Identity & Access for DrGodly

One secure identity for every patient, doctor, and care team

DrGodly’s identity platform verifies every sign-in and enforces exactly who can see what — across consultations, records, and every connected app.

OAuth 2.1 SecuredRole-Based AccessTwo-Factor AuthMulti-Clinic Ready
A doctor reviewing a consultation on a tablet
Platform Features

Everything your care platform needs

Purpose-built identity infrastructure for clinics, care teams, and every app patients and doctors rely on.

Multi-Clinic Support
Manage multiple clinics and care teams with isolated organizations, memberships, and permission scopes.
Role-Based Care Access
Define roles for doctors, nurses, and staff with granular permissions. DENY always overrides ALLOW for predictable access.
OAuth 2.1 & OIDC
Acts as a full OAuth 2.1 authorization server, issuing access, refresh, and ID tokens to every connected DrGodly app.
Session & Token Security
JWT with configurable expiry, refresh token rotation, API keys, and instant revocation when access needs to change.
Audit-Ready Activity Logs
Database-backed sessions and audit hooks, so you always know who accessed what, and when.
Two-Factor Authentication
Email OTP 2FA and magic-link sign-in add an extra layer of protection for sensitive care data.
How It Works

Simple flow, powerful control

Three phases that take every patient and doctor from sign-in to secure access.

01
Verify Every Sign-In
Email & password, social OAuth (GitHub, Google), magic links, and two-factor OTP keep every account secure.
  • Email & Password
  • OAuth Providers
  • Magic Links
  • 2FA / OTP
02
Assign Roles to Care Teams
Create roles with fine-grained permissions scoped to a clinic or care team. Supports role inheritance.
  • Custom role definitions
  • Permission inheritance
  • Team-level scoping
  • Dynamic access control
03
Enforce Access on Every Request
Every request is validated against effective permissions, with DENY always taking precedence.
  • Per-request validation
  • DENY overrides ALLOW
  • Cached permission sets
  • API key enforcement
Use Cases

Built for real-world care delivery

From a single clinic to a network of care teams and partners.

Telemedicine Consultations

Verify doctors and patients before every video visit, with session-level access tied to their role.

Multi-Clinic Networks

Each clinic gets its own organization, roles, and member list — fully isolated from every other tenant.

Care Team Collaboration

Doctors, nurses, and coordinators share patient context with permissions scoped to their exact role.

Partner & Insurance Integrations

Issue OAuth 2.1 tokens for service-to-service access, with scopes and audiences enforced consistently.

Security & Reliability

Secure by design

Every layer is designed with sensitive health data and predictable access in mind.

Token Rotation

Refresh tokens rotate automatically, with instant revocation when access needs to end.

Role Enforcement

Every protected action is checked against your role and permissions before it runs.

Persistent Sessions

Sessions are stored securely and cached briefly for a fast, reliable experience.

Audit Support

Authentication events and permission changes are tracked for accountability.

Built to Scale

A clean, modular architecture that grows with your clinics, teams, and integrations.

Least-Privilege Defaults

Every new account starts with guest-level access — elevated roles are granted explicitly.

Give every patient, doctor, and care team a secure way in

DrGodly’s identity platform is ready wherever you need it — web, mobile, and every connected app.