List sessions
| Method | Path |
|---|---|
GET | /auth/session |
Authentication · Account routes
Lists the caller's sessions, one per sign-in. Use it to build a "where you are signed in" screen, and to find the session id to pass to Revoke sessions.
note
This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns.
Auth: Bearer token of a patient or a practitioner. Scope: The signed-in user's own sessions.
Request
No parameters.
Behaviour
- A session is listed when it belongs to the user, has a project membership and is not revoked. A session that has been idle for a long time is listed as long as it is not revoked.
- The list is ordered newest first, by the time each session was last used to sign in or refresh.
- Nothing in the list marks the current session. Its
idis thelogin_idclaim of your access token. browserandosarenullfor sessions that the FHIR server has not reported them for, such as sessions idle for an hour or more.- The call only reads. It does not change any session.
Example
curl -X GET 'https://api.sandbox.ovok.com/auth/session' \
-H "Authorization: Bearer ${OVOK_TOKEN}"
Successful response
200 — A JSON array with one object per session.
[
{
"id": "8c5e7a21-4b9d-4f36-a1c8-0d2e6b9f3a54",
"lastUpdated": "2026-10-09T08:53:20.000Z",
"authMethod": "password",
"remoteAddress": "203.0.113.24",
"browser": "Chrome",
"os": "Mac OS"
},
{
"id": "6b0d3f92-5a7c-4e18-b4d9-1c8a2e7f5d36",
"lastUpdated": "2026-10-02T17:12:41.000Z",
"authMethod": "password",
"remoteAddress": "198.51.100.7",
"browser": null,
"os": null
}
]
| Field | Type | Description |
|---|---|---|
[].id | string (uuid) | Session id. Pass it to DELETE /auth/session/:option to revoke this session. |
[].lastUpdated | string | When the session was last used to sign in or refresh. ISO 8601. |
[].authMethod | string | How the session was started, for example password. |
[].remoteAddress | string | IP address the session was started from. |
[].browser | string | null | Browser name, when known. |
[].os | string | null | Operating system, when known. |
Errors
| Status | Meaning |
|---|---|
400 | The access token carries no session id, or the session's account could not be resolved. |
401 | The bearer token is missing, invalid, expired or revoked. |
429 | Too many requests. |