Skip to main content

Step 2: Create and configure the Ovok project

What we are building​

A sandbox project where a synthetic patient can authenticate, read only their own medication plan and adherence history, and create their own patient-reported adherence events.

What you should already have​

  • The Expo app from step 1.
  • Project owner or administrator access to the Ovok Console.
  • A synthetic patient account and synthetic medication data only.

The implementation​

Ovok Console configuration​

In the Console, create or select the sandbox project and record its tenant code. Use the sandbox API host from the app's .env file.

Configure only the project capabilities the tutorial uses:

  1. Enable patient sign-in and, only if patients will create their own test accounts, PATIENT_REGISTRATION_ENABLED. Self-registration also requires the project’s defaultPatientAccessPolicy; configure it in the Console. There is no project-settings key for this field, and registration fails until it exists. If a project administrator provisions the synthetic patient, leave self-registration off.
  2. Configure an AccessPolicy for the patient workflow. It must scope access to the authenticated Patient and permit the specific interactions this tutorial uses: read/search MedicationRequest, read/search MedicationAdministration, and create MedicationAdministration. Assign it as the default patient policy only if new patients should receive it. Do not grant broad project-wide access just to make a tutorial request succeed. Test the policy with a patient account, not an administrator account.
  3. Confirm the live CapabilityStatement advertises MedicationAdministration conditional create. Step 8 writes one resource per request, so it does not need the all-or-nothing transaction-bundles feature. If you later group multiple clinical writes into one transaction, enable and verify that feature first.
  4. Enable the CMS for the project and publish the tutorial's translations groups to the sandbox environment used by the app. The CMS/i18n guide explains the collection and publication flow.
  5. Patient self-registration does not require a custom email template. If the product should send a welcome message, map the PATIENT_WELCOME template; configure invitation or password-reset templates only when those flows are enabled. See the authentication setup guide and email template docs.

The medication resources are standard FHIR resources. There is no medication-specific feature switch in this tutorial. Check the project's live CapabilityStatement for resource interactions and search parameters; API availability does not grant a patient permission to use them.

Mobile application configuration​

Put the sandbox host and tenant code in the public Expo configuration created in step 1. Do not embed an administrator account, API key, or privileged token in the app. The application signs in as the patient and uses that patient's access policy for all resource requests.

The tutorial uses email/password sign-in. It does not configure social login, OAuth callbacks, or app links. Add deep links only if you introduce a verified email or password-reset link flow and follow the corresponding authentication documentation.

Important Ovok decisions​

  • The patient app reads an existing plan; it must not let a patient create or alter a prescription. A project administrator or authorised clinical workflow creates the synthetic MedicationRequest used in the sandbox exercise.
  • The AccessPolicy is the security boundary. Filtering a resource list in React Native is not authorization.
  • No migration is required. The app reads FHIR resources directly and does not install a medication schema or custom profile.

Expected result​

You have a sandbox tenant code, a patient-only account, a tested AccessPolicy, and the CMS ready for published translation strings.

Common errors and troubleshooting​

  • The endpoint is in the CapabilityStatement but returns 403: the authenticated patient AccessPolicy does not allow that resource interaction or scope. Do not switch to a privileged token in the client.
  • A conditional create is rejected: check the resource's CapabilityStatement interactions and the conditional-create query in the Bundle entry.
  • Patient registration is disabled: use an already provisioned synthetic patient or enable the registration setting for this sandbox project only.
  • CMS strings are missing: verify the tenant code, locale, publication state, and environment match the app configuration.

Previous / Next​

Previous: step 1: create the React Native app · Continue to step 3: model the medication plan.