Cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Help with Web API traffic

Hey all,

 

I work for a healthcare organization and we are trying to sync Fitbit data back into our Epic EMR environment. Using a reverse proxy server endpoint to send the traffic through we are running into issues figuring out what to "whitelist." I have seen the documentation stating not to whitelist but does anyone know if all the traffic is at least coming from api.fitbit.com? Thanks for your time.

Best Answer
0 Votes
1 REPLY 1

Hi @Telehealthynhh,

 

You are correct, you should not whitelist the Fitbit IP addresses for your subscriber endpoints.  Instead, you should verify the X-fitbit-Signature header in the requests.  The data should be coming from a fitbit.com server.

 

Please read the Security section of the documentation for more information.

 

Gordon

Gordon Crenshaw
Senior Technical Solutions Consultant
Fitbit Partner Engineering & Web API Support | Google
Best Answer
0 Votes