plain Server framework. Hapi Fhir Server is an agent skill from aehrc/pathling. Expert guidance for implementing FHIR servers using HAPI FHIR Plain Server framework.

When should I use Hapi Fhir Server?

Hapi Fhir Server fits situations like: creating RESTful FHIR server implementations; implementing resource providers; adding FHIR operations (read; implementing server interceptors for logging.

How do I install Hapi Fhir Server in Claude Code?

Run `npx skills add aehrc/pathling --skill hapi-fhir-server -a claude-code`. Or copy the skill folder (.claude/skills/hapi-fhir-server in aehrc/pathling) into .claude/skills/hapi-fhir-server in your project. Claude Code loads it when a task matches its description.

How do I install Hapi Fhir Server in Codex?

Run `npx skills add aehrc/pathling --skill hapi-fhir-server -a codex`. Or copy the skill folder (.claude/skills/hapi-fhir-server in aehrc/pathling) into .agents/skills/hapi-fhir-server in your project. Codex loads it when a task matches its description.

Can I use Hapi Fhir Server in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aehrc/pathling --skill hapi-fhir-server -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hapi-fhir-server, .gemini/skills/hapi-fhir-server, .github/skills/hapi-fhir-server and .opencode/skills/hapi-fhir-server in your project.

What does Hapi Fhir Server need to run?

SKILL.md names no scripts, command-line tools or credentials: Hapi Fhir Server is instructions for the agent only.

Does Hapi Fhir Server access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hapi Fhir Server safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hapi Fhir Server use?

Hapi Fhir Server is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hapi Fhir Server use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 19k tokens, read only when the agent opens those files.

What are the alternatives to Hapi Fhir Server?

Skills that share tags, products or a category with Hapi Fhir Server: Fhir Developer Skill (FreedomIntelligence/OpenClaw-Medical-Skills, 3.1k stars), Clinical Trials Database (google-deepmind/science-skills, 3.2k stars), CHARLS Paper Reproduction Guide (xjtulyc/MedgeClaw, 617 stars) and Biomedical Analysis Dispatch (xjtulyc/MedgeClaw, 617 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hapi Fhir Server?

aehrc (a GitHub organization) maintains it in aehrc/pathling, which has 137 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 8, 2026.

Source: aehrc/pathling on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.