v1
latestOpenAPI 3.1.0Private2026-07-24196240439.2 KBAccountAccessToken
Create Patient Portal access token
Usage Instructions and Security Best Practices
- Authenticate Patients: Only generate access tokens for patients that your system has already authenticated.
- On-Demand Links: Generate the access token only when a patient requests to view their data.
- New Windows/Tabs: Automatically redirect patients to the URL provided, instead of showing them the link directly.
- Avoid Caching: Do not cache or store access tokens in your application.
- Do Not Display Directly: Avoid displaying the access tokens directly in your application.
- Avoid Email Transmission: Never send access tokens via email due to token expiry and security concerns.
Example Workflow
- Request Access: Patient logs into your system and requests to view their Hint Health data.
- Generate Token: Your system makes a POST request to the Access Tokens endpoint.
- Provide Link: Your application receives the URL and automatically redirects the patient to the URL in a new window or tab.
post/provider/patients/{patient_id}/account_access_tokens
Path parameters
patient_idstring required
Unique Patient ID
Response
Successful response