PRACTITIONER_LOGIN_ENABLED
Controls whether practitioners can sign in to the project. Turn it off to pause clinician access, for example during a migration or an incident.
| Type | Boolean setting |
| Change with | PUT /v1/project/settings/PRACTITIONER_LOGIN_ENABLED |
| Who can change it | Project admin |
| When unset | Practitioner sign-in is on, although GET /v1/project/settings reports false |
| Set on new projects | true for child projects created with POST /v1/slim/project/child; not set by any other project-creation route |
| Inherited | No. A child project reads only its own value. |
Turn practitioner sign-in off
curl --request PUT \
--url 'https://api.sandbox.ovok.com/v1/project/settings/PRACTITIONER_LOGIN_ENABLED' \
--header "Authorization: Bearer ${OVOK_TOKEN}" \
--header 'Content-Type: application/json' \
--data '{"enabled":false}'
Project admins are not exempt. If you turn practitioner sign-in off and your own session ends, you cannot sign back in to turn it on again. Keep a signed-in admin session open until you have confirmed the change.
Which sign-in this applies to
Tenant sign-in (/auth/tenant/Practitioner/...) is the current way to sign in to an Ovok project. Every project has a tenant code, which names the project in the request. The older routes in the table below still work and are listed because the switch covers them too: POST /auth/login, TAN sign-in, /auth/external/* and /auth/signup are marked deprecated, and POST /v2/auth/login is the older client-ID sign-in that the platform's own code says to replace with tenant sign-in.
Where the switch applies
| Sign-in path | Checked today? |
|---|---|
POST /auth/tenant/Practitioner/login/token | Yes |
POST /v2/auth/login and the deprecated POST /auth/login | Yes |
POST /auth/tenant/Practitioner/login/start and login/mfa | No |
| TAN sign-in | No |
Token refresh (POST /auth/refresh-token, /oauth2/token) | No |
POST /auth/tenant/Practitioner/register (returns tokens on success) | No |
The switch is being extended to the remaining paths. Treat the table as the contract for your current release and test the paths your app uses.
What callers see when it is off
| Route | Status | Message |
|---|---|---|
POST /auth/tenant/Practitioner/login/token | 403 | Login is not enabled for this project. |
POST /v2/auth/login | 403 | Login is not enabled for this project. |
On the tenant route the check runs before the session code is used, so a refused request does not consume the code. An unknown tenant code answers 404 first.
Gotchas
- The refusal arrives late in the two-step flow.
login/startandlogin/mfastill verify the password and the second factor, and the response can list the project among the user's profiles. The user only learns that sign-in is off atlogin/token. Build your sign-in screen to handle a403at that step. - Turning it off does not end sessions. Signed-in practitioners keep working and can keep refreshing. An access token lasts up to 60 minutes. Revoke a session with
DELETE /auth/session/:idorPOST /auth/logout. GETshowsfalsefor a project that has never set it, but practitioners can sign in. Set the key to the value you intend. See Unset settings.- Registration and invitations are separate. A practitioner who registers through
POST /auth/tenant/Practitioner/registerreceives tokens even when this switch is off. - A failed read looks like "off". If the project cannot be read for a moment, callers see the same
403as when the switch is off. - Rate limits.
login/tokenallows 30 requests per minute per client address,login/mfa5, andlogin/start10.
Related
- Practitioner sign-in, the flow this switch controls
- PATIENT_LOGIN_ENABLED
- PRACTITIONER_REGISTRATION_ENABLED
- PRACTITIONER_INVITATION_ENABLED