<jwt> is the same Clerk session token issued when a clinic_admin or super_admin user logs into the Emma dashboard. There is no separate API key, client credential, or OAuth/SMART-on-FHIR flow for this sandbox today, grab the token from the dashboard’s own browser network tab while logged in.
All requests are automatically scoped to the authenticated user’s own clinic. There is no cross-clinic access, and no clinicId parameter to pass, it is resolved from the token.
The Live-Call Tools pages (Patient Journey, Patient Intake, EMR Scheduling, Abandonment Recovery) don’t use this Bearer scheme — they’re called by Vapi mid-call, with no logged-in user, and are authenticated with a shared x-vapi-secret header instead. See each of those pages for details.
Errors
401 Unauthorized, returned when the token is missing, malformed, or expired:clinic_admin or super_admin:
