Open the provider-hosted enrollment session
Returns a HealthSherpa-hosted enrollment session for a deeplink-routed application, for the authorized agent to open in their own browser. Available only while authorized_actions contains the deeplink rel.
Each call opens a new session, so request one per launch rather than storing the URL. expires_at is null when the provider does not state an expiry; that means unknown, not unlimited. Nothing on the application changes until HealthSherpa reports the hosted application back, so keep polling the application details rather than assuming it launched.
Authentication
API Key or Access Token authentication using Bearer token in Authorization header. API keys use the vit_apk_ prefix, access tokens use the vit_at_ prefix.
Path parameters
Headers
Organization to act as for this request (e.g. org_SGVsbG8gV29ybGQ). Optional when your credentials reach a single organization. Required when they reach several — omitting it then returns 400 organization_required. A malformed value returns 400 invalid_organization_header, and naming an organization you do not have access to returns 403 organization_access_denied.
Response headers
Unix timestamp (seconds) when the rate limit window resets

