Skip to main content

Get account information

MethodPath
GET/auth/me

Authentication · Account routes · Access policies

Returns the signed-in user's context: account, project, membership, profile, access policy and security details such as the second-factor status and sessions. Call it after sign-in to learn who the token belongs to.

note

This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns.

Auth: Bearer token of a patient or a practitioner. A missing, non-bearer, invalid, expired or revoked token gives 401. Scope: The project of the token.

Request​

No parameters.

Behaviour​

  • The answer is the FHIR server's own auth/me document for the session of the token.
  • Every call discards the cached copy of this user's profile and reads a fresh one. A change to the profile or the access policy shows up in this response and in later requests with the same token.
  • Use profile.resourceType to tell patients from practitioners. A client application token answers with ClientApplication.
  • security.sessions lists only recently active sessions and at most 20 of them. A session that has been idle for an hour is missing from it. Use List sessions for the complete list.
  • Only a bearer token is accepted. Basic credentials give 401.

Example​

curl -X GET 'https://api.sandbox.ovok.com/auth/me' \
-H "Authorization: Bearer ${OVOK_TOKEN}"

Successful response​

200 — The user's context. The example is trimmed.

{
"user": {
"resourceType": "User",
"id": "9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
"email": "alex@example.com"
},
"project": {
"resourceType": "Project",
"id": "1e6b8d30-2c4f-4a95-8d7e-b0a2c4e6f918",
"name": "Example Project"
},
"membership": {
"resourceType": "ProjectMembership",
"id": "5d2a9c64-7e1b-4830-b6f5-9a3c1e8d7b02",
"user": {
"reference": "User/9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
"display": "alex@example.com"
},
"profile": {
"reference": "Patient/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21",
"display": "Alex Example"
}
},
"profile": {
"resourceType": "Patient",
"id": "3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21",
"name": [{ "given": ["Alex"], "family": "Example" }],
"telecom": [{ "system": "email", "use": "work", "value": "alex@example.com" }]
},
"config": {
"resourceType": "UserConfiguration",
"menu": [{ "title": "Favorites", "link": [] }]
},
"accessPolicy": {
"resourceType": "AccessPolicy",
"resource": [{ "resourceType": "Patient" }]
},
"security": {
"mfaEnrolled": false,
"sessions": [
{
"id": "8c5e7a21-4b9d-4f36-a1c8-0d2e6b9f3a54",
"lastUpdated": "2026-10-09T08:53:20.000Z",
"authMethod": "password",
"remoteAddress": "203.0.113.24",
"browser": "Chrome",
"os": "Mac OS"
}
]
}
}

The body is a FHIR-style document, not a single resource. Other fields of the FHIR server's auth/me answer can be present.

FieldTypeDescription
userobjectThe User resource of the account.
user.idstring (uuid)User id.
user.emailstringSign-in email address.
projectobjectThe Project the token is for.
project.idstring (uuid)Project id.
project.namestringProject name.
membershipobjectThe ProjectMembership that ties the user to the project.
membership.idstring (uuid)Membership id.
membership.userobjectReference to the User, with reference and display.
membership.profileobjectReference to the Patient or Practitioner, with reference and display.
profileobjectThe signed-in Patient or Practitioner. For a client application token it is the ClientApplication.
profile.resourceType"Patient" | "Practitioner" | "ClientApplication"Kind of profile.
profile.idstring (uuid)Profile id.
profile.nameobject[]The profile's names, as on the FHIR resource.
profile.telecomobject[]The profile's contact points, as on the FHIR resource.
configobjectThe user's UserConfiguration, for example the app menu.
accessPolicyobjectThe AccessPolicy that applies to the membership. Left out when the membership has none.
security.mfaEnrolledbooleanWhether the user has enrolled a second factor.
security.sessionsobject[]Recently active sessions, in no guaranteed order. At most 20.
security.sessions[].idstring (uuid)Session id.
security.sessions[].lastUpdatedstringWhen the session was last used to sign in or refresh. ISO 8601.
security.sessions[].authMethodstringHow the session was started, for example password.
security.sessions[].remoteAddressstringIP address the session was started from.
security.sessions[].browserstringBrowser name, when known.
security.sessions[].osstringOperating system, when known.

Errors​

StatusMeaning
400The access token carries no session id, so it is not a user session token.
401The bearer token is missing, not a bearer token, invalid, expired or revoked.
429Too many requests.