

本文為英文版的機器翻譯版本，如內容有任何歧義或不一致之處，概以英文版為準。

# 在啟用 FHIR 的 HealthLake 資料存放區上建立 SMART
<a name="reference-smart-on-fhir-create-data-store"></a>

若要搭配 HealthLake 使用 FHIR 上的 SMART 架構，請使用`CreateFHIRDatastore`請求中指定的 `IdentityProviderConfiguration` 參數建立 HealthLake 資料存放區。在 `IdentityProviderConfiguration` 參數中，您可以指定下列資訊：
+ 將 [AuthorizationStrategy](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html) 設定為等於 `SMART_ON_FHIR_V1`。
+ 將 [IdpLambdaArn](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html) 設定為等於 AWS Lambda 您建立的 ARN，以使用授權伺服器管理字符解碼。
+ 將授權伺服器中指定的[中繼資料](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html)元素定義為 JSON 區塊。探索文件中會傳回這些中繼資料元素。
+ *選用*：啟用 [FineGrainedAuthorizationEnabled](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html)。指定 `True` 使用 HealthLake 提供的精細授權

**注意**  
建立資料存放區之後，您可以使用 變更其身分提供者組態，包括 `AuthorizationStrategy`、`Metadata`、 `IdpLambdaArn`和 `FineGrainedAuthorizationEnabled`值`UpdateFHIRDatastore`。更新身分提供者組態會將其完全取代，因此請包含您要保留的每個欄位；您省略的任何欄位都會清除。身分提供者更新會立即生效，而且不會將資料存放區移至 `UPDATING` 狀態。如需詳細資訊，請參閱[更新 HealthLake 資料存放區](managing-data-stores-update.md)。

您可以使用 AWS Command Line Interface (AWS CLI) 或透過其中一個 AWS 支援的 SDKs 在啟用 FHIR 的資料存放區上建立 SMART。不支援使用 HealthLake 主控台在啟用 FHIR 的 HealthLake 資料存放區上建立 SMART。

## 使用 AWS CLI 在啟用 FHIR 的 HealthLake 資料存放區上建立 SMART
<a name="create-smart-ds-request"></a>

您可以使用下列程式碼範例，使用 在啟用 FHIR 的 HealthLake 資料存放區上建立 SMART AWS CLI。在啟用 FHIR 的 HealthLake 資料存放區上建立 SMART 時，您必須指定 [`identity-provider-configuration`](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html) 參數。

在 `identity-provider-configuration` 參數中，您可以*選擇性地*啟用精細授權，方法是將 設定為`FineGrainedAuthorizationEnabled`等於 `True`。若要進一步了解精細授權，請參閱 [在啟用 FHIR 的 HealthLake 資料存放區上搭配 SMART 使用精細授權](reference-smart-on-fhir-fine-grained-authorization.md)。以下範例包含一個特殊字元`\`，用來表示換行或做為逸出字元。這是為了清楚起見。

```
aws healthlake create-fhir-datastore \
  --region us-east-1 \
  --datastore-name "your-data-store-name" \
  --datastore-type-version R4 \
  --preload-data-config PreloadDataType="SYNTHEA" \
  --sse-configuration '{ "KmsEncryptionConfig": { \
    "CmkType": "customer-managed-kms-key1",
    "KmsKeyId": "arn:aws:kms:us-east-1:your-account-id:key/your-key-id" } }' \
  --identity-provider-configuration  \
      '{"AuthorizationStrategy": "SMART_ON_FHIR_V1", \
      "FineGrainedAuthorizationEnabled": boolean-false-by-default, \
      "IdpLambdaArn": "arn:aws:lambda:your-region:your-account-id:function:your-lambda-name", \
      "Metadata": "{\"issuer\":\"https://ehr.example.com\",\"jwks_uri\":\"https://ehr.example.com/.well-known/jwks.json\",\"authorization_endpoint\":\"https://ehr.example.com/auth/authorize\",\"token_endpoint\":\"https://ehr.token.com/auth/token\",\"token_endpoint_auth_methods_supported\":[\"client_secret_basic\",\"foo\"],\"grant_types_supported\":[\"client_credentials\",\"foo\"],\"registration_endpoint\":\"https://ehr.example.com/auth/register\",\"scopes_supported\":[\"openid\",\"profile\",\"launch\"],\"response_types_supported\":[\"code\"],\"management_endpoint\":\"https://ehr.example.com/user/manage\",\"introspection_endpoint\":\"https://ehr.example.com/user/introspect\",\"revocation_endpoint\":\"https://ehr.example.com/user/revoke\",\"code_challenge_methods_supported\":[\"S256\"],\"capabilities\":[\"launch-ehr\",\"sso-openid-connect\",\"client-public\"]}"}'
```

成功時，您會收到下列 JSON 回應：

```
{
  "DatastoreArn": "arn:aws:healthlake:your-region:111122223333:datastore/fhir/your-datastore-id",
  "DatastoreEndpoint": "https://healthlake.{{region}}.amazonaws.com/datastore/{{datastoreId}}/r4/",
  "DatastoreId": "your-data-store-id",
  "DatastoreStatus": "data-store-creation-status"
}
```