---
title: Log out
sidebar_label: Log out
sidebar_position: 5
description: End an access token on the server with POST /v1/auth/logout so it stops working before it expires.
---

# Log out

| Method | Path |
| --- | --- |
| `POST` | `/v1/auth/logout` |

[Authentication](/authentication) · [Account routes](/authentication#account-routes)

Signs the caller out on the server. The access token in the `Authorization` header stops working for every authenticated route, although it has not expired.

:::note
This is an account-level route. It has no `/auth/tenant/` variant. Use the access token that a [tenant sign-in](/authentication) returns. The same route also answers at `/auth/logout`, without `/v1`.
:::

**Auth:** Bearer token of a patient or a practitioner. A missing or invalid token gives `401`.
**Scope:** The access token you call with.

## Request

No parameters. No body.

## Behaviour

- Only this access token is ended. The session and its refresh token are not touched, so the refresh token can still [renew](/authentication/account/refresh-token) the session. To end the session itself, use [Revoke sessions](/authentication/account/revoke-sessions) with `current`.
- The token is rejected for the rest of its lifetime. A token that has already expired is ignored.
- Repeating the call with the same token answers `401`, because the token no longer works.
- If revocation cannot be stored on the server, the call still answers `204` and the token stays valid until it expires. Clear the local session as well.
- The response has no body.

## Example

```bash
curl -X POST 'https://api.sandbox.ovok.com/v1/auth/logout' \
  -H "Authorization: Bearer ${OVOK_TOKEN}"
```

## Successful response

`204` — No content. The access token no longer works.

## Errors

| Status | Meaning |
| --- | --- |
| `401` | The bearer token is missing, invalid, expired or already revoked. |
| `429` | Too many requests. |
