Authentication
HMS4all supports two authentication methods: API keys (recommended for agents) and JWT bearer tokens (for interactive applications).
API Key Authentication (Recommended)
API keys are the recommended way to authenticate MCP clients and A2A agents. Keys are scoped to specific tool categories and rate-limited per key.
Creating an API Key
- Log in to the admin dashboard
- Navigate to Automation → API Keys
- Click “Create API Key”
- Choose a name, select scopes, and set an expiry date
- Copy the key immediately — it cannot be viewed again
Using the API Key
Include the key in the Authorization header:
curl https://your-api.hms4all.com/mcp \ -H "Authorization: Bearer hms4all_sk_abc123def456"
Key Rotation
Rotate keys without downtime: click Rotate on an existing key. This generates a new key and revokes the old one. Update your clients with the new key within the grace period.
Scopes Reference
Each scope controls access to a category of MCP tools. API keys withnull scopes (all scopes) have unrestricted tool access.
| Scope | Description |
|---|---|
agents:planning:read | Hospital planning tools (suggest-departments, design-hospital) |
agents:clinical:read | Clinical read tools (SOAP notes, lab analysis, vitals, CDS) |
agents:clinical:write | Clinical write tools (HITL propose-prescription, propose-admission, etc.) |
agents:reception:read | Reception read tools (search-patients, list-appointments) |
agents:reception:write | Reception write tools (register-patient, book/cancel-appointment) |
agents:billing:read | Billing read tools (get-billing-summary, estimate-cost) |
agents:billing:write | Billing write tools (billing-health-check) |
agents:hr:write | HR tools (generate-roster) |
agents:pharmacy:read | Pharmacy tools (pharmacy-expiry-scan, get-pharmacy-stock) |
agents:operations:read | Operations tools (get-bed-availability, get-queue-status) |
agents:onboarding:read | Onboarding chat tool |
agents:support:read | Support query tool |
agents:monitoring:read | System monitoring tool |
agents:simulation:write | Demo data generation tool |
JWT Authentication
For interactive applications, use JWT bearer tokens obtained via the login endpoint.
Login
curl -X POST https://your-api.hms4all.com/auth/login \
-H "Content-Type: application/json" \
-d '{
"email": "you@your-hospital.com",
"password": "your-password"
}'
# Response:
{
"access_token": "eyJhbGciOiJIUzI1NiIs...",
"user": {
"id": "uuid",
"email": "you@your-hospital.com",
"role": "ADMIN",
"tenantId": "tenant-uuid",
"permissions": ["VIEW_DASHBOARD", "VIEW_OPD", ...]
}
}Using the JWT
curl https://your-api.hms4all.com/appointments \ -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIs..." -H "x-tenant-id: tenant-uuid"
Token Expiry
JWT tokens expire based on the JWT_EXPIRATION server config (default: 24 hours). When a token expires, re-authenticate via the login endpoint.
Rate Limits
| Endpoint | Limit |
|---|---|
| Global (all endpoints) | 30 requests/minute |
MCP Server (/mcp, /sse) | 10 requests/minute |
Login (/auth/login) | 5 requests/minute |
| Public registration | 3 requests/minute |