Revoke sessions
| Method | Path |
|---|---|
DELETE | /auth/session/:option |
Authentication · Account routes
Signs the caller out of one or more sessions. Use it for "sign out everywhere" and "sign out other devices" actions.
note
This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns.
Auth: Bearer token of a patient or a practitioner. Scope: The signed-in user's own sessions. A session id that is not one of the caller's sessions revokes nothing.
Request
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
option | "current" | "other" | "all" | string (uuid) | Yes | Which sessions to revoke. current is the session of the token you call with. other is every session except the current one. all is every session, including the current one. A uuid is one session id from List sessions. |
No query parameters. No body.
Behaviour
- Revoked sessions stop working: their access tokens are rejected from the next request on, and their refresh tokens can no longer renew them.
currentandallalso end the token you called with. Sign in again afterwards.currentand a session id revoke exactly that one session.otherleaves the current session alone.- A session id that is not one of your own sessions revokes nothing, but the answer is still
200with{ "revoked": true }and no other field. Check theidin the answer to see that a session was matched. - The response echoes the revoked sessions with
revoked: true: one object forcurrentor a session id, an array forotherandall.otheranswers an empty array when there is no other session. - To end only the access token you hold, without ending the session, use Log out. That leaves the refresh token usable.
Example
curl -X DELETE 'https://api.sandbox.ovok.com/auth/session/other' \
-H "Authorization: Bearer ${OVOK_TOKEN}"
Successful response
200 — The revoked sessions. For other and all, a JSON array:
[
{
"id": "6b0d3f92-5a7c-4e18-b4d9-1c8a2e7f5d36",
"lastUpdated": "2026-10-02T17:12:41.000Z",
"authMethod": "password",
"remoteAddress": "198.51.100.7",
"browser": null,
"os": null,
"revoked": true
}
]
For current or a session id, a single object with the same fields:
{
"id": "8c5e7a21-4b9d-4f36-a1c8-0d2e6b9f3a54",
"lastUpdated": "2026-10-09T08:53:20.000Z",
"authMethod": "password",
"remoteAddress": "203.0.113.24",
"browser": "Chrome",
"os": "Mac OS",
"revoked": true
}
| Field | Type | Description |
|---|---|---|
id | string (uuid) | Session id. Missing when option is a session id that is not yours. |
lastUpdated | string | When the session was last used to sign in or refresh. ISO 8601. |
authMethod | string | How the session was started. |
remoteAddress | string | IP address the session was started from. |
browser | string | null | Browser name, when known. |
os | string | null | Operating system, when known. |
revoked | boolean | Always true. |
Errors
| Status | Meaning |
|---|---|
400 | The access token carries no session id, or the session's account could not be resolved. |
401 | The bearer token is missing, invalid, expired or revoked. |
422 | option is not current, other, all or a uuid. |
429 | Too many requests. |