Smart App Launch
aehrc/pathling
Expert guidance for implementing SMART App Launch (HL7 FHIR specification for OAuth 2.0-based authorization).
Scaffold a SMART-on-FHIR app (SMART App Launch v2 — EHR launch and standalone launch, OAuth2 PKCE, scopes, token handling, fhirContext) so an OpenMed-powered tool can run inside Epic or…
$ npx skills add maziyarpanahi/openmed --skill scaffolding-smart-on-fhir -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install maziyarpanahi/openmed scaffolding-smart-on-fhir --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/scaffolding-smart-on-fhir .claude/skills/scaffolding-smart-on-fhir && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "scaffolding-smart-on-fhir" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/scaffolding-smart-on-fhir into .claude/skills/scaffolding-smart-on-fhir/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scaffolding-smart-on-fhir", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/maziyarpanahi/openmed/tree/master/skills/scaffolding-smart-on-fhirType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add maziyarpanahi/openmed --skill scaffolding-smart-on-fhir -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install maziyarpanahi/openmed scaffolding-smart-on-fhir --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/scaffolding-smart-on-fhir .agents/skills/scaffolding-smart-on-fhir && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "scaffolding-smart-on-fhir" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/scaffolding-smart-on-fhir into .agents/skills/scaffolding-smart-on-fhir/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scaffolding-smart-on-fhir", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maziyarpanahi/openmed --skill scaffolding-smart-on-fhir -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install maziyarpanahi/openmed scaffolding-smart-on-fhir --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/scaffolding-smart-on-fhir .cursor/skills/scaffolding-smart-on-fhir && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "scaffolding-smart-on-fhir" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/scaffolding-smart-on-fhir into .cursor/skills/scaffolding-smart-on-fhir/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scaffolding-smart-on-fhir", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/maziyarpanahi/openmed.git --path skills/scaffolding-smart-on-fhir--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add maziyarpanahi/openmed --skill scaffolding-smart-on-fhir -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install maziyarpanahi/openmed scaffolding-smart-on-fhir --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/scaffolding-smart-on-fhir .gemini/skills/scaffolding-smart-on-fhir && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "scaffolding-smart-on-fhir" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/scaffolding-smart-on-fhir into .gemini/skills/scaffolding-smart-on-fhir/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scaffolding-smart-on-fhir", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install maziyarpanahi/openmed scaffolding-smart-on-fhirInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add maziyarpanahi/openmed --skill scaffolding-smart-on-fhir -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/scaffolding-smart-on-fhir .github/skills/scaffolding-smart-on-fhir && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "scaffolding-smart-on-fhir" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/scaffolding-smart-on-fhir into .github/skills/scaffolding-smart-on-fhir/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scaffolding-smart-on-fhir", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maziyarpanahi/openmed --skill scaffolding-smart-on-fhir -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install maziyarpanahi/openmed scaffolding-smart-on-fhir --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/scaffolding-smart-on-fhir .opencode/skills/scaffolding-smart-on-fhir && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "scaffolding-smart-on-fhir" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/scaffolding-smart-on-fhir into .opencode/skills/scaffolding-smart-on-fhir/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scaffolding-smart-on-fhir", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
scaffolding-smart-on-fhirScaffold a SMART-on-FHIR app (SMART App Launch v2 — EHR launch and standalone launch, OAuth2 PKCE, scopes, token handling, fhirContext) so an OpenMed-powered tool can run inside Epic or…
Scaffolding Smart On Fhir is an agent skill from maziyarpanahi/openmed. Scaffold a SMART-on-FHIR app (SMART App Launch v2 — EHR launch and standalone launch, OAuth2 PKCE, scopes, token handling, fhirContext) so an OpenMed-powered tool can run inside Epic or Cerner/Oracle Health. Covers the .well-known/smart-configuration discovery, authorize/token sequence, scopes like patient/DocumentReference.rs and launch/patient, and fetching clinical notes the app then de-identifies and runs NER on locally with OpenMed. Use when the user wants to embed OpenMed inside an EHR, mentions SMART on…
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Research & Science, covering Clinical and healthcare research, OAuth and OpenID Connect and Project scaffolding. The repository describes itself as: Local-first healthcare AI: clinical NER and HIPAA PII de-identification on hardware you control. 2,200+ medical models, 35 model-backed PII languages, and Python, MLX, Android… The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 34d7b8c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
hl7.orgdatatracker.ietf.orgfhir.epic.comfhir.cerner.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Scaffolding Smart On Fhir loads about 1.9k tokens when it runs. Until then it costs about 158 tokens; SKILL.md has 617 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from maziyarpanahi/openmed at commit 34d7b8c, republished under its Apache-2.0 licence (© maziyarpanahi). 617 words, ~1,893 tokens.
.claude/skills/scaffolding-smart-on-fhir/SKILL.md (or your agent's skills folder).To put an OpenMed-powered tool inside a clinician's EHR (Epic, Cerner/Oracle Health), you build a SMART on FHIR app: a web app the EHR launches with an OAuth2 flow, granting scoped, time-limited access to the patient's FHIR data. The app fetches the clinical notes, then runs OpenMed on-device (de-id + NER) — so PHI is processed locally and only de-identified output, if anything, leaves the browser/host.
Reach for this when the deliverable is a clinician-facing app embedded in an
EHR, or a standalone app authorizing against an EHR's FHIR endpoint. Triggers:
"SMART on FHIR", "EHR launch", "OAuth2 scopes", "Epic/Cerner app",
"embed OpenMed in the chart". For pulling notes at cohort scale (no UI), use
exporting-bulk-fhir instead.
launch_uri?iss=<fhir-base>&launch=<opaque>; you complete OAuth2 and inherit
the current patient/encounter context.Both use SMART App Launch v2: OAuth2 authorization code flow with PKCE
(required in v2), discovered via .well-known/smart-configuration.
1. EHR launch URL:
GET https://app.example/launch?iss=https://ehr.example/fhir&launch=abc123
2. Discover endpoints:
GET https://ehr.example/fhir/.well-known/smart-configuration
-> { "authorization_endpoint": ".../authorize",
"token_endpoint": ".../token",
"code_challenge_methods_supported": ["S256"],
"capabilities": ["launch-ehr","client-public","context-ehr-patient", ...] }
3. Redirect the browser to authorize (PKCE + the launch token):
GET .../authorize?
response_type=code&
client_id=YOUR_CLIENT_ID&
redirect_uri=https://app.example/callback&
scope=launch openid fhirUser patient/DocumentReference.rs patient/Patient.r&
state=RANDOM&
aud=https://ehr.example/fhir&
launch=abc123&
code_challenge=BASE64URL(SHA256(verifier))&
code_challenge_method=S256
4. Callback -> exchange code for token:
POST .../token
grant_type=authorization_code&code=...&redirect_uri=...&
client_id=...&code_verifier=ORIGINAL_VERIFIER
-> { "access_token": "...", "token_type": "Bearer", "expires_in": 3600,
"scope": "patient/DocumentReference.rs ...",
"patient": "Patient-123", "encounter": "Encounter-9",
"id_token": "..." }
5. Call FHIR with the token:
GET https://ehr.example/fhir/DocumentReference?patient=Patient-123&type=clinical-note
Authorization: Bearer <access_token>The token response carries the launch context (patient, sometimes
encounter, and in v2 a fhirContext array). Use patient to scope every
subsequent query.
SMART v2 scopes are <level>/<Resource>.<permissions> where permissions are a
subset of c r u d s (create/read/update/delete/search) — .rs = read +
search. Request the minimum:
| Scope | Why |
|---|---|
launch | EHR launch context (omit for standalone; use launch/patient) |
openid fhirUser | Identify the launching user |
patient/Patient.r | The in-context patient demographics |
patient/DocumentReference.rs | Read + search the patient's clinical notes |
patient/Condition.rs | (optional) reconcile against existing problems |
offline_access | (optional) refresh token for background work |
Prefer patient/… (current-patient) over user/… (everything the user can see)
to keep the blast radius small. Granular v2 scopes (.rs) are stricter than the
v1 .read/.write forms — use them.
Notes arrive as DocumentReference → content.attachment (often base64 or a
url to a Binary). Decode, then process locally:
import base64, openmed
note_b64 = document_reference["content"][0]["attachment"]["data"]
note = base64.b64decode(note_b64).decode("utf-8")
# De-identify on-device before anything else touches it
deid = openmed.deidentify(note, method="replace", policy="hipaa_safe_harbor")
# Clinical NER on the (de-identified or raw, per your IRB) text
entities = openmed.analyze_text(deid.text, model_name="disease_detection_superclinical")
# -> render highlights in the SMART app UI, or export FHIR (exporting-to-fhir)OpenMed models run on-device after a one-time download — no note text is sent to a third party by OpenMed. Keep the access token and any PHI in memory only; do not log them.
DocumentReference notes →
openmed.deidentify → openmed.analyze_text.exporting-to-fhir) → to_bundle (assembling-fhir-bundles) → write back
with a write scope (e.g. patient/Condition.c) if your use case persists
findings. Validate first (validating-us-core).openmed_analyze_text and openmed_deidentify — same on-device guarantees.code_verifier per launch; never reuse.state and aud. Reject the callback if state does not match;
set aud to the FHIR base or the EHR will reject the authorize request.expires_in; use offline_access +
refresh tokens only if you genuinely need background access, and store them
securely (never client-side for confidential clients).scope and degrade gracefully..well-known/smart-configuration: https://hl7.org/fhir/smart-app-launch/conformance.html© maziyarpanahi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/scaffolding-smart-on-fhir of maziyarpanahi/openmed.
Open the folder on GitHubat commit 34d7b8c
Scaffolding Smart On Fhir next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Scaffolding Smart On Fhir this skillmaziyarpanahi/openmed | 5.5k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Smart App Launchaehrc/pathling | 137 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Clinical Trials Databasegoogle-deepmind/science-skills | 3.2k | 2 repos | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| CHARLS Paper Reproduction Guidexjtulyc/MedgeClaw | 617 | 1 repos | ~1.8k | Automated safety check: Pass | None | |
| Biomedical Analysis Dispatchxjtulyc/MedgeClaw | 617 | 1 repos | ~2k | Automated safety check: Pass | None | |
| Research Paperluwill/research-skills | 862 | — | ~1.9k | Automated safety check: Pass | None |
aehrc/pathling
Expert guidance for implementing SMART App Launch (HL7 FHIR specification for OAuth 2.0-based authorization).
google-deepmind/science-skills
Query ClinicalTrials.gov via APIv2. An agent skill from google-deepmind/science-skills.
xjtulyc/MedgeClaw
Guides an agent through reproducing papers built on the CHARLS health and retirement survey, from variable mapping to cognition, depression and isolation scores.
xjtulyc/MedgeClaw
Routes bioinformatics, drug discovery, clinical and multi-omics tasks from a chat interface to Claude Code sessions running K-Dense scientific skills, with a live dashboard per task.
luwill/research-skills
A skill your agent uses when the user asks to write or draft an ORIGINAL RESEARCH ARTICLE — IMRaD paper, conference paper, short/workshop paper, 研究论文/期刊论文/会议论文 — reporting their own completed…
luwill/research-skills
A skill your agent uses when the user asks to write or draft a PhD / doctoral research proposal, research plan, 研究计划书, or 开题报告 — a forward-looking plan of background, gap, research questions…
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
maziyarpanahi/openmed
Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
maziyarpanahi/openmed
Suggests candidate ICD-10-CM diagnosis and ICD-10-PCS procedure codes for clinical text extracted by OpenMed, with rationale for a certified coder to review.
maziyarpanahi/openmed
Maps OpenMed-extracted, terminology-coded conditions, drugs and measurements into OMOP CDM v5.4 tables for OHDSI and ATLAS analytics.
maziyarpanahi/openmed
Finds social risks such as housing instability or food insecurity in clinical notes and proposes matching ICD-10-CM Z-codes for a coder to confirm.
Categories
Scaffold a SMART-on-FHIR app (SMART App Launch v2 — EHR launch and standalone launch, OAuth2 PKCE, scopes, token handling, fhirContext) so an OpenMed-powered tool can run inside Epic or…. Scaffolding Smart On Fhir is an agent skill from maziyarpanahi/openmed. Scaffold a SMART-on-FHIR app (SMART App Launch v2 — EHR launch and standalone launch, OAuth2 PKCE, scopes, token handling, fhirContext) so an OpenMed-powered tool can run inside Epic or Cerner/Oracle Health.
Scaffolding Smart On Fhir fits situations like: the user wants to embed OpenMed inside an EHR; mentions SMART on FHIR; epic/Cerner app; clinician-facing FHIR app.
Run `npx skills add maziyarpanahi/openmed --skill scaffolding-smart-on-fhir -a claude-code`. Or copy the skill folder (skills/scaffolding-smart-on-fhir in maziyarpanahi/openmed) into .claude/skills/scaffolding-smart-on-fhir in your project. Claude Code loads it when a task matches its description.
Run `npx skills add maziyarpanahi/openmed --skill scaffolding-smart-on-fhir -a codex`. Or copy the skill folder (skills/scaffolding-smart-on-fhir in maziyarpanahi/openmed) into .agents/skills/scaffolding-smart-on-fhir in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maziyarpanahi/openmed --skill scaffolding-smart-on-fhir -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scaffolding-smart-on-fhir, .gemini/skills/scaffolding-smart-on-fhir, .github/skills/scaffolding-smart-on-fhir and .opencode/skills/scaffolding-smart-on-fhir in your project.
SKILL.md names no scripts, command-line tools or credentials: Scaffolding Smart On Fhir is instructions for the agent only. Our summary lists: Python 3.
SKILL.md names 4 domains. As links in the text: hl7.org, datatracker.ietf.org, fhir.epic.com and fhir.cerner.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Scaffolding Smart On Fhir is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Scaffolding Smart On Fhir: Smart App Launch (aehrc/pathling, 137 stars), Clinical Trials Database (google-deepmind/science-skills, 3.2k stars), CHARLS Paper Reproduction Guide (xjtulyc/MedgeClaw, 617 stars) and Biomedical Analysis Dispatch (xjtulyc/MedgeClaw, 617 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
maziyarpanahi (a GitHub user) maintains it in maziyarpanahi/openmed, which has 5,506 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on October 11, 2026.
Source: maziyarpanahi/openmed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.