---
title: Get account information
sidebar_label: Get account information
sidebar_position: 1
description: Read who an access token belongs to with GET /auth/me, including the project, profile, access policy and sessions.
---

# Get account information

| Method | Path |
| --- | --- |
| `GET` | `/auth/me` |

[Authentication](/authentication) · [Account routes](/authentication#account-routes) · [Access policies](/access-policies)

Returns the signed-in user's context: account, project, membership, profile, access policy and security details such as the second-factor status and sessions. Call it after sign-in to learn who the token belongs to.

:::note
This is an account-level route. It has no `/auth/tenant/` variant. Use the access token that a [tenant sign-in](/authentication) returns.
:::

**Auth:** Bearer token of a patient or a practitioner. A missing, non-bearer, invalid, expired or revoked token gives `401`.
**Scope:** The project of the token.

## Request

No parameters.

## Behaviour

- The answer is the FHIR server's own `auth/me` document for the session of the token.
- Every call discards the cached copy of this user's profile and reads a fresh one. A change to the profile or the access policy shows up in this response and in later requests with the same token.
- Use `profile.resourceType` to tell patients from practitioners. A client application token answers with `ClientApplication`.
- `security.sessions` lists only recently active sessions and at most 20 of them. A session that has been idle for an hour is missing from it. Use [List sessions](/authentication/account/list-sessions) for the complete list.
- Only a bearer token is accepted. Basic credentials give `401`.

## Example

```bash
curl -X GET 'https://api.sandbox.ovok.com/auth/me' \
  -H "Authorization: Bearer ${OVOK_TOKEN}"
```

## Successful response

`200` — The user's context. The example is trimmed.

```json
{
  "user": {
    "resourceType": "User",
    "id": "9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
    "email": "alex@example.com"
  },
  "project": {
    "resourceType": "Project",
    "id": "1e6b8d30-2c4f-4a95-8d7e-b0a2c4e6f918",
    "name": "Example Project"
  },
  "membership": {
    "resourceType": "ProjectMembership",
    "id": "5d2a9c64-7e1b-4830-b6f5-9a3c1e8d7b02",
    "user": {
      "reference": "User/9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
      "display": "alex@example.com"
    },
    "profile": {
      "reference": "Patient/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21",
      "display": "Alex Example"
    }
  },
  "profile": {
    "resourceType": "Patient",
    "id": "3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21",
    "name": [{ "given": ["Alex"], "family": "Example" }],
    "telecom": [{ "system": "email", "use": "work", "value": "alex@example.com" }]
  },
  "config": {
    "resourceType": "UserConfiguration",
    "menu": [{ "title": "Favorites", "link": [] }]
  },
  "accessPolicy": {
    "resourceType": "AccessPolicy",
    "resource": [{ "resourceType": "Patient" }]
  },
  "security": {
    "mfaEnrolled": false,
    "sessions": [
      {
        "id": "8c5e7a21-4b9d-4f36-a1c8-0d2e6b9f3a54",
        "lastUpdated": "2026-10-09T08:53:20.000Z",
        "authMethod": "password",
        "remoteAddress": "203.0.113.24",
        "browser": "Chrome",
        "os": "Mac OS"
      }
    ]
  }
}
```

The body is a FHIR-style document, not a single resource. Other fields of the FHIR server's `auth/me` answer can be present.

| Field | Type | Description |
| --- | --- | --- |
| `user` | `object` | The User resource of the account. |
| `user.id` | `string (uuid)` | User id. |
| `user.email` | `string` | Sign-in email address. |
| `project` | `object` | The Project the token is for. |
| `project.id` | `string (uuid)` | Project id. |
| `project.name` | `string` | Project name. |
| `membership` | `object` | The ProjectMembership that ties the user to the project. |
| `membership.id` | `string (uuid)` | Membership id. |
| `membership.user` | `object` | Reference to the User, with `reference` and `display`. |
| `membership.profile` | `object` | Reference to the Patient or Practitioner, with `reference` and `display`. |
| `profile` | `object` | The signed-in Patient or Practitioner. For a client application token it is the ClientApplication. |
| `profile.resourceType` | `"Patient"` \| `"Practitioner"` \| `"ClientApplication"` | Kind of profile. |
| `profile.id` | `string (uuid)` | Profile id. |
| `profile.name` | `object[]` | The profile's names, as on the FHIR resource. |
| `profile.telecom` | `object[]` | The profile's contact points, as on the FHIR resource. |
| `config` | `object` | The user's UserConfiguration, for example the app menu. |
| `accessPolicy` | `object` | The AccessPolicy that applies to the membership. Left out when the membership has none. |
| `security.mfaEnrolled` | `boolean` | Whether the user has enrolled a second factor. |
| `security.sessions` | `object[]` | Recently active sessions, in no guaranteed order. At most 20. |
| `security.sessions[].id` | `string (uuid)` | Session id. |
| `security.sessions[].lastUpdated` | `string` | When the session was last used to sign in or refresh. ISO 8601. |
| `security.sessions[].authMethod` | `string` | How the session was started, for example `password`. |
| `security.sessions[].remoteAddress` | `string` | IP address the session was started from. |
| `security.sessions[].browser` | `string` | Browser name, when known. |
| `security.sessions[].os` | `string` | Operating system, when known. |

## Errors

| Status | Meaning |
| --- | --- |
| `400` | The access token carries no session id, so it is not a user session token. |
| `401` | The bearer token is missing, not a bearer token, invalid, expired or revoked. |
| `429` | Too many requests. |
