---
title: List sessions
sidebar_label: List sessions
sidebar_position: 2
description: List the signed-in user's sessions with GET /auth/session to build a "where you are signed in" screen.
---

# List sessions

| Method | Path |
| --- | --- |
| `GET` | `/auth/session` |

[Authentication](/authentication) · [Account routes](/authentication#account-routes)

Lists the caller's sessions, one per sign-in. Use it to build a "where you are signed in" screen, and to find the session id to pass to [Revoke sessions](/authentication/account/revoke-sessions).

:::note
This is an account-level route. It has no `/auth/tenant/` variant. Use the access token that a [tenant sign-in](/authentication) returns.
:::

**Auth:** Bearer token of a patient or a practitioner.
**Scope:** The signed-in user's own sessions.

## Request

No parameters.

## Behaviour

- A session is listed when it belongs to the user, has a project membership and is not revoked. A session that has been idle for a long time is listed as long as it is not revoked.
- The list is ordered newest first, by the time each session was last used to sign in or refresh.
- Nothing in the list marks the current session. Its `id` is the `login_id` claim of your access token.
- `browser` and `os` are `null` for sessions that the FHIR server has not reported them for, such as sessions idle for an hour or more.
- The call only reads. It does not change any session.

## Example

```bash
curl -X GET 'https://api.sandbox.ovok.com/auth/session' \
  -H "Authorization: Bearer ${OVOK_TOKEN}"
```

## Successful response

`200` — A JSON array with one object per session.

```json
[
  {
    "id": "8c5e7a21-4b9d-4f36-a1c8-0d2e6b9f3a54",
    "lastUpdated": "2026-10-09T08:53:20.000Z",
    "authMethod": "password",
    "remoteAddress": "203.0.113.24",
    "browser": "Chrome",
    "os": "Mac OS"
  },
  {
    "id": "6b0d3f92-5a7c-4e18-b4d9-1c8a2e7f5d36",
    "lastUpdated": "2026-10-02T17:12:41.000Z",
    "authMethod": "password",
    "remoteAddress": "198.51.100.7",
    "browser": null,
    "os": null
  }
]
```

| Field | Type | Description |
| --- | --- | --- |
| `[].id` | `string (uuid)` | Session id. Pass it to `DELETE /auth/session/:option` to revoke this session. |
| `[].lastUpdated` | `string` | When the session was last used to sign in or refresh. ISO 8601. |
| `[].authMethod` | `string` | How the session was started, for example `password`. |
| `[].remoteAddress` | `string` | IP address the session was started from. |
| `[].browser` | `string \| null` | Browser name, when known. |
| `[].os` | `string \| null` | Operating system, when known. |

## Errors

| Status | Meaning |
| --- | --- |
| `400` | The access token carries no session id, or the session's account could not be resolved. |
| `401` | The bearer token is missing, invalid, expired or revoked. |
| `429` | Too many requests. |
