Get account information
| Method | Path |
|---|---|
GET | /auth/me |
Authentication · Account routes · Access policies
Returns the signed-in user's context: account, project, membership, profile, access policy and security details such as the second-factor status and sessions. Call it after sign-in to learn who the token belongs to.
note
This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns.
Auth: Bearer token of a patient or a practitioner. A missing, non-bearer, invalid, expired or revoked token gives 401.
Scope: The project of the token.
Request
No parameters.
Behaviour
- The answer is the FHIR server's own
auth/medocument for the session of the token. - Every call discards the cached copy of this user's profile and reads a fresh one. A change to the profile or the access policy shows up in this response and in later requests with the same token.
- Use
profile.resourceTypeto tell patients from practitioners. A client application token answers withClientApplication. security.sessionslists only recently active sessions and at most 20 of them. A session that has been idle for an hour is missing from it. Use List sessions for the complete list.- Only a bearer token is accepted. Basic credentials give
401.
Example
curl -X GET 'https://api.sandbox.ovok.com/auth/me' \
-H "Authorization: Bearer ${OVOK_TOKEN}"
Successful response
200 — The user's context. The example is trimmed.
{
"user": {
"resourceType": "User",
"id": "9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
"email": "alex@example.com"
},
"project": {
"resourceType": "Project",
"id": "1e6b8d30-2c4f-4a95-8d7e-b0a2c4e6f918",
"name": "Example Project"
},
"membership": {
"resourceType": "ProjectMembership",
"id": "5d2a9c64-7e1b-4830-b6f5-9a3c1e8d7b02",
"user": {
"reference": "User/9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
"display": "alex@example.com"
},
"profile": {
"reference": "Patient/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21",
"display": "Alex Example"
}
},
"profile": {
"resourceType": "Patient",
"id": "3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21",
"name": [{ "given": ["Alex"], "family": "Example" }],
"telecom": [{ "system": "email", "use": "work", "value": "alex@example.com" }]
},
"config": {
"resourceType": "UserConfiguration",
"menu": [{ "title": "Favorites", "link": [] }]
},
"accessPolicy": {
"resourceType": "AccessPolicy",
"resource": [{ "resourceType": "Patient" }]
},
"security": {
"mfaEnrolled": false,
"sessions": [
{
"id": "8c5e7a21-4b9d-4f36-a1c8-0d2e6b9f3a54",
"lastUpdated": "2026-10-09T08:53:20.000Z",
"authMethod": "password",
"remoteAddress": "203.0.113.24",
"browser": "Chrome",
"os": "Mac OS"
}
]
}
}
The body is a FHIR-style document, not a single resource. Other fields of the FHIR server's auth/me answer can be present.
| Field | Type | Description |
|---|---|---|
user | object | The User resource of the account. |
user.id | string (uuid) | User id. |
user.email | string | Sign-in email address. |
project | object | The Project the token is for. |
project.id | string (uuid) | Project id. |
project.name | string | Project name. |
membership | object | The ProjectMembership that ties the user to the project. |
membership.id | string (uuid) | Membership id. |
membership.user | object | Reference to the User, with reference and display. |
membership.profile | object | Reference to the Patient or Practitioner, with reference and display. |
profile | object | The signed-in Patient or Practitioner. For a client application token it is the ClientApplication. |
profile.resourceType | "Patient" | "Practitioner" | "ClientApplication" | Kind of profile. |
profile.id | string (uuid) | Profile id. |
profile.name | object[] | The profile's names, as on the FHIR resource. |
profile.telecom | object[] | The profile's contact points, as on the FHIR resource. |
config | object | The user's UserConfiguration, for example the app menu. |
accessPolicy | object | The AccessPolicy that applies to the membership. Left out when the membership has none. |
security.mfaEnrolled | boolean | Whether the user has enrolled a second factor. |
security.sessions | object[] | Recently active sessions, in no guaranteed order. At most 20. |
security.sessions[].id | string (uuid) | Session id. |
security.sessions[].lastUpdated | string | When the session was last used to sign in or refresh. ISO 8601. |
security.sessions[].authMethod | string | How the session was started, for example password. |
security.sessions[].remoteAddress | string | IP address the session was started from. |
security.sessions[].browser | string | Browser name, when known. |
security.sessions[].os | string | Operating system, when known. |
Errors
| Status | Meaning |
|---|---|
400 | The access token carries no session id, so it is not a user session token. |
401 | The bearer token is missing, not a bearer token, invalid, expired or revoked. |
429 | Too many requests. |