---
title: Give or withdraw the medical consent
sidebar_label: Give or withdraw the medical consent
sidebar_position: 11
description: Give or withdraw the medical settings notifications consent of the signed-in practitioner with POST /v1/me/consent/medical.
---

# Give or withdraw the medical consent

| Method | Path |
| --- | --- |
| `POST` | `/v1/me/consent/medical` |

[Authentication](/authentication) · [Account routes](/authentication#account-routes) · [Access policies](/access-policies)

Gives or withdraws the medical settings notifications consent for the signed-in practitioner and returns the resulting medical consent. Other consents are not changed.

:::note
This is an account-level route. It has no `/auth/tenant/` variant. Use the access token that a [tenant sign-in](/authentication) returns.
:::

**Auth:** Bearer token of a practitioner session (the profile must be a `Practitioner`). The caller's access policy must grant `Consent:read`, `Consent:search`, `Consent:create` and `Consent:update`. Project admins skip the access policy check.
**Scope:** The caller's practitioner profile in the project of the token.

## Request

### Body

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `medicalSettingsNotificationsConsent` | `boolean` | Yes | `true` gives the consent on the currently published version. `false` withdraws it. |

## Behaviour

- `true` records the consent on the currently published version. `false` withdraws it.
- Sending the current value again writes nothing.
- The value that [`GET /v1/slim/user/consents`](/slim-apis/user/get-all-user-consents) returns changes in the same write.
- The write is atomic. It either succeeds completely or changes nothing.
- The response has the shape of [Get medical consent](/authentication/account/get-medical-consent) and is read after the write. `medical` is `null` after a withdrawal.

## Example

```bash
curl -X POST 'https://api.sandbox.ovok.com/v1/me/consent/medical' \
  -H "Authorization: Bearer ${OVOK_TOKEN}" \
  -H 'Content-Type: application/json' \
  -d '{ "medicalSettingsNotificationsConsent": true }'
```

## Successful response

`201` — The resulting medical consent.

```json
{
  "medical": {
    "consentId": "0199a1b2-c3d4-7e5f-8a9b-0c1d2e3f4a5b",
    "acceptedAt": "2026-10-09T09:15:00.000Z"
  }
}
```

| Field | Type | Description |
| --- | --- | --- |
| `medical` | `object \| null` | The consent. `null` after a withdrawal. |
| `medical.consentId` | `string` | Id of the Consent resource that holds the consent. |
| `medical.acceptedAt` | `string \| null` | When the consent was given. ISO 8601. |

## Errors

| Status | Meaning |
| --- | --- |
| `400` | The FHIR server refused the consent write. |
| `401` | The bearer token is missing or invalid. |
| `403` | The session is not a practitioner session, has no project, or its access policy lacks one of the `Consent` interactions. |
| `409` | The write lost a conflict with a concurrent write. Retry. |
| `422` | `medicalSettingsNotificationsConsent` is missing or not a boolean. |
| `429` | Too many requests. |
| `503` | The access policy cannot be read for the moment. Retry shortly. |
