{
  "resourceType" : "CodeSystem",
  "id" : "NdhEndpointAccessControlMechanismCS",
  "text" : {
    "status" : "generated",
    "div" : "<div xmlns=\"http://www.w3.org/1999/xhtml\"><p class=\"res-header-id\"><b>Generated Narrative: CodeSystem NdhEndpointAccessControlMechanismCS</b></p><a name=\"NdhEndpointAccessControlMechanismCS\"> </a><a name=\"hcNdhEndpointAccessControlMechanismCS\"> </a><p>This case-sensitive code system <code>http://hl7.org/fhir/us/ndh/CodeSystem/NdhEndpointAccessControlMechanismCS</code> defines the following codes:</p><table class=\"codes\"><tr><td style=\"white-space:nowrap\"><b>Code</b></td><td><b>Display</b></td><td><b>Definition</b></td></tr><tr><td style=\"white-space:nowrap\">public<a name=\"NdhEndpointAccessControlMechanismCS-public\"> </a></td><td>Public</td><td>Public access without any specific access control.</td></tr><tr><td style=\"white-space:nowrap\">OAuth<a name=\"NdhEndpointAccessControlMechanismCS-OAuth\"> </a></td><td>OAuth</td><td>OAuth (unspecified version see oauth.net).</td></tr><tr><td style=\"white-space:nowrap\">SMART-on-FHIR<a name=\"NdhEndpointAccessControlMechanismCS-SMART-on-FHIR\"> </a></td><td>SMART-on-FHIR</td><td>OAuth2 using SMART-on-FHIR profile (see http://docs.smarthealthit.org/).</td></tr><tr><td style=\"white-space:nowrap\">NTLM<a name=\"NdhEndpointAccessControlMechanismCS-NTLM\"> </a></td><td>NTLM</td><td>Microsoft NTLM Authentication.</td></tr><tr><td style=\"white-space:nowrap\">basic<a name=\"NdhEndpointAccessControlMechanismCS-basic\"> </a></td><td>Basic</td><td>Basic authentication defined in HTTP specification.</td></tr><tr><td style=\"white-space:nowrap\">Kerberos<a name=\"NdhEndpointAccessControlMechanismCS-Kerberos\"> </a></td><td>Kerberos</td><td>see http://www.ietf.org/rfc/rfc4120.txt.</td></tr><tr><td style=\"white-space:nowrap\">Certificates<a name=\"NdhEndpointAccessControlMechanismCS-Certificates\"> </a></td><td>Certificates</td><td>SSL where client must have a certificate registered with the server.</td></tr><tr><td style=\"white-space:nowrap\">opaque-access-token<a name=\"NdhEndpointAccessControlMechanismCS-opaque-access-token\"> </a></td><td>Opaque Access Token</td><td>Uses an opaque token for access control, which is a token whose structure is not visible or meaningful to the client.</td></tr><tr><td style=\"white-space:nowrap\">jwt-access-token<a name=\"NdhEndpointAccessControlMechanismCS-jwt-access-token\"> </a></td><td>JWT Access Token</td><td>Uses a JSON Web Token (JWT) for access control, which is a compact, URL-safe means of representing claims to be transferred between two parties.</td></tr><tr><td style=\"white-space:nowrap\">mutual-tls<a name=\"NdhEndpointAccessControlMechanismCS-mutual-tls\"> </a></td><td>Mutual TLS</td><td>Uses mutual Transport Layer Security (TLS) where both client and server authenticate each other using certificates.</td></tr><tr><td style=\"white-space:nowrap\">wss-saml-token<a name=\"NdhEndpointAccessControlMechanismCS-wss-saml-token\"> </a></td><td>WSS SAML Token</td><td>Uses a Security Assertion Markup Language (SAML) token within the Web Services Security (WSS) framework for access control.</td></tr><tr><td style=\"white-space:nowrap\">wss-username-token<a name=\"NdhEndpointAccessControlMechanismCS-wss-username-token\"> </a></td><td>WSS User Name Token</td><td>Uses a username token within the WSS framework for access control.</td></tr><tr><td style=\"white-space:nowrap\">wss-kerberos-token<a name=\"NdhEndpointAccessControlMechanismCS-wss-kerberos-token\"> </a></td><td>WSS Kerberos Token</td><td>Uses a Kerberos token within the WSS framework for access control.</td></tr><tr><td style=\"white-space:nowrap\">wss-x509-token<a name=\"NdhEndpointAccessControlMechanismCS-wss-x509-token\"> </a></td><td>WSS X509 Token</td><td>Uses an X.509 certificate token within the WSS framework for access control.</td></tr><tr><td style=\"white-space:nowrap\">wss-custom-token<a name=\"NdhEndpointAccessControlMechanismCS-wss-custom-token\"> </a></td><td>WSS Custom Token</td><td>Uses a custom token within the WSS framework for access control.</td></tr></table></div>"
  },
  "extension" : [{
    "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-wg",
    "valueCode" : "pa"
  },
  {
    "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-fmm",
    "valueInteger" : 4,
    "_valueInteger" : {
      "extension" : [{
        "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom",
        "valueCanonical" : "http://hl7.org/fhir/us/ndh/ImplementationGuide/hl7.fhir.us.ndh"
      }]
    }
  },
  {
    "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-standards-status",
    "valueCode" : "trial-use",
    "_valueCode" : {
      "extension" : [{
        "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom",
        "valueCanonical" : "http://hl7.org/fhir/us/ndh/ImplementationGuide/hl7.fhir.us.ndh"
      }]
    }
  }],
  "url" : "http://hl7.org/fhir/us/ndh/CodeSystem/NdhEndpointAccessControlMechanismCS",
  "version" : "2.0.0-current",
  "name" : "NdhEndpointAccessControlMechanismCS",
  "title" : "Endpoint Access Control Mechanism Code System",
  "status" : "active",
  "experimental" : false,
  "date" : "2026-03-30T14:03:58+00:00",
  "publisher" : "HL7 International / Patient Administration",
  "contact" : [{
    "name" : "HL7 International / Patient Administration",
    "telecom" : [{
      "system" : "url",
      "value" : "http://www.hl7.org/Special/committees/pafm"
    },
    {
      "system" : "email",
      "value" : "pafm@lists.hl7.org"
    }]
  }],
  "description" : "Endpoint Access Control Mechanism",
  "jurisdiction" : [{
    "coding" : [{
      "system" : "urn:iso:std:iso:3166",
      "code" : "US",
      "display" : "United States of America"
    }]
  }],
  "caseSensitive" : true,
  "content" : "complete",
  "count" : 15,
  "concept" : [{
    "code" : "public",
    "display" : "Public",
    "definition" : "Public access without any specific access control."
  },
  {
    "code" : "OAuth",
    "display" : "OAuth",
    "definition" : "OAuth (unspecified version see oauth.net)."
  },
  {
    "code" : "SMART-on-FHIR",
    "display" : "SMART-on-FHIR",
    "definition" : "OAuth2 using SMART-on-FHIR profile (see http://docs.smarthealthit.org/)."
  },
  {
    "code" : "NTLM",
    "display" : "NTLM",
    "definition" : "Microsoft NTLM Authentication."
  },
  {
    "code" : "basic",
    "display" : "Basic",
    "definition" : "Basic authentication defined in HTTP specification."
  },
  {
    "code" : "Kerberos",
    "display" : "Kerberos",
    "definition" : "see http://www.ietf.org/rfc/rfc4120.txt."
  },
  {
    "code" : "Certificates",
    "display" : "Certificates",
    "definition" : "SSL where client must have a certificate registered with the server."
  },
  {
    "code" : "opaque-access-token",
    "display" : "Opaque Access Token",
    "definition" : "Uses an opaque token for access control, which is a token whose structure is not visible or meaningful to the client."
  },
  {
    "code" : "jwt-access-token",
    "display" : "JWT Access Token",
    "definition" : "Uses a JSON Web Token (JWT) for access control, which is a compact, URL-safe means of representing claims to be transferred between two parties."
  },
  {
    "code" : "mutual-tls",
    "display" : "Mutual TLS",
    "definition" : "Uses mutual Transport Layer Security (TLS) where both client and server authenticate each other using certificates."
  },
  {
    "code" : "wss-saml-token",
    "display" : "WSS SAML Token",
    "definition" : "Uses a Security Assertion Markup Language (SAML) token within the Web Services Security (WSS) framework for access control."
  },
  {
    "code" : "wss-username-token",
    "display" : "WSS User Name Token",
    "definition" : "Uses a username token within the WSS framework for access control."
  },
  {
    "code" : "wss-kerberos-token",
    "display" : "WSS Kerberos Token",
    "definition" : "Uses a Kerberos token within the WSS framework for access control."
  },
  {
    "code" : "wss-x509-token",
    "display" : "WSS X509 Token",
    "definition" : "Uses an X.509 certificate token within the WSS framework for access control."
  },
  {
    "code" : "wss-custom-token",
    "display" : "WSS Custom Token",
    "definition" : "Uses a custom token within the WSS framework for access control."
  }]
}