Skip to content

Developer · OAuth 2.0

Sign in with Dentra

OAuth 2.0 and OpenID Connect: practices sign in to your app with the «Sign in with Dentra» button, without another password. You learn who they are and, if they allow it, their practice details.

How it works

Sign in with Dentra follows the OAuth 2.0 and OpenID Connect standards: your app opens a Dentra page, the practice signs in and agrees on a consent screen, and your app receives keys to know who it is and read what it was granted.

It works for desktop apps, which can't keep a secret, and for websites with a server. The Dentra account is the practice's: one account, one practice.

Until we approve it, your app is in test mode: it opens only with your own Dentra account and receives the data of a sample practice. Once approved, it opens to every practice.

Registering the app

  1. You need a Dentra account with Developer access: request it in /app, under «Developer» in the account menu.
  2. In the Developer page, «Sign in with Dentra» tab, press «Register an application» and enter the name, what kind of app it is, the data controller, the link to your privacy notice, the redirect addresses and the permissions you need.
  3. You get the app code (client_id). A website also gets a secret, shown only once. A desktop app has no secret: PKCE protects it.
  4. Upload your logo (PNG, JPG or WEBP, up to 512 KB): it appears on the consent screen with the controller's name and the link to your privacy notice, which must be https.
  5. A website's redirect addresses are https (http only on 127.0.0.1, for local testing). A desktop app's are http://127.0.0.1/<path>, with no port and never localhost, or your own scheme. You can change redirect addresses, sign-out addresses and the logo at any time; you choose the permissions when you register and they can't be changed afterwards.

The discovery document

The OAuth and OpenID Connect addresses are also in the discovery document; the API ones (/api/v1) are not.

discovery
https://dentra.it/.well-known/openid-configuration

Addresses

Restricted

Opens when you sign in with active Developer access.

Connecting step by step

Restricted

Opens when you sign in with active Developer access.

Permissions

Request only what you need: the consent screen lists every permission, and you can request only those registered for your app.

Every app has openid, email and profile. openid must be requested at every sign-in: it says who it is, with an identifier that never changes. email and profile (the name) arrive in the id_token, from userinfo and in the user section of /api/v1/me only if you request them: without them, those fields are null.

offline_access
Stays connected: you also get a refresh key.
clinic:read
The practice: name, VAT number, address, contacts, active Dentra systems. Adds clinic_id to the sign-in.
orders:read
Open orders: number, status, dates and type of work. Never patient data.
preferences:read
The practice's clinical preferences.
systems:read
Dentra systems: which exist, which the practice has, on which plan, and how your app uses them (GET /api/v1/systems).
oralsnap:model
Use Oralsnap Model embedded in your app: the scan stays on the practice's computer.

Keys, refresh and sign-out

Restricted

Opens when you sign in with active Developer access.

Practice data

Restricted

Opens when you sign in with active Developer access.

Dentra systems in your app

Restricted

Opens when you sign in with active Developer access.

The subscription

Restricted

Opens when you sign in with active Developer access.

Rules and privacy

  • Once the practice agrees, you are the controller of the data you receive: you handle it under your privacy notice, which appears on the consent screen.
  • You never receive patient data, files, invoices or the memories of Dentra's assistant, and you can't order or change anything on the practice's behalf.
  • Don't present your app as a Dentra product: the screen always says whose it is.