{
  "resourceType": "StructureDefinition",
  "id": "IdentityProvider",
  "url": "https://haste-health.com/StructureDefinition/IdentityProvider",
  "version": "4.0.1",
  "name": "IdentityProvider",
  "status": "active",
  "publisher": "haste-health",
  "fhirVersion": "4.0.1",
  "kind": "resource",
  "abstract": false,
  "type": "IdentityProvider",
  "description": "External identity provider configuration.",
  "baseDefinition": "http://hl7.org/fhir/StructureDefinition/Resource",
  "derivation": "specialization",
  "snapshot": {
    "element": [
      {
        "id": "IdentityProvider",
        "path": "IdentityProvider",
        "min": 0,
        "definition": "External identity provider configuration.",
        "max": "*",
        "base": {
          "path": "IdentityProvider",
          "min": 0,
          "max": "*"
        },
        "isModifier": false,
        "isSummary": false
      },
      {
        "id": "IdentityProvider.id",
        "path": "IdentityProvider.id",
        "short": "Logical id of this artifact",
        "definition": "The logical id of the resource, as used in the URL for the resource. Once assigned, this value never changes.",
        "comment": "The only time that a resource does not have an id is when it is being submitted to the server using a create operation.",
        "min": 0,
        "max": "1",
        "base": {
          "path": "Resource.id",
          "min": 0,
          "max": "1"
        },
        "type": [
          {
            "extension": [
              {
                "url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-fhir-type",
                "valueUrl": "string"
              }
            ],
            "code": "http://hl7.org/fhirpath/System.String"
          }
        ],
        "isModifier": false,
        "isSummary": true
      },
      {
        "id": "IdentityProvider.meta",
        "path": "IdentityProvider.meta",
        "short": "Metadata about the resource",
        "definition": "The metadata about the resource. This is content that is maintained by the infrastructure. Changes to the content might not always be associated with version changes to the resource.",
        "min": 0,
        "max": "1",
        "base": {
          "path": "Resource.meta",
          "min": 0,
          "max": "1"
        },
        "type": [
          {
            "code": "Meta"
          }
        ],
        "constraint": [
          {
            "key": "ele-1",
            "severity": "error",
            "human": "All FHIR elements must have a @value or children",
            "expression": "hasValue() or (children().count() > id.count())",
            "xpath": "@value|f:*|h:div",
            "source": "http://hl7.org/fhir/StructureDefinition/Element"
          }
        ],
        "isModifier": false,
        "isSummary": true
      },
      {
        "id": "IdentityProvider.name",
        "path": "IdentityProvider.name",
        "definition": "The name of the external identity provider.",
        "short": "The name of the external identity provider.",
        "type": [
          {
            "code": "string"
          }
        ],
        "min": 1,
        "max": "1"
      },
      {
        "id": "IdentityProvider.status",
        "path": "IdentityProvider.status",
        "definition": "The status of the identity provider.",
        "short": "The status of the identity provider.",
        "type": [
          {
            "code": "code"
          }
        ],
        "min": 1,
        "max": "1",
        "binding": {
          "strength": "required",
          "valueSet": "https://haste.health/fhir/ValueSet/IdentityProviderStatus|4.0.1"
        }
      },
      {
        "id": "IdentityProvider.accessType",
        "path": "IdentityProvider.accessType",
        "definition": "Method for connecting to external identity provider.",
        "short": "Method for connecting to external identity provider.",
        "type": [
          {
            "code": "code"
          }
        ],
        "min": 1,
        "max": "1",
        "binding": {
          "strength": "required",
          "valueSet": "https://haste.health/fhir/ValueSet/IdentityProviderAccessType|4.0.1"
        }
      },
      {
        "id": "IdentityProvider.oidc",
        "path": "IdentityProvider.oidc",
        "definition": "OIDC connection configuration for the identity provider.",
        "short": "OIDC connection configuration for the identity provider.",
        "type": [
          {
            "code": "BackboneElement"
          }
        ],
        "min": 0,
        "max": "1"
      },
      {
        "id": "IdentityProvider.oidc.authorization_endpoint",
        "path": "IdentityProvider.oidc.authorization_endpoint",
        "definition": "OIDC authorization endpoint.",
        "short": "OIDC authorization endpoint.",
        "type": [
          {
            "code": "string"
          }
        ],
        "min": 1,
        "max": "1"
      },
      {
        "id": "IdentityProvider.oidc.token_endpoint",
        "path": "IdentityProvider.oidc.token_endpoint",
        "definition": "OIDC token endpoint.",
        "short": "OIDC token endpoint.",
        "type": [
          {
            "code": "string"
          }
        ],
        "min": 1,
        "max": "1"
      },
      {
        "id": "IdentityProvider.oidc.userinfo_endpoint",
        "path": "IdentityProvider.oidc.userinfo_endpoint",
        "definition": "The OIDC user info endpoint.",
        "short": "The OIDC user info endpoint.",
        "type": [
          {
            "code": "string"
          }
        ],
        "min": 0,
        "max": "1"
      },
      {
        "id": "IdentityProvider.oidc.jwks_uri",
        "path": "IdentityProvider.oidc.jwks_uri",
        "definition": "If included will verify id token based on this jwks keys.",
        "short": "If included will verify id token based on this jwks keys.",
        "type": [
          {
            "code": "string"
          }
        ],
        "min": 0,
        "max": "1"
      },
      {
        "id": "IdentityProvider.oidc.scopes",
        "path": "IdentityProvider.oidc.scopes",
        "definition": "Scopes to send to the OIDC provider.",
        "short": "Scopes to send to the OIDC provider.",
        "type": [
          {
            "code": "string"
          }
        ],
        "min": 0,
        "max": "*"
      },
      {
        "id": "IdentityProvider.oidc.client",
        "path": "IdentityProvider.oidc.client",
        "definition": "Registered client for the OIDC provider.",
        "short": "Registered client for the OIDC provider.",
        "type": [
          {
            "code": "BackboneElement"
          }
        ],
        "min": 1,
        "max": "1"
      },
      {
        "id": "IdentityProvider.oidc.client.clientId",
        "path": "IdentityProvider.oidc.client.clientId",
        "definition": "Registered clients id.",
        "short": "Registered clients id.",
        "type": [
          {
            "code": "string"
          }
        ],
        "min": 1,
        "max": "1"
      },
      {
        "id": "IdentityProvider.oidc.client.secret",
        "path": "IdentityProvider.oidc.client.secret",
        "definition": "Registered clients secret.",
        "short": "Registered clients secret.",
        "type": [
          {
            "code": "string"
          }
        ],
        "min": 0,
        "max": "1"
      },
      {
        "id": "IdentityProvider.oidc.pkce",
        "path": "IdentityProvider.oidc.pkce",
        "definition": "PKCE Configuration",
        "short": "PKCE Configuration",
        "type": [
          {
            "code": "BackboneElement"
          }
        ],
        "min": 0,
        "max": "1"
      },
      {
        "id": "IdentityProvider.oidc.pkce.code_challenge_method",
        "path": "IdentityProvider.oidc.pkce.code_challenge_method",
        "definition": "PKCE code challenge method.",
        "short": "PKCE code challenge method.",
        "type": [
          {
            "code": "code"
          }
        ],
        "binding": {
          "strength": "required",
          "valueSet": "https://haste.health/fhir/ValueSet/IdentityProviderPKCEChallengeMethod|4.0.1"
        },
        "min": 0,
        "max": "1"
      },
      {
        "id": "IdentityProvider.oidc.pkce.enabled",
        "path": "IdentityProvider.oidc.pkce.enabled",
        "definition": "PKCE enabled.",
        "short": "PKCE enabled.",
        "type": [
          {
            "code": "boolean"
          }
        ],
        "min": 0,
        "max": "1"
      }
    ]
  }
}