Ovok platform resource types
The inspected sandbox schema includes these 16 non-FHIR platform types in addition to the 146 FHIR R4 resources. Their presence in introspection describes the schema; it does not make them application data models or grant access. Use FHIR resources for clinical data, and use the Console and linked platform references for project configuration and account workflows.
For each type, the table lists the read-by-ID field, list field, connection field, resource-specific list arguments, and available CRUD mutations. Shared list arguments are documented in queries and pagination.
| Ovok type | Read, list, connection fields | Resource-specific list arguments | Mutations |
|---|---|---|---|
AccessPolicy | AccessPolicy(id: ID!)AccessPolicyListAccessPolicyConnection | name | AccessPolicyCreateAccessPolicyUpdateAccessPolicyPatchAccessPolicyDelete |
Agent | Agent(id: ID!)AgentListAgentConnection | identifier, name, status | AgentCreateAgentUpdateAgentPatchAgentDelete |
AsyncJob | AsyncJob(id: ID!)AsyncJobListAsyncJobConnection | type, status | AsyncJobCreateAsyncJobUpdateAsyncJobPatchAsyncJobDelete |
Bot | Bot(id: ID!)BotListBotConnection | identifier, name, category, cds_hook | BotCreateBotUpdateBotPatchBotDelete |
BulkDataExport | BulkDataExport(id: ID!)BulkDataExportListBulkDataExportConnection | status | BulkDataExportCreateBulkDataExportUpdateBulkDataExportPatchBulkDataExportDelete |
ClientApplication | ClientApplication(id: ID!)ClientApplicationListClientApplicationConnection | name | ClientApplicationCreateClientApplicationUpdateClientApplicationPatchClientApplicationDelete |
DomainConfiguration | DomainConfiguration(id: ID!)DomainConfigurationListDomainConfigurationConnection | domain | DomainConfigurationCreateDomainConfigurationUpdateDomainConfigurationPatchDomainConfigurationDelete |
JsonWebKey | JsonWebKey(id: ID!)JsonWebKeyListJsonWebKeyConnection | active | JsonWebKeyCreateJsonWebKeyUpdateJsonWebKeyPatchJsonWebKeyDelete |
Login | Login(id: ID!)LoginListLoginConnection | user, code, cookie | LoginCreateLoginUpdateLoginPatchLoginDelete |
Project | Project(id: ID!)ProjectListProjectConnection | identifier, name, owner, google_client_id, recaptcha_site_key | ProjectCreateProjectUpdateProjectPatchProjectDelete |
ProjectMembership | ProjectMembership(id: ID!)ProjectMembershipListProjectMembershipConnection | project, user, profile, profile_type, user_name, external_id, access_policy, identifier, active | ProjectMembershipCreateProjectMembershipUpdateProjectMembershipPatchProjectMembershipDelete |
SmartAppLaunch | SmartAppLaunch(id: ID!)SmartAppLaunchListSmartAppLaunchConnection | — | SmartAppLaunchCreateSmartAppLaunchUpdateSmartAppLaunchPatchSmartAppLaunchDelete |
SubscriptionStatus | SubscriptionStatus(id: ID!)SubscriptionStatusListSubscriptionStatusConnection | — | SubscriptionStatusCreateSubscriptionStatusUpdateSubscriptionStatusPatchSubscriptionStatusDelete |
User | User(id: ID!)UserListUserConnection | identifier, email, external_id, project | UserCreateUserUpdateUserPatchUserDelete |
UserConfiguration | UserConfiguration(id: ID!)UserConfigurationListUserConfigurationConnection | name | UserConfigurationCreateUserConfigurationUpdateUserConfigurationPatchUserConfigurationDelete |
UserSecurityRequest | UserSecurityRequest(id: ID!)UserSecurityRequestListUserSecurityRequestConnection | user | UserSecurityRequestCreateUserSecurityRequestUpdateUserSecurityRequestPatchUserSecurityRequestDelete |
Security-sensitive fields
Some platform object types can contain authentication, credential, key, or user-security data. Introspection reveals field names, not authorization. Do not select, return, or log secrets, password material, MFA data, tokens, or private key material from a general application. Use the documented Authentication, Access policies, and Settings and features flows instead.