Log out
| Method | Path |
|---|---|
POST | /v1/auth/logout |
Authentication · Account routes
Signs the caller out on the server. The access token in the Authorization header stops working for every authenticated route, although it has not expired.
note
This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns. The same route also answers at /auth/logout, without /v1.
Auth: Bearer token of a patient or a practitioner. A missing or invalid token gives 401.
Scope: The access token you call with.
Request
No parameters. No body.
Behaviour
- Only this access token is ended. The session and its refresh token are not touched, so the refresh token can still renew the session. To end the session itself, use Revoke sessions with
current. - The token is rejected for the rest of its lifetime. A token that has already expired is ignored.
- Repeating the call with the same token answers
401, because the token no longer works. - If revocation cannot be stored on the server, the call still answers
204and the token stays valid until it expires. Clear the local session as well. - The response has no body.
Example
curl -X POST 'https://api.sandbox.ovok.com/v1/auth/logout' \
-H "Authorization: Bearer ${OVOK_TOKEN}"
Successful response
204 — No content. The access token no longer works.
Errors
| Status | Meaning |
|---|---|
401 | The bearer token is missing, invalid, expired or already revoked. |
429 | Too many requests. |