Fig. 2: SMART Backend Service Authorization Workflow.
From: Push Button Population Health: The SMART/HL7 FHIR Bulk Data Access Application Programming Interface

An authentication JWT is posted to an EHR authorization server, which responds with an access token.