Generate a short-lived Access Token (JWT) to authenticate Hero Health Elements (SDKs).
Important: This endpoint must only be called from your server — never from client-side code. The returned token expires after 30 minutes.
Use the returned access_token as the jwt-token attribute when rendering a Hero Element (React component or Web Component).
Admin attribution on the newly created token is resolved from:
x-admin-idon token generation (header)- the default-admin behaviour: falls back to the practice group's configured default admin when the header is not supplied.
Security
apiKeyAuth and practiceGroupId
- Mock serverhttps://developer.herohealth.net/_mock/apis/public-api/openapi/v1/access_token
- Staginghttps://api.staging.htech.app/v1/access_token
- Productionhttps://api.herohealth.net/v1/access_token
curl -i -X POST \
https://developer.herohealth.net/_mock/apis/public-api/openapi/v1/access_token \
-H 'x-api-key: YOUR_API_KEY_HERE' \
-H 'x-practice-group-id: YOUR_API_KEY_HERE'