Skip to main content

List sessions

MethodPath
GET/auth/session

Authentication · Account routes

Lists the caller's sessions, one per sign-in. Use it to build a "where you are signed in" screen, and to find the session id to pass to Revoke sessions.

note

This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns.

Auth: Bearer token of a patient or a practitioner. Scope: The signed-in user's own sessions.

Request​

No parameters.

Behaviour​

  • A session is listed when it belongs to the user, has a project membership and is not revoked. A session that has been idle for a long time is listed as long as it is not revoked.
  • The list is ordered newest first, by the time each session was last used to sign in or refresh.
  • Nothing in the list marks the current session. Its id is the login_id claim of your access token.
  • browser and os are null for sessions that the FHIR server has not reported them for, such as sessions idle for an hour or more.
  • The call only reads. It does not change any session.

Example​

curl -X GET 'https://api.sandbox.ovok.com/auth/session' \
-H "Authorization: Bearer ${OVOK_TOKEN}"

Successful response​

200 — A JSON array with one object per session.

[
{
"id": "8c5e7a21-4b9d-4f36-a1c8-0d2e6b9f3a54",
"lastUpdated": "2026-10-09T08:53:20.000Z",
"authMethod": "password",
"remoteAddress": "203.0.113.24",
"browser": "Chrome",
"os": "Mac OS"
},
{
"id": "6b0d3f92-5a7c-4e18-b4d9-1c8a2e7f5d36",
"lastUpdated": "2026-10-02T17:12:41.000Z",
"authMethod": "password",
"remoteAddress": "198.51.100.7",
"browser": null,
"os": null
}
]
FieldTypeDescription
[].idstring (uuid)Session id. Pass it to DELETE /auth/session/:option to revoke this session.
[].lastUpdatedstringWhen the session was last used to sign in or refresh. ISO 8601.
[].authMethodstringHow the session was started, for example password.
[].remoteAddressstringIP address the session was started from.
[].browserstring | nullBrowser name, when known.
[].osstring | nullOperating system, when known.

Errors​

StatusMeaning
400The access token carries no session id, or the session's account could not be resolved.
401The bearer token is missing, invalid, expired or revoked.
429Too many requests.