PRACTITIONER_APP_URL
The root address of your practitioner dashboard. Ovok builds the links in practitioner emails on it: accept an invitation, set a password, reset a password.
| Type | Text setting |
| Change with | PUT /v1/project/settings/values/PRACTITIONER_APP_URL |
| Value | An https URL, or an app deep link such as myapp://. null removes it. |
| Who can change it | Project admin |
| When unset | Falls back to the parent project, an older setting, the request's Origin (for some routes) and the platform default, in that order. Routes that cannot fall back answer 409. |
| Set on new projects | Not set by any project-creation route |
| Inherited | Yes, from the direct parent project, at send time. GET does not show the inherited value. |
Set it
curl --request PUT \
--url 'https://api.sandbox.ovok.com/v1/project/settings/values/PRACTITIONER_APP_URL' \
--header "Authorization: Bearer ${OVOK_TOKEN}" \
--header 'Content-Type: application/json' \
--data '{"value":"https://dashboard.example.com"}'
Ovok stores the canonical form (no trailing slash, lowercase host), so https://dashboard.example.com/ is stored as https://dashboard.example.com. The same rules, errors and gotchas as PATIENT_APP_URL apply to the value you send.
What the link looks like
| Flow | Link |
|---|---|
| Practitioner invitation, password reset | <app URL>/setpassword/<id>/<secret> |
| Invitation for someone who already has an account | <app URL>/accept-invite?invite=<id>&code=<code> |
With https://dashboard.example.com the invitation link is https://dashboard.example.com/setpassword/<id>/<secret>. With myapp:// it is myapp:///setpassword/<id>/<secret>.
How the address is chosen
For a practitioner link, Ovok takes the first of these that exists:
PRACTITIONER_APP_URLon the project.PRACTITIONER_APP_URLon the parent project.- The older
CLINICIAN_DASHBOARD_URLon the project, then on the parent. - The
Originof the request, only for the flows below that allow it, and only if that origin is on the platform's allowed-origins list and is not the API's own host. - The platform default, if your environment has one.
Which routes use it
| Route | Uses PRACTITIONER_APP_URL? | Uses the request Origin? |
|---|---|---|
POST /v1/projects/me/members | Yes | Yes |
POST /auth/invite with type Practitioner | Yes | No |
POST /v1/invites/practitioner and /accept | Yes | No |
| Business-email sign-up (see CLINICIAN_INVITE_ON_BUSINESS_EMAIL) | Yes | No |
POST /v2/auth/reset-password | Yes, for a practitioner who belongs to one project | Yes |
POST /v1/saas/register | No: uses the platform address | Yes |
POST /v1/slim/invite/practitioner | No | Yes, otherwise the platform default |
What callers see when nothing resolves
| Route | Result |
|---|---|
POST /auth/invite, POST /v1/projects/me/members, POST /v1/invites/practitioner | 409 with code app_url_not_configured. Nothing is created. |
POST /v1/saas/register | 409, before anything is written |
POST /v2/auth/reset-password | The call succeeds; the email can go out without a usable link. |
Gotchas
POST /v1/slim/invite/practitionerignores this setting. Its link points at the app that made the request, or the platform default when the request has noOrigin. A call from your server therefore does not produce a link to your dashboard. PreferPOST /v1/projects/me/membersif you need the configured address.- A practitioner in several projects gets the platform address for password resets, never one project's URL, because no single project's admins may choose where that link goes.
- The
Originfallback is for convenience in browser apps. It is never used for a link sent to a different audience, and it is ignored unless the origin is on the allowed list. Do not depend on it in production; set the URL. GETshows only this project's stored value. An inherited URL appears asnull.- Password resets never fail on a missing URL. Set the address before you rely on resets.
- You edit only your own project. A parent admin cannot set a child's URL.