Skip to main content

Log out

MethodPath
POST/v1/auth/logout

Authentication · Account routes

Signs the caller out on the server. The access token in the Authorization header stops working for every authenticated route, although it has not expired.

note

This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns. The same route also answers at /auth/logout, without /v1.

Auth: Bearer token of a patient or a practitioner. A missing or invalid token gives 401. Scope: The access token you call with.

Request​

No parameters. No body.

Behaviour​

  • Only this access token is ended. The session and its refresh token are not touched, so the refresh token can still renew the session. To end the session itself, use Revoke sessions with current.
  • The token is rejected for the rest of its lifetime. A token that has already expired is ignored.
  • Repeating the call with the same token answers 401, because the token no longer works.
  • If revocation cannot be stored on the server, the call still answers 204 and the token stays valid until it expires. Clear the local session as well.
  • The response has no body.

Example​

curl -X POST 'https://api.sandbox.ovok.com/v1/auth/logout' \
-H "Authorization: Bearer ${OVOK_TOKEN}"

Successful response​

204 — No content. The access token no longer works.

Errors​

StatusMeaning
401The bearer token is missing, invalid, expired or already revoked.
429Too many requests.