> ## Documentation Index
> Fetch the complete documentation index at: https://docs.carewithemma.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Bearer JWT authentication for the Emma EMR Sandbox API

Every endpoint on this page and under FHIR Resources / Guides requires a Bearer token:

```text theme={null}
Authorization: Bearer <jwt>
```

The `<jwt>` is the same Clerk session token issued when a `clinic_admin` or `super_admin` user logs into the Emma dashboard. There is no separate API key, client credential, or OAuth/SMART-on-FHIR flow for this sandbox today, grab the token from the dashboard's own browser network tab while logged in.

All requests are automatically scoped to the authenticated user's own clinic. There is no cross-clinic access, and no `clinicId` parameter to pass, it is resolved from the token.

<Note>
  The Live-Call Tools pages (Patient Journey, Patient Intake, EMR Scheduling, Abandonment Recovery) don't use this Bearer scheme — they're called by Vapi mid-call, with no logged-in user, and are authenticated with a shared x-vapi-secret header instead. See each of those pages for details.
</Note>

## Errors

401 Unauthorized, returned when the token is missing, malformed, or expired:

```json theme={null}
{ "statusCode": 401, "message": "Unauthorized" }
```

403 Forbidden, returned when the token is valid but the user's role isn't `clinic_admin` or `super_admin`:

```json theme={null}
{ "statusCode": 403, "message": "Requires one of: clinic_admin, super_admin", "error": "Forbidden" }
```
