Skip to main content

PATIENT_LOGIN_ENABLED

Controls whether patients can sign in to the project. Turn it off to pause patient sign-in while practitioners keep working.

TypeBoolean setting
Change withPUT /v1/project/settings/PATIENT_LOGIN_ENABLED
Who can change itProject admin
When unsetPatient sign-in is on, although GET /v1/project/settings reports false
Set on new projectsfalse for child projects created with POST /v1/slim/project/child; not set by any other project-creation route
InheritedNo. A child project reads only its own value.

Turn patient sign-in off​

curl --request PUT \
--url 'https://api.sandbox.ovok.com/v1/project/settings/PATIENT_LOGIN_ENABLED' \
--header "Authorization: Bearer ${OVOK_TOKEN}" \
--header 'Content-Type: application/json' \
--data '{"enabled":false}'

The response is the full settings record. The change applies to the next request; there is no cache to wait for.

Which sign-in this applies to​

Tenant sign-in (/auth/tenant/Patient/...) is the current way to sign in to an Ovok project. Every project has a tenant code, which names the project in the request. The older routes in the table below still work and are listed because the switch covers them too: POST /auth/login, TAN sign-in, /auth/external/* and /auth/signup are marked deprecated, and POST /v2/auth/login is the older client-ID sign-in that the platform's own code says to replace with tenant sign-in.

Where the switch applies​

Sign-in pathChecked today?
POST /auth/tenant/Patient/login/startYes
POST /v2/auth/login and the deprecated POST /auth/loginYes
POST /auth/signup with resourceType Patient and a password (the automatic sign-in after sign-up)Yes, but see the sign-up gotcha
POST /auth/tenant/Patient/login/mfa and login/tokenNo
TAN sign-in (POST /auth/login/tan, /auth/tan-login/:tan)No
Google and Apple sign-in (POST /auth/external/google, /auth/external/apple)No
Token refresh (POST /auth/refresh-token, /oauth2/token)No
POST /auth/tenant/Patient/register (returns tokens on success)No

The switch is being extended to the remaining paths. Treat the table as the contract for your current release and test the paths your app uses.

What callers see when it is off​

RouteStatusMessage
POST /auth/tenant/Patient/login/start403Login is not enabled.
POST /v2/auth/login403Login is not enabled for this project.
POST /auth/signup (patient, with password)400Login is not enabled for this project.

On the tenant route, an unknown tenant code answers 404 Tenant not found. before the switch is checked.

Gotchas​

  • Turning it off does not end sessions. A patient who is already signed in keeps working, and can keep refreshing, until their session ends. An access token lasts up to 60 minutes. To end a session, revoke it with DELETE /auth/session/:id or POST /auth/logout.
  • A session code issued before the switch changed still works. A code from login/start can be redeemed at login/token after you turn the switch off.
  • GET shows false for a project that has never set it, but patients can sign in. Set the key to the value you intend rather than relying on the default. See Unset settings.
  • Projects created with POST /v1/slim/project/child start with patient sign-in off. Turn it on before you launch a patient app.
  • Sign-up can create the account and still answer 400. POST /auth/signup creates the patient, then signs them in. With the switch off, the account exists but the call returns 400 Login is not enabled for this project.
  • A failed read looks like "off". If the project cannot be read for a moment, the check fails closed and callers see the same 403 as when the switch is off.
  • Rate limit. login/start allows 10 requests per minute per client address; over that returns 429.
  • Registration is separate. A patient who registers through POST /auth/tenant/Patient/register receives tokens even when this switch is off. Use PATIENT_REGISTRATION_ENABLED to stop registration.