Skip to content

Practice Group

Manage practice group settings, access tokens, and configuration. Use the access token endpoint to generate short-lived JWTs for Hero Elements.

Create an Access Token

Request

Generate a short-lived Access Token (JWT) to authenticate Hero Health Elements (SDKs).

Important: This endpoint must only be called from your server — never from client-side code. The returned token expires after 30 minutes.

Use the returned access_token as the jwt-token attribute when rendering a Hero Element (React component or Web Component).

Admin attribution on the newly created token is resolved from:

  • x-admin-id on token generation (header)
  • the default-admin behaviour: falls back to the practice group's configured default admin when the header is not supplied.
Security
apiKeyAuth and practiceGroupId
curl -i -X POST \
  https://developer.herohealth.net/_mock/apis/public-api/openapi/v1/access_token \
  -H 'x-api-key: YOUR_API_KEY_HERE' \
  -H 'x-practice-group-id: YOUR_API_KEY_HERE'

Responses

Ok

Bodyapplication/json
access_tokenstringrequired
Response
{ "access_token": "string" }