---
title: Revoke sessions
sidebar_label: Revoke sessions
sidebar_position: 3
description: Sign the caller out of the current session, all other sessions, all sessions, or one session id with DELETE /auth/session/{option}.
---

# Revoke sessions

| Method | Path |
| --- | --- |
| `DELETE` | `/auth/session/:option` |

[Authentication](/authentication) · [Account routes](/authentication#account-routes)

Signs the caller out of one or more sessions. Use it for "sign out everywhere" and "sign out other devices" actions.

:::note
This is an account-level route. It has no `/auth/tenant/` variant. Use the access token that a [tenant sign-in](/authentication) returns.
:::

**Auth:** Bearer token of a patient or a practitioner.
**Scope:** The signed-in user's own sessions. A session id that is not one of the caller's sessions revokes nothing.

## Request

### Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `option` | `"current"` \| `"other"` \| `"all"` \| `string (uuid)` | Yes | Which sessions to revoke. `current` is the session of the token you call with. `other` is every session except the current one. `all` is every session, including the current one. A uuid is one session id from [List sessions](/authentication/account/list-sessions). |

No query parameters. No body.

## Behaviour

- Revoked sessions stop working: their access tokens are rejected from the next request on, and their refresh tokens can no longer renew them.
- `current` and `all` also end the token you called with. Sign in again afterwards.
- `current` and a session id revoke exactly that one session. `other` leaves the current session alone.
- A session id that is not one of your own sessions revokes nothing, but the answer is still `200` with `{ "revoked": true }` and no other field. Check the `id` in the answer to see that a session was matched.
- The response echoes the revoked sessions with `revoked: true`: one object for `current` or a session id, an array for `other` and `all`. `other` answers an empty array when there is no other session.
- To end only the access token you hold, without ending the session, use [Log out](/authentication/account/log-out). That leaves the refresh token usable.

## Example

```bash
curl -X DELETE 'https://api.sandbox.ovok.com/auth/session/other' \
  -H "Authorization: Bearer ${OVOK_TOKEN}"
```

## Successful response

`200` — The revoked sessions. For `other` and `all`, a JSON array:

```json
[
  {
    "id": "6b0d3f92-5a7c-4e18-b4d9-1c8a2e7f5d36",
    "lastUpdated": "2026-10-02T17:12:41.000Z",
    "authMethod": "password",
    "remoteAddress": "198.51.100.7",
    "browser": null,
    "os": null,
    "revoked": true
  }
]
```

For `current` or a session id, a single object with the same fields:

```json
{
  "id": "8c5e7a21-4b9d-4f36-a1c8-0d2e6b9f3a54",
  "lastUpdated": "2026-10-09T08:53:20.000Z",
  "authMethod": "password",
  "remoteAddress": "203.0.113.24",
  "browser": "Chrome",
  "os": "Mac OS",
  "revoked": true
}
```

| Field | Type | Description |
| --- | --- | --- |
| `id` | `string (uuid)` | Session id. Missing when `option` is a session id that is not yours. |
| `lastUpdated` | `string` | When the session was last used to sign in or refresh. ISO 8601. |
| `authMethod` | `string` | How the session was started. |
| `remoteAddress` | `string` | IP address the session was started from. |
| `browser` | `string \| null` | Browser name, when known. |
| `os` | `string \| null` | Operating system, when known. |
| `revoked` | `boolean` | Always `true`. |

## Errors

| Status | Meaning |
| --- | --- |
| `400` | The access token carries no session id, or the session's account could not be resolved. |
| `401` | The bearer token is missing, invalid, expired or revoked. |
| `422` | `option` is not `current`, `other`, `all` or a uuid. |
| `429` | Too many requests. |
