Skip to main content

Give or withdraw the medical consent

MethodPath
POST/v1/me/consent/medical

Authentication · Account routes · Access policies

Gives or withdraws the medical settings notifications consent for the signed-in practitioner and returns the resulting medical consent. Other consents are not changed.

note

This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns.

Auth: Bearer token of a practitioner session (the profile must be a Practitioner). The caller's access policy must grant Consent:read, Consent:search, Consent:create and Consent:update. Project admins skip the access policy check. Scope: The caller's practitioner profile in the project of the token.

Request​

Body​

NameTypeRequiredDescription
medicalSettingsNotificationsConsentbooleanYestrue gives the consent on the currently published version. false withdraws it.

Behaviour​

  • true records the consent on the currently published version. false withdraws it.
  • Sending the current value again writes nothing.
  • The value that GET /v1/slim/user/consents returns changes in the same write.
  • The write is atomic. It either succeeds completely or changes nothing.
  • The response has the shape of Get medical consent and is read after the write. medical is null after a withdrawal.

Example​

curl -X POST 'https://api.sandbox.ovok.com/v1/me/consent/medical' \
-H "Authorization: Bearer ${OVOK_TOKEN}" \
-H 'Content-Type: application/json' \
-d '{ "medicalSettingsNotificationsConsent": true }'

Successful response​

201 — The resulting medical consent.

{
"medical": {
"consentId": "0199a1b2-c3d4-7e5f-8a9b-0c1d2e3f4a5b",
"acceptedAt": "2026-10-09T09:15:00.000Z"
}
}
FieldTypeDescription
medicalobject | nullThe consent. null after a withdrawal.
medical.consentIdstringId of the Consent resource that holds the consent.
medical.acceptedAtstring | nullWhen the consent was given. ISO 8601.

Errors​

StatusMeaning
400The FHIR server refused the consent write.
401The bearer token is missing or invalid.
403The session is not a practitioner session, has no project, or its access policy lacks one of the Consent interactions.
409The write lost a conflict with a concurrent write. Retry.
422medicalSettingsNotificationsConsent is missing or not a boolean.
429Too many requests.
503The access policy cannot be read for the moment. Retry shortly.