---
title: Get medical consent
sidebar_label: Get medical consent
sidebar_position: 10
description: Read the signed-in practitioner's medical settings notifications consent with GET /v1/me/consent/medical, or null when it is not given.
---

# Get medical consent

| Method | Path |
| --- | --- |
| `GET` | `/v1/me/consent/medical` |

[Authentication](/authentication) · [Account routes](/authentication#account-routes) · [Access policies](/access-policies)

Returns the signed-in practitioner's medical settings notifications consent, or `null` when it is not given. Use it on app load to decide whether to show the medical notifications prompt.

:::note
This is an account-level route. It has no `/auth/tenant/` variant. Use the access token that a [tenant sign-in](/authentication) returns.
:::

**Auth:** Bearer token of a practitioner session (the profile must be a `Practitioner`). The caller's access policy must grant `Consent:read` and `Consent:search`. Project admins skip the access policy check.
**Scope:** The caller's practitioner profile in the project of the token.

## Request

No parameters.

## Behaviour

- `medical` is `null` when the practitioner never gave the consent or withdrew it.
- Only withdrawing ends it. Unlike [`GET /v1/slim/user/medical-settings-notifications-consent`](/slim-apis/user/get-medical-settings-notifications-consent), a newly published version does not turn it off here.
- `acceptedAt` is when the consent was given, or `null` when that is not recorded.
- Answers are cached for up to one day. A consent write by the practitioner refreshes them right away.
- To change the answer, use [Give or withdraw the medical consent](/authentication/account/update-medical-consent).

## Example

```bash
curl -X GET 'https://api.sandbox.ovok.com/v1/me/consent/medical' \
  -H "Authorization: Bearer ${OVOK_TOKEN}"
```

## Successful response

`200` — The medical consent.

```json
{
  "medical": {
    "consentId": "0199a1b2-c3d4-7e5f-8a9b-0c1d2e3f4a5b",
    "acceptedAt": "2026-09-02T07:30:00.000Z"
  }
}
```

| Field | Type | Description |
| --- | --- | --- |
| `medical` | `object \| null` | The consent. `null` when it is not given. |
| `medical.consentId` | `string` | Id of the Consent resource that holds the consent. |
| `medical.acceptedAt` | `string \| null` | When the consent was given. ISO 8601. |

## Errors

| Status | Meaning |
| --- | --- |
| `401` | The bearer token is missing or invalid. |
| `403` | The session is not a practitioner session, has no project, or its access policy lacks `Consent:read` or `Consent:search`. |
| `429` | Too many requests. |
| `503` | The access policy cannot be read for the moment. Retry shortly. |
