---
title: Connect rpm-ehr-example-app to an Ovok sandbox
sidebar_label: Connect a sandbox
description: Configure the EHR example for an authorized Ovok sandbox project and Practitioner account.
---

# Connect rpm-ehr-example-app to an Ovok sandbox

Use sandbox mode after a project administrator has prepared a sandbox project, an authorized Practitioner account, and least-privilege AccessPolicies. The app uses `@ovok/core` against the FHIR R4 API; each request is still authorized by Ovok.

## Prepare the project

1. Create an Ovok account and a sandbox project in the [Ovok Console](https://ovok.com/console). For project setup, see [Create and configure a project](/authentication/project-setup).
2. Enable Practitioner sign-in and configure an AccessPolicy for only the FHIR reads and writes the example needs. Review [Practitioner login](/authentication/practitioner-login) and [Access Policies](/access-policies).
3. If you will try patient registration, configure patient invitations, patient sharing, the patient application URL, and the required policies. Follow [Invite a patient](/invitations/invite-a-patient).

The tenant code identifies a project; it does not authorize requests or replace an AccessPolicy.

## Set public app configuration

From the standalone repository root, create a local environment file:

```sh
cp .env.example .env.local
```

Set the sandbox API origin and the tenant code for your project:

```dotenv
VITE_OVOK_API_BASE_URL=https://api.sandbox.ovok.com
VITE_OVOK_TENANT_CODE=your-sandbox-tenant-code
```

These `VITE_` values are bundled into browser code. Do not put a ClientApplication secret, service credential, access token, password, or patient information in them. Restart Vite after changing configuration.

## Sign in and verify access

Open the EHR, choose **Connect sandbox**, and sign in with your own Practitioner account. The SDK may request an authenticator code. Search results and chart records are limited to what the signed-in Practitioner may access. A UI assignment or Patient ID link does not grant access.

If a patient registration succeeds but the later invitation request fails, the Patient record may already exist: those are separate, non-atomic requests. The invitation response means only that the request was accepted for sending; it does not confirm delivery or patient acceptance. Do not retry Patient creation without checking the project first.

Continue to the [FHIR workflow walkthrough](/example-rpm-app/ehr/clinic-workflow) for the records this example reads and writes. For the resource contract, see the [FHIR R4 documentation](/api/fhir/r4).
