Skip to main content

Revoke sessions

MethodPath
DELETE/auth/session/:option

Authentication · Account routes

Signs the caller out of one or more sessions. Use it for "sign out everywhere" and "sign out other devices" actions.

note

This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns.

Auth: Bearer token of a patient or a practitioner. Scope: The signed-in user's own sessions. A session id that is not one of the caller's sessions revokes nothing.

Request​

Path parameters​

NameTypeRequiredDescription
option"current" | "other" | "all" | string (uuid)YesWhich sessions to revoke. current is the session of the token you call with. other is every session except the current one. all is every session, including the current one. A uuid is one session id from List sessions.

No query parameters. No body.

Behaviour​

  • Revoked sessions stop working: their access tokens are rejected from the next request on, and their refresh tokens can no longer renew them.
  • current and all also end the token you called with. Sign in again afterwards.
  • current and a session id revoke exactly that one session. other leaves the current session alone.
  • A session id that is not one of your own sessions revokes nothing, but the answer is still 200 with { "revoked": true } and no other field. Check the id in the answer to see that a session was matched.
  • The response echoes the revoked sessions with revoked: true: one object for current or a session id, an array for other and all. other answers an empty array when there is no other session.
  • To end only the access token you hold, without ending the session, use Log out. That leaves the refresh token usable.

Example​

curl -X DELETE 'https://api.sandbox.ovok.com/auth/session/other' \
-H "Authorization: Bearer ${OVOK_TOKEN}"

Successful response​

200 — The revoked sessions. For other and all, a JSON array:

[
{
"id": "6b0d3f92-5a7c-4e18-b4d9-1c8a2e7f5d36",
"lastUpdated": "2026-10-02T17:12:41.000Z",
"authMethod": "password",
"remoteAddress": "198.51.100.7",
"browser": null,
"os": null,
"revoked": true
}
]

For current or a session id, a single object with the same fields:

{
"id": "8c5e7a21-4b9d-4f36-a1c8-0d2e6b9f3a54",
"lastUpdated": "2026-10-09T08:53:20.000Z",
"authMethod": "password",
"remoteAddress": "203.0.113.24",
"browser": "Chrome",
"os": "Mac OS",
"revoked": true
}
FieldTypeDescription
idstring (uuid)Session id. Missing when option is a session id that is not yours.
lastUpdatedstringWhen the session was last used to sign in or refresh. ISO 8601.
authMethodstringHow the session was started.
remoteAddressstringIP address the session was started from.
browserstring | nullBrowser name, when known.
osstring | nullOperating system, when known.
revokedbooleanAlways true.

Errors​

StatusMeaning
400The access token carries no session id, or the session's account could not be resolved.
401The bearer token is missing, invalid, expired or revoked.
422option is not current, other, all or a uuid.
429Too many requests.