For EHR integrators
SMART on FHIR
A launch-initiated app that reads a patient's medication list and opens this atlas to the anti-cancer agents on it. It removes the typing, not the thinking: what it shows is the same public literature you would reach by looking each drug up by hand.
What it does not do
- It makes no statement about the patient. No ranking, no severity score, no attribution. The output is a set of links.
- The medication list never reaches a NephTox server. It is read in the browser, matched there, and discarded there. No NephTox server-side code takes part in the handshake — the app is a public OAuth client using PKCE, so it holds no secret, and no access token or FHIR response ever reaches this site. The EHR's redirect back does carry the single-use authorization code in the page URL, so — like any page request — it appears in this site's ordinary access logs; it is useless there, because exchanging it requires the PKCE verifier, which never leaves the browser.What else reaches this site is what any link does: following a result opens
/drugs/<agent>, and that request appears in the same access logs like any other page view. One agent per click, never the list, never the patient — and the result links are built withprefetch={false}so an agent's name is sent only when a clinician chooses to open it, not merely because it was rendered. - It never writes back. Read-only scopes, and none of them requests the patient's identity.
Registration
https://nephtox.com/smart/launchhttps://nephtox.com/smart/applaunch patient/MedicationRequest.read patient/MedicationStatement.readSMART v1 scope syntax; a v2 server spells the same read-and-search permission patient/MedicationRequest.rs. Deliberately no patient/Patient.read, openid or fhirUser — the app never needs to know who the patient or the user is.iss the launch supplies, and the authorization and token endpoints the server advertises — must be https, and a launch that names anything else is stopped before a request is made.A deployment must also name the servers it accepts launches from, in NEXT_PUBLIC_SMART_ISS_ALLOWLIST (comma-separated origins). https alone would still let this page be pointed at any host, so a launch naming an unregistered server is refused.Matching, and its limits
Medications are matched on RxNorm codes against a table of 3,252 concepts covering the catalog's agents and the dispensable products that contain them. A medication with no RxNorm coding, or one that is not an agent in this atlas, is reported as unmatched rather than silently dropped — “nothing here is in the atlas” and “this list could not be read” are different answers and the app says which one it means.
10 agents have no dispensable product in RxNorm and match only if the source system codes the ingredient itself. Most are antibody-drug conjugates, where matching through the bare antibody would claim a conjugate the patient is not receiving; that coverage gap is deliberate.
Educational reference only — not medical advice, and not a clinical decision support tool. See methods for how the atlas is sourced.