Skip to main content

PRACTITIONER_INVITATION_ENABLED

Controls whether project admins can invite practitioners by email. Practitioners are invited to join your project; they set a password from the emailed link.

TypeBoolean setting
Change withPUT /v1/project/settings/PRACTITIONER_INVITATION_ENABLED
Who can change itProject admin
When unsetPractitioner invitations are on, although GET /v1/project/settings reports false
Set on new projectstrue for child projects created with POST /v1/slim/project/child; not set by any other project-creation route
NeedsA practitioner app URL; for some routes a default practitioner AccessPolicy
InheritedThe switch is not. The app URL can fall back to the parent project.

Turn practitioner invitations off​

curl --request PUT \
--url 'https://api.sandbox.ovok.com/v1/project/settings/PRACTITIONER_INVITATION_ENABLED' \
--header "Authorization: Bearer ${OVOK_TOKEN}" \
--header 'Content-Type: application/json' \
--data '{"enabled":false}'

Routes it covers​

Three routes add a practitioner to a project, and a fourth lets a patient share their record with one. They behave differently, so choose deliberately; the Invitations section explains when to use each.

RouteCallerAccess policy of the invited practitionerLink base
POST /v1/projects/me/membersProject adminThe default practitioner AccessPolicy, plus any access entries you send. Without access, none is named.PRACTITIONER_APP_URL, then parent, then older fallbacks, then the request Origin (if it is on the allowed-origins list), then the deployment default
POST /auth/invite with type PractitionerProject adminNone. The default practitioner AccessPolicy is not applied, so no policy limits the member.PRACTITIONER_APP_URL chain
POST /v1/slim/invite/practitionerA practitioner with permission to create practitionersThe accessPolicyId in the bodyThe request's Origin, else the deployment default. PRACTITIONER_APP_URL is not read.
POST /v1/invites/practitioner and /acceptA patient makes the offer; a practitioner acceptsThe default practitioner AccessPolicy for a new account, plus the patient's record as a share. This is not a colleague invitation.PRACTITIONER_APP_URL chain; the request Origin is never used

For access-controlled invitations, prefer POST /v1/projects/me/members with access entries.

What callers see when it is off​

RouteStatusMessage
POST /auth/invite403Invitation is not enabled for this project.
POST /v1/slim/invite/practitioner403Invitation is not enabled for this project.
POST /v1/projects/me/members403Practitioner invitations are disabled for this project.
POST /v1/invites/practitioner403Invitation is not enabled for this project.

Other responses you will meet​

ConditionStatusResponse
POST /auth/invite from a non-admin400Only admins can invite practitioners!
POST /auth/invite with a projectId other than the token's400As a member of your project, you cannot invite members to other projects!
/v1/projects/me/members for an existing member409A member with this email already exists on this project.
/v1/projects/me/members with access entries and no default practitioner AccessPolicy409error invitation_not_configured
No practitioner app URL resolves409code app_url_not_configured. Nothing is created.

Gotchas​

  • POST /auth/invite creates a practitioner with no AccessPolicy. It does not read DEFAULT_PRACTITIONER_ACCESS_POLICY. Use POST /v1/projects/me/members when the invited practitioner must be limited.
  • POST /v1/slim/invite/practitioner ignores PRACTITIONER_APP_URL. The link points at whatever app made the request. A call made from a server, with no Origin, falls back to the deployment default rather than your configured app.
  • Someone who can already sign in gets access, not an email. POST /v1/projects/me/members adds a membership for an existing account and sends no invitation; the response flags it with existingAccount.
  • GET shows false for a project that has never set it, but invitations work. Set the key to the value you intend.
  • The refusal wording differs by route. Match on the status code, not the text.
  • Error identifiers are not in one field. app_url_not_configured is in code; invitation_not_configured is in error.