Skip to main contentArrow Right
All storiesArrow Left

b.well Connected Health: Unified user and machine identity at scale

Descope bwell customer story thumbnail

b.well Connected Health gives people one place to gather and act on their health data, serving patients directly and through partner platforms. Unifying identity through Descope let b.well meet compliance requirements and adopt new patterns like FHIR scopes for machine access control and outbound SSO. Here’s how Descope helped them keep the same business logic while reducing cost, complexity, and engineering effort associated with high-volume token exchanges.


About b.well Connected Health

b.well is the connective layer between patients and the health data scattered across systems that hold it. The company works with partners including Samsung and Walgreens, and its platform sits behind consumer health experiences announced with OpenAI, Google, and Perplexity.

Logan Edwards, Senior Director of Engineering at b.well, said:

“The mission at b.well is to simplify healthcare. We focus on helping people access, manage, and truly own their health data. EMRs don’t talk to each other by default. That’s why we help you see all your health data in one place, with the least friction possible.”

Partners can serve b.well to their end customers using two integration patterns:

  • A partner authenticates its own users and b.well appears seamlessly inside their product, without re-authenticating

  • b.well builds the end-to-end experience, white-labeled to the partner’s brand

Why Descope

Compliance was the primary driver for seeking an external auth vendor, made more urgent by the growing number of enterprise partners b.well serves. A major customer’s requirements led b.well to seek vendors with native FHIR compliance.

The second compelling event was the sheer volume of partner-driven token exchanges, measured in tens of millions per month. On their incumbent provider, the cost of these machine-to-machine transactions began to soar. The team was now working against the clock to find an alternative with friendlier pricing.

The final piece came from what b.well themselves were building: a FHIR (Fast Healthcare Interoperability Resources) database that works as a master patient index, resolving the same person across partner ecosystems that would otherwise hold unconnected records for them. 

Getting those identifiers into a token uses a pipeline designed by b.well’s engineering team: Lambda triggers, SDK calls, and a gateway service handle the business logic around them. b.well had already solved their FHIR scoping model, so what they needed was an auth provider who could fit neatly into that flow rather than ripping and replacing it.

b.well had already solved the identifier enrichment problem, but at a cost: claim customization sat outside what their previous provider offered by default, with their gateway handling the surrounding logic.

Logan Edwards, Senior Director of Engineering at b.well, said:

“OAuth and FHIR compliance were obviously top of mind during vendor selection, but so was the ability to customize a user’s claims on their token. That wasn’t out-of-the-box, and we were paying for it. The fact that Descope did that by default and offered even more options definitely impressed.”

Beyond OAuth compliance and custom claims on tokens, b.well wanted the ability to leverage plug-and -play components it wouldn’t have to build. If the organization was going to work with an external auth provider, out-of-the-box building blocks Descope provided made the migration more worthwhile. That included features like diverse multi-factor authentication (MFA) options, passkeys, single sign-on (SSO), and easily maintainable flows.

The Descope experience

b.well started their Descope implementation with machine-to-machine (M2M) authentication, aiming to address rising costs and rate limits on their existing system.

Logan Edwards, Senior Director of Engineering at b.well, said:

“M2M was the right place to start. We validated that Descope could handle our scaling needs better than what we were on, before anything touched a patient. The migration itself was a non-event, which is exactly what you want.”

b.well bases its standards on FHIR and uses FHIR-specific scopes for access control, so moving meant building app clients carrying those same scopes. Their M2M traffic now runs through Descope Inbound Apps on the OAuth Client Credentials flow, with roles and permissions attached. These span their FHIR service, token service, and integration hub. Using the Descope Terraform provider and a GitHub Actions wrapper, b.well manages scopes and Inbound Apps in a version-controlled manner alongside the rest of their infrastructure. 

Some aspects of their previous solution needed to be rebuilt, but Descope’s dev-friendly tooling made this a light effort. Signup and authentication journeys now run as Descope Flows embedded as web components inside their React and React Native apps, with per-tenant styling and per-partner custom domains. Each white-labeled experience keeps its own look and feel, and end-patients don’t see b.well screens or branding unless the partner chooses to expose it. 

Imran Qureshi, Chief Technology Officer and Chief AI Officer at b.well, said:

"Descope flows save us from building auth UI, which can be tricky to make secure. And the Descope MCP Server can edit Flows, so we don't even need to learn the Descope Console. The Descope CI/CD promotion is cool because you can promote Descope changes from dev to staging to prod like code."

b.well can now offer auth methods and features with drop-in, out-of-the-box simplicity: passkeys (including Face ID and Touch ID on native), authenticator apps, magic links, per-tenant MFA policy (plus saving user preferences), and self-service SSO.

b.well login screen

For their partner-side build, Descope paves the way for easier onboarding. When building for one partner, for example, patients needed to click through the portal to third-party services for cost estimates and similar tasks, which meant outbound federation. b.well knew this was a solved problem, and their engineers’ time was better spent on the core product rather than building this from scratch.

b.well built those portal journeys on Descope Federated Apps, with Flows handling the assertion binding. The same design balance shows up in b.well’s signup flows, where an HTTP Connector calls back into b.well’s own systems. Descope does the protocol work, and the rules that decide what a patient can see stay where b.well wants them, in their own backend.

Improving patient access, one login at a time

Several capabilities in Descope were spurred on by b.well’s technical requirements:

  • An Epic electronic health record(EHR) client-assertion function needed RS384 signing where Descope’s default was RS256; Descope swiftly added support and documentation 

  • Descope also added support for JSON objects as custom claims, alongside larger claim payloads

  • b.well provided valuable input for extending Descope’s delegation mechanisms, which would serve caregivers of patients or those signing in on behalf of dependents

b.well Connected Health went looking for an identity provider that could satisfy enterprise compliance needs and bring down the cost of high-volume token exchange. They got both, and along the way, they also added passkeys, fully featured MFA, and outbound SSO their engineers never had to build. 

Logan Edwards, Senior Director of Engineering at b.well, said:

“For engineering leaders of organizations in a similar scenario, I’d encourage them to lean into what a vendor offers as their value-add. Compliance and M2M volume were what started our search, but we got so much more by choosing Descope.”

While the migration is complete, b.well’s engineering team looks forward to expanding their Descope solution by leveraging features like agentic identity (their platform already boasts an agent-ready SDK) and end-to-end automation. Their team expects automation to deliver the most value, with setting up and managing infrastructure across different customer verticals becoming significantly easier than before.

Ross Hosman, Chief Information Security Officer at b.well, said:

"I’d like to thank the Descope team for this winning partnership. They’ve completely changed how our engineering team thinks about and does auth in our applications today."


Descope is a flexible customer and agentic platform that helps organizations easily add authentication, authorization, and identity management to their apps, AI agents, and MCP servers. Customers use us for initiatives such as passwordless authentication, SSO, identity federation, strong MFA, fraud prevention, and agentic identity.

To get started with Descope, sign up for a Free Forever account. If you have questions about our platform, book time with our auth experts.