Authorization value changes.
How it works
- Your IdP authenticates the doctor and signs a SAML assertion.
- Your backend calls
POST /v1/sso/exchangewith your institution secret key and the assertion. - Telepatia verifies the signature, issuer, audience and validity against the SAML configuration of your institution, and returns a doctor access token plus a refresh token.
- Your backend calls the API with the doctor token, and renews it through
POST /v1/sso/refresh— no new IdP round-trip until the refresh chain ends.
Prerequisites
- An institution secret key (
sk_…) created with the SAML SSO exchange permission (thesaml:exchangecheckbox in the platform’s API Keys page). - The SAML configuration saved in the platform’s Developers → SSO tab: your IdP’s entity ID (issuer) and its signing certificate.
- The doctor must already exist in your institution. SSO authenticates doctors; it does not create them.
Service Provider details
Register these fixed Telepatia values in your identity provider. They are the same for every institution.Exchanging an assertion
Send the base64-encoded SAML response with your institution key:200:
403.
Assertion requirements
- The assertion is signed (RSA-SHA256, enveloped signature) with the certificate configured for your institution.
- The
Issuerequals the IdP entity ID configured for your institution. - The
Audienceequals the SP entity ID above. - The
Destinationequals the ACS URL above. - The validity window (
NotBefore/NotOnOrAfter) covers the moment of the exchange. - The assertion carries an
AttributeStatement— standard IdPs always include one. - The doctor’s email arrives as the subject
NameID(formatemailAddress), or in the attribute named by the optional email attribute setting.
Refreshing the session
The refresh token is the credential — no institution key and no assertion:401.