Skip to main content

Step 2: Create and configure the Ovok project

What we are building​

A sandbox project that can register and authenticate test Patients, read the approved Questionnaire, save their QuestionnaireResponses, and save blood-glucose Observations.

What you should already have​

  • The Expo project from step 1.
  • Access to the Ovok Console and permission to configure a sandbox project.
  • The approved, licensed FINDRISC Questionnaire resource and its reviewed canonical URL and version.

The implementation​

Configure the project in Ovok Console​

  1. Create or select a sandbox project. Use synthetic patient records and test accounts only.
  2. Record the tenant code and the server-assigned ID, canonical URL, and version of the approved FHIR Questionnaire published in this project. The URL and version must match the instrument approval record.
  3. Ensure PATIENT_LOGIN_ENABLED is not false. Enable PATIENT_REGISTRATION_ENABLED only if the tutorial app will create its own test accounts. Patient self-registration also needs a default Patient AccessPolicy. See patient login, patient registration, and project setup.
  4. Configure a least-privilege default Patient AccessPolicy. It should allow a Patient to access only the Patient’s own profile, the approved Questionnaire, that Patient’s QuestionnaireResponses, and the relevant blood-glucose Observations required by the app. Follow the policy guidance for patient scoping; do not copy a broad example policy into a production project.
  5. Verify in the project’s FHIR R4 CapabilityStatement that Questionnaire, QuestionnaireResponse, and Observation support the interactions this app uses. The current sandbox statement advertises these resources and the Questionnaire operations; a project’s access policy still determines what a signed-in Patient can do.
  6. transaction-bundles is not needed for the basic form submission or single measurement write shown here. Enable it only if the approved Questionnaire uses the standard Observation extraction workflow, which writes the response and extracted Observations atomically. New projects may already have this feature; check Transaction bundles rather than assuming.
  7. A welcome email is optional for the email/password sample. If your account flow sends one, configure a real mapped template and a ready email provider using the template catalogue. This guide does not prescribe a template name or send email itself.
  8. Enable Ovok CMS. Step 3 stores app-owned user interface strings in the translations collection and publishes them to the sandbox staging environment.

Configure the application​

Copy the project tenant code and reviewed Questionnaire identifiers into the local environment file created in step 1:

EXPO_PUBLIC_OVOK_BASE_URL=https://api.sandbox.ovok.com
EXPO_PUBLIC_TENANT_CODE=your-sandbox-tenant-code
EXPO_PUBLIC_FINDRISC_QUESTIONNAIRE_ID=server-assigned-questionnaire-id
EXPO_PUBLIC_FINDRISC_QUESTIONNAIRE_URL=https://example.org/your-approved-questionnaire
EXPO_PUBLIC_FINDRISC_QUESTIONNAIRE_VERSION=reviewed-questionnaire-version

The example canonical URL above is a placeholder. Replace it with the value on your approved Questionnaire. Do not use a demo URL as the actual canonical identifier.

Create src/config/ovok.ts:

const baseUrl =
process.env.EXPO_PUBLIC_OVOK_BASE_URL ?? "https://api.sandbox.ovok.com";
const tenantCode = process.env.EXPO_PUBLIC_TENANT_CODE;
const questionnaireId = process.env.EXPO_PUBLIC_FINDRISC_QUESTIONNAIRE_ID;
const questionnaireUrl = process.env.EXPO_PUBLIC_FINDRISC_QUESTIONNAIRE_URL;
const questionnaireVersion =
process.env.EXPO_PUBLIC_FINDRISC_QUESTIONNAIRE_VERSION;

if (!tenantCode || !questionnaireId || !questionnaireUrl || !questionnaireVersion) {
throw new Error("Set the sandbox tenant and reviewed Questionnaire identifiers.");
}

export const ovokConfig = {
baseUrl,
tenantCode,
questionnaireId,
questionnaireUrl,
questionnaireVersion,
};

This configuration belongs in the app. The patient AccessPolicy, patient login/registration settings, resource publication, and CMS content belong in Ovok Console.

Important Ovok decisions​

  • Do not create a duplicate Patient after registration. The supported Patient registration flow creates the account and profile.
  • AccessPolicy is the authorization boundary. Hiding a screen in React Native is not permission enforcement.
  • Do not require a glucose reading to take FINDRISC. These are separate workflows and data sources.
  • No server-side FINDRISC scoring operation appears in the current CapabilityStatement or SDK surface. Step 5 implements a reviewed local score map and keeps the QuestionnaireResponse as the saved source record.
  • $populate is useful only for valid FHIR-derived prefill configured for the approved Questionnaire. Never infer lifestyle answers from unrelated demographics. $extract is optional and applies only where the Questionnaire is explicitly configured for supported structured extraction.

Expected result​

The sandbox project can authenticate test Patients and its AccessPolicy permits the app’s approved Questionnaire and self-scoped records. The app has the correct sandbox tenant and reviewed Questionnaire identifiers locally.

Common errors and troubleshooting​

  • Registration is refused: confirm patient registration is enabled and the project has a default Patient AccessPolicy.
  • FHIR calls return forbidden: check the project AccessPolicy and Patient scope; do not solve this by granting access to every Patient.
  • The Questionnaire loads from another project: confirm the API origin, tenant code, and resource ID all belong to the same sandbox project.
  • Extraction fails: check whether the Questionnaire uses the supported standard extraction configuration and whether transaction-bundles is enabled.
  • The questionnaire version is unexpected: stop scoring, confirm the approved resource was published, and compare its canonical URL and version with the project’s reviewed values.

Previous / Next​

Previous: create the React Native app · Next: configure localisation