Give or withdraw the medical consent
| Method | Path |
|---|---|
POST | /v1/me/consent/medical |
Authentication · Account routes · Access policies
Gives or withdraws the medical settings notifications consent for the signed-in practitioner and returns the resulting medical consent. Other consents are not changed.
note
This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns.
Auth: Bearer token of a practitioner session (the profile must be a Practitioner). The caller's access policy must grant Consent:read, Consent:search, Consent:create and Consent:update. Project admins skip the access policy check.
Scope: The caller's practitioner profile in the project of the token.
Request
Body
| Name | Type | Required | Description |
|---|---|---|---|
medicalSettingsNotificationsConsent | boolean | Yes | true gives the consent on the currently published version. false withdraws it. |
Behaviour
truerecords the consent on the currently published version.falsewithdraws it.- Sending the current value again writes nothing.
- The value that
GET /v1/slim/user/consentsreturns changes in the same write. - The write is atomic. It either succeeds completely or changes nothing.
- The response has the shape of Get medical consent and is read after the write.
medicalisnullafter a withdrawal.
Example
curl -X POST 'https://api.sandbox.ovok.com/v1/me/consent/medical' \
-H "Authorization: Bearer ${OVOK_TOKEN}" \
-H 'Content-Type: application/json' \
-d '{ "medicalSettingsNotificationsConsent": true }'
Successful response
201 — The resulting medical consent.
{
"medical": {
"consentId": "0199a1b2-c3d4-7e5f-8a9b-0c1d2e3f4a5b",
"acceptedAt": "2026-10-09T09:15:00.000Z"
}
}
| Field | Type | Description |
|---|---|---|
medical | object | null | The consent. null after a withdrawal. |
medical.consentId | string | Id of the Consent resource that holds the consent. |
medical.acceptedAt | string | null | When the consent was given. ISO 8601. |
Errors
| Status | Meaning |
|---|---|
400 | The FHIR server refused the consent write. |
401 | The bearer token is missing or invalid. |
403 | The session is not a practitioner session, has no project, or its access policy lacks one of the Consent interactions. |
409 | The write lost a conflict with a concurrent write. Retry. |
422 | medicalSettingsNotificationsConsent is missing or not a boolean. |
429 | Too many requests. |
503 | The access policy cannot be read for the moment. Retry shortly. |