Security and Data Access
1 min
the formulary download api restricts content based on the account of the user accessing the system—identified by the mtls client certificate submitted in the request in addition to mtls certificate validation, all requests to the formulary download api must include the http header x participant id this header must contain the participant id associated with the requester surescripts uses this value in conjunction with the mtls client certificate to validate that the requester is authorized to access the requested data surescripts validates the submitted certificate and determines the associated account id and participant id these are used to determine the ncpdp formulary & benefit version(s) available to the requester • the requester’s preferred drug database for rolled up formulary data any permission restrictions for accessing formulary data