Skip to main content

PRACTITIONER_LOGIN_ENABLED

Controls whether practitioners can sign in to the project. Turn it off to pause clinician access, for example during a migration or an incident.

TypeBoolean setting
Change withPUT /v1/project/settings/PRACTITIONER_LOGIN_ENABLED
Who can change itProject admin
When unsetPractitioner sign-in is on, although GET /v1/project/settings reports false
Set on new projectstrue for child projects created with POST /v1/slim/project/child; not set by any other project-creation route
InheritedNo. A child project reads only its own value.

Turn practitioner sign-in off​

curl --request PUT \
--url 'https://api.sandbox.ovok.com/v1/project/settings/PRACTITIONER_LOGIN_ENABLED' \
--header "Authorization: Bearer ${OVOK_TOKEN}" \
--header 'Content-Type: application/json' \
--data '{"enabled":false}'

Project admins are not exempt. If you turn practitioner sign-in off and your own session ends, you cannot sign back in to turn it on again. Keep a signed-in admin session open until you have confirmed the change.

Which sign-in this applies to​

Tenant sign-in (/auth/tenant/Practitioner/...) is the current way to sign in to an Ovok project. Every project has a tenant code, which names the project in the request. The older routes in the table below still work and are listed because the switch covers them too: POST /auth/login, TAN sign-in, /auth/external/* and /auth/signup are marked deprecated, and POST /v2/auth/login is the older client-ID sign-in that the platform's own code says to replace with tenant sign-in.

Where the switch applies​

Sign-in pathChecked today?
POST /auth/tenant/Practitioner/login/tokenYes
POST /v2/auth/login and the deprecated POST /auth/loginYes
POST /auth/tenant/Practitioner/login/start and login/mfaNo
TAN sign-inNo
Token refresh (POST /auth/refresh-token, /oauth2/token)No
POST /auth/tenant/Practitioner/register (returns tokens on success)No

The switch is being extended to the remaining paths. Treat the table as the contract for your current release and test the paths your app uses.

What callers see when it is off​

RouteStatusMessage
POST /auth/tenant/Practitioner/login/token403Login is not enabled for this project.
POST /v2/auth/login403Login is not enabled for this project.

On the tenant route the check runs before the session code is used, so a refused request does not consume the code. An unknown tenant code answers 404 first.

Gotchas​

  • The refusal arrives late in the two-step flow. login/start and login/mfa still verify the password and the second factor, and the response can list the project among the user's profiles. The user only learns that sign-in is off at login/token. Build your sign-in screen to handle a 403 at that step.
  • Turning it off does not end sessions. Signed-in practitioners keep working and can keep refreshing. An access token lasts up to 60 minutes. Revoke a session with DELETE /auth/session/:id or POST /auth/logout.
  • GET shows false for a project that has never set it, but practitioners can sign in. Set the key to the value you intend. See Unset settings.
  • Registration and invitations are separate. A practitioner who registers through POST /auth/tenant/Practitioner/register receives tokens even when this switch is off.
  • A failed read looks like "off". If the project cannot be read for a moment, callers see the same 403 as when the switch is off.
  • Rate limits. login/token allows 30 requests per minute per client address, login/mfa 5, and login/start 10.