Backend Services authenticates your application, not an individual end user — there’s no OAuth redirect or login screen. eClinicalWorks verifies a JWT that Nango signs on your behalf, checking it against a public key you publish yourself. Nango signs with
RS384, so the private key you generate and give Nango must be an RSA key — the same key type eClinicalWorks verifies against.1
Register your app with the eClinicalWorks Dev Portal
Go to the eClinicalWorks Platform for Open Development and register as a developer. Create an app entry and select the Backend Services (non-interactive, system-to-system) authentication type.
2
Generate an RSA key pair
eClinicalWorks requires Keep
RS384 for Backend Services apps that register a JSON Web Key Set URL (the setup this guide uses):privatekey.pem secret — you’ll paste its contents into Nango in a later step. Never commit it to source control or share it outside Nango.3
Host a JWKS file with your public key
Convert your public key to JWK format and publish it as a JWKS document at a stable, publicly reachable URL you control (e.g.
https://your-domain.com/.well-known/eclinicalworks-jwks.json). Assign a unique kid (key ID) to the key entry — you’ll need this exact value in Nango.4
Register your JWKS URL with eClinicalWorks
On your app’s entry in the Dev Portal, add the JWKS URL from the previous step and request the scope(s) your app needs (e.g.
system/Patient.read). Note the Client ID eClinicalWorks assigns your app — you’ll need it for the next step, along with the kid you chose.Include
system/Group.read in your scope request only if you need bulk Group/$export access — omit it if you only need the Backend Single Patient API.5
Enter your credentials in Nango
- In Nango, go to Integrations → your eClinicalWorks (FHIR) integration → Settings tab.
- Enter:
- Client ID — from the previous step
- Key ID — the
kidfrom your JWKS entry - Private Key — the full contents of
privatekey.pem, the RSA private key you generated in step 2. Nango signs withRS384, so this must be an RSA key — an EC key won’t work. - Scope — the SMART Backend Services scope(s) eClinicalWorks granted your app (e.g.
system/Patient.read)
6
Next
Follow the connect guide to create a connection for your first practice.