Unified OAuth2 FHIR Authentication using go

via Freelancer ·

Budget / Salary$10–30
TypeFreelance project
LocationRemote
Posted2 hours ago
I need a clean, repeatable OAuth2 login flow that lets my application connect to both the Athena Healthcare FHIR sandbox and a live customer instance without changing code between environments. The login must operate strictly system-to-system—no individual user roles—yet obtain tokens that carry full read/write scope for any valid FHIR resource exposed by Athena.

You will handle the entire authentication layer: client registration (sandbox and production), token retrieval, automatic refresh, and secure storage of secrets. I should be able to point the code at either endpoint, supply the relevant client credentials, and immediately receive a working access token that passes Athena’s FHIR authorization checks.

Deliverables
• Source code for the OAuth2 client (language/framework of your choice, but well-documented)
• Environment configuration samples for both sandbox and production URLs
• A short setup guide that shows how to register the client in Athena, retrieve scopes for full read/write, and verify connectivity with a simple FHIR read/write test
• Postman (or similar) collection demonstrating the flow, including automated token refresh

Acceptance criteria
• One command or API call authenticates successfully against sandbox and production using only endpoint-specific credentials
• Returned tokens allow create, read, update and delete on any FHIR resource supported by Athena
• All secrets stored using best-practice encryption or environment variables; nothing hard-coded in source control

If you have prior Athena or FHIR integration experience, let me know—otherwise clear, thorough documentation will be essential so I can extend the work in-house.
cloud computing software architecture agile development software development web services oauth documentation restful api security api development
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.