Agent skill

Smart App Launch

by aehrc in aehrc/pathling

Expert guidance for implementing SMART App Launch (HL7 FHIR specification for OAuth 2.0-based authorization).

Apache-2.0Auto-check passedBackend & APIs

Install Smart App Launch

skills CLI
$ npx skills add aehrc/pathling --skill smart-app-launch -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aehrc/pathling smart-app-launch --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aehrc/pathling.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/smart-app-launch .claude/skills/smart-app-launch && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
smart-app-launch
GitHub stars
137
Token cost
~1.3k tokens
SKILL.md length
374 words
Files
7 (incl. references)
Skills in repo
25
Repo updated
First seen
Licence
Apache-2.0

At a glance

Expert guidance for implementing SMART App Launch (HL7 FHIR specification for OAuth 2.0-based authorization).

  • Works in 5 steps: Discover server capabilities → Choose client authentication → Request authorization → …
  • Implementing FHIR app authorization
  • SKILL.md covers Choosing a launch pattern, Core workflow, Scopes quick reference and Backend services, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Smart App Launch is an agent skill from aehrc/pathling. Expert guidance for implementing SMART App Launch (HL7 FHIR specification for OAuth 2.0-based authorization). Use this skill when implementing FHIR app authorization, EHR launch sequences, standalone app launch, backend services authentication, SMART scopes, token handling, or capability discovery. Trigger keywords include "SMART", "SMART on FHIR", "EHR launch", "standalone launch", "FHIR authorization", "FHIR OAuth", "backend services", "system scopes", "patient scopes", "fhirUser"…

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/app-launch.md`, `references/backend-services.md` and `references/capability-discovery.md`).

It sits in Backend & APIs, covering Clinical and healthcare research, OAuth and OpenID Connect and Authorization and RBAC. The repository describes itself as: Tools that make it easier to use FHIR and clinical terminology within data analytics, built on Apache Spark. The licence is Apache-2.0.

When your agent uses it

  • Implementing FHIR app authorization
  • EHR launch sequences
  • Standalone app launch
  • Backend services authentication

Example prompts

  • “SMART on FHIR”
  • “EHR launch”
  • “standalone launch”
  • “/smart-app-launch”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Discover server capabilities
  2. Choose client authentication
  3. Request authorization
  4. Exchange code for tokens
  5. Access FHIR resources

What it can do on your machine

Read from SKILL.md and the folder at commit 56a3b4a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are http).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Smart App Launch loads about 1.3k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 147 tokens; SKILL.md has 374 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~147
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aehrc/pathling at commit 56a3b4a, republished under its Apache-2.0 licence (© aehrc). 374 words, ~1,328 tokens.

Download SKILL.mdSave it as .claude/skills/smart-app-launch/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
smart-app-launch
description
Expert guidance for implementing SMART App Launch (HL7 FHIR specification for OAuth 2.0-based authorization). Use this skill when implementing FHIR app authorization, EHR launch sequences, standalone app launch, backend services authentication, SMART scopes, token handling, or capability discovery. Trigger keywords include "SMART", "SMART on FHIR", "EHR launch", "standalone launch", "FHIR authorization", "FHIR OAuth", "backend services", "system scopes", "patient scopes", "fhirUser", ".well-known/smart-configuration", "PKCE", "client_credentials", "launch context".

SMART App Launch

SMART App Launch provides a standardised OAuth 2.0-based authorization framework for FHIR applications. It enables apps to securely access healthcare data with appropriate user consent and context.

Choosing a launch pattern

Select the appropriate pattern based on your use case:

PatternUse whenGrant type
EHR LaunchApp launched from within EHR UIauthorization_code
Standalone LaunchApp launched independently by userauthorization_code
Backend ServicesServer-to-server, no user presentclient_credentials

Core workflow

Step 1: Discover server capabilities

Fetch {fhir-base}/.well-known/smart-configuration to discover:

  • authorization_endpoint and token_endpoint
  • capabilities array (launch modes, client types, permission models)
  • code_challenge_methods_supported (must include S256)

See references/capability-discovery.md for full field reference.

Step 2: Choose client authentication
Client typeMethodRegistration
PublicPKCE only, no secretclient_id only
Confidential (symmetric)Client secretSecret shared at registration
Confidential (asymmetric)Private key JWTJWKS URL or keys registered

Backend services require asymmetric authentication. See references/client-authentication.md.

Step 3: Request authorization

EHR Launch: App receives iss and launch parameters, echoes launch in authorization request.

Standalone Launch: App initiates flow, may request launch/patient or launch/encounter to establish context.

Required authorization parameters:

  • response_type=code
  • client_id, redirect_uri, scope, state (122+ bits entropy)
  • aud (FHIR server base URL)
  • code_challenge + code_challenge_method=S256

See references/app-launch.md for complete flow details.

Step 4: Exchange code for tokens

POST to token endpoint with:

  • grant_type=authorization_code
  • code, redirect_uri, code_verifier
  • Client authentication (if confidential)

Token response includes:

  • access_token, token_type, scope, expires_in
  • Optional: refresh_token, id_token, launch context (patient, encounter)
Show full SKILL.md (142 more words)Show less
Step 5: Access FHIR resources
http
GET {fhir-base}/Patient/123
Authorization: Bearer {access_token}

Scopes quick reference

patient/Observation.rs     # Read + search patient observations
user/Appointment.cruds     # Full access to user's appointments
system/Patient.rs          # Backend service read/search all patients
launch/patient             # Request patient context at launch
openid fhirUser            # Get user identity via OIDC
offline_access             # Request refresh token

Scope syntax: {context}/{resource}.{permissions}[?{constraints}]

See references/scopes.md for complete scope grammar and examples.

Backend services

For server-to-server access without user interaction:

  1. Register client with JWKS URL
  2. Create signed JWT assertion with required claims (iss, sub, aud, exp, jti)
  3. POST to token endpoint with grant_type=client_credentials and client_assertion
  4. Use system/ scopes only

See references/backend-services.md for JWT structure and examples.

Security requirements

  • PKCE with S256 is mandatory for all authorization code flows
  • TLS 1.2+ required for all token transmission
  • Access tokens should expire within 1 hour (5 minutes for backend services)
  • Validate state parameter to prevent CSRF
  • Validate aud matches your FHIR endpoint

See references/security.md for comprehensive security guidance.

References

© aehrc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in .claude/skills/smart-app-launch of aehrc/pathling.

  • SKILL.md
  • references/app-launch.md
  • references/backend-services.md
  • references/capability-discovery.md
  • references/client-authentication.md
  • references/scopes.md
  • references/security.md

Open the folder on GitHubat commit 56a3b4a

Compare with similar skills

Smart App Launch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Smart App Launch compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Smart App Launch this skillaehrc/pathling137—~1.3kAutomated safety check: PassApache-2.0
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS61710 repos~4.4kAutomated safety check: PassNone
Soundcloud API Authsoundcloud/api258—~562Automated safety check: PassNone
Frontmcp Auth UIagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0

Similar skills

  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Soundcloud API Auth

    soundcloud/api

    Implements SoundCloud OAuth 2.1 flows — Authorization Code with PKCE and Client Credentials — including token refresh and secure credential storage.

    258 GitHub stars~562 tokensUpdated 7 days ago
    Backend & APIsAuto-check passed
  • Frontmcp Auth UI

    agentfront/frontmcp

    A skill your agent uses when customizing, branding, or replacing the built-in FrontMCP OAuth pages (the login, consent, federated-select, incremental-authorization, and error pages) with your own…

    146 GitHub stars~3.7k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Authentication

    codewithmukesh/dotnet-claude-kit

    Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed

More from aehrc/pathling

All 25 skills in this repo
  • Fhir API

    aehrc/pathling

    Expert guidance for implementing FHIR RESTful API servers and clients following the HL7 FHIR specification.

    137 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Fhir Bulk Data

    aehrc/pathling

    Expert guidance for implementing FHIR Bulk Data Access (Flat FHIR) following the HL7 specification.

    137 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Databricks CLI

    aehrc/pathling

    Expert guidance for using the Databricks CLI to manage Databricks workspaces, clusters, jobs, pipelines, Unity Catalog, SQL warehouses, serving endpoints, secrets, bundles, and all other Databricks…

    137 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Fhir Search Spec

    aehrc/pathling

    FHIR RESTful search specification expert with access to the official HL7 search specification text and the formal SearchParameter registry.

    137 GitHub stars~649 tokensUpdated today
    Auto-check passed
  • Design and generate comprehensive FHIRPath test suites using input domain partitioning and Pathling's DSL test framework.

    137 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Hapi Fhir Server

    aehrc/pathling

    Expert guidance for implementing FHIR servers using HAPI FHIR Plain Server framework.

    137 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Questions about Smart App Launch

What does Smart App Launch do?

Expert guidance for implementing SMART App Launch (HL7 FHIR specification for OAuth 2.0-based authorization). Smart App Launch is an agent skill from aehrc/pathling.0-based authorization).

When should I use Smart App Launch?

Smart App Launch fits situations like: implementing FHIR app authorization; EHR launch sequences; standalone app launch; backend services authentication.

How do I install Smart App Launch in Claude Code?

Run `npx skills add aehrc/pathling --skill smart-app-launch -a claude-code`. Or copy the skill folder (.claude/skills/smart-app-launch in aehrc/pathling) into .claude/skills/smart-app-launch in your project. Claude Code loads it when a task matches its description.

How do I install Smart App Launch in Codex?

Run `npx skills add aehrc/pathling --skill smart-app-launch -a codex`. Or copy the skill folder (.claude/skills/smart-app-launch in aehrc/pathling) into .agents/skills/smart-app-launch in your project. Codex loads it when a task matches its description.

Can I use Smart App Launch in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aehrc/pathling --skill smart-app-launch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/smart-app-launch, .gemini/skills/smart-app-launch, .github/skills/smart-app-launch and .opencode/skills/smart-app-launch in your project.

What does Smart App Launch need to run?

SKILL.md names no scripts, command-line tools or credentials: Smart App Launch is instructions for the agent only.

Does Smart App Launch access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Smart App Launch safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Smart App Launch use?

Smart App Launch is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Smart App Launch use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Smart App Launch?

Skills that share tags, products or a category with Smart App Launch: Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Auth Implementation Patterns (ynulihao/AgentSkillOS, 617 stars), Soundcloud API Auth (soundcloud/api, 258 stars) and Frontmcp Auth UI (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Smart App Launch?

aehrc (a GitHub organization) maintains it in aehrc/pathling, which has 137 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 8, 2026.

Source: aehrc/pathling on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.