Skip to navigation

Open the provider-hosted enrollment session

Returns a HealthSherpa-hosted enrollment session for a deeplink-routed application, for the authorized agent to open in their own browser. Available only while authorized_actions contains the deeplink rel.

Each call opens a new session, so request one per launch rather than storing the URL. expires_at is null when the provider does not state an expiry; that means unknown, not unlimited. Nothing on the application changes until HealthSherpa reports the hosted application back, so keep polling the application details rather than assuming it launched.

Authentication

AuthorizationBearer

API Key or Access Token authentication using Bearer token in Authorization header. API keys use the vit_apk_ prefix, access tokens use the vit_at_ prefix.

Path parameters

carrier_application_idstringRequired

Headers

X-Vitable-OrganizationstringOptional

Organization to act as for this request (e.g. org_SGVsbG8gV29ybGQ). Optional when your credentials reach a single organization. Required when they reach several — omitting it then returns 400 organization_required. A malformed value returns 400 invalid_organization_header, and naming an organization you do not have access to returns 403 organization_access_denied.

Response headers

X-RateLimit-Limitinteger
Maximum number of requests allowed within the rate limit window
X-RateLimit-Remaininginteger
Number of requests remaining in the current rate limit window
X-RateLimit-Resetinteger

Unix timestamp (seconds) when the rate limit window resets

Response

This endpoint returns an object.
dataobject

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
409
Conflict Error
429
Too Many Requests Error
500
Internal Server Error
502
Bad Gateway Error