Skip to main content

PRACTITIONER_REGISTRATION_ENABLED

Controls whether a practitioner can create their own account in the project without being invited. It is off by default and should stay off unless you want anyone who can reach the sign-up route to become a practitioner of your project.

TypeBoolean setting
Change withPUT /v1/project/settings/PRACTITIONER_REGISTRATION_ENABLED
Who can change itProject admin
When unsetRegistration is off, and GET /v1/project/settings reports false
Set on new projectsfalse for child projects created with POST /v1/slim/project/child; not set by any other project-creation route
NeedsDEFAULT_PRACTITIONER_ACCESS_POLICY
InheritedNo. A child project reads only its own value and its own policy.

Turn practitioner registration on​

Set the default practitioner AccessPolicy first, then switch registration on:

curl --request PUT \
--url 'https://api.sandbox.ovok.com/v1/project/settings/values/DEFAULT_PRACTITIONER_ACCESS_POLICY' \
--header "Authorization: Bearer ${OVOK_TOKEN}" \
--header 'Content-Type: application/json' \
--data '{"value":"AccessPolicy/practitioner-policy-id"}'
curl --request PUT \
--url 'https://api.sandbox.ovok.com/v1/project/settings/PRACTITIONER_REGISTRATION_ENABLED' \
--header "Authorization: Bearer ${OVOK_TOKEN}" \
--header 'Content-Type: application/json' \
--data '{"enabled":true}'

Every practitioner who registers gets that AccessPolicy. Choose the least privilege you are happy to give a stranger.

What callers see​

POST /auth/tenant/Practitioner/register runs its checks in this order:

OrderConditionStatusResponse
1Too many requests (5 per minute per client address)429
2Unknown tenant code404Tenant not found.
3Empty password422Validation error
4The switch is off403Registration is not enabled for this project.
5The switch is on but there is no valid default practitioner AccessPolicy409error practitioner_registration_not_configured: Practitioner registration is on for this project, but it has no valid default access policy.
6Another registration for the same email is in progress409
7The email already belongs to an account400Registration failed.

On success the response contains tokens and no email is sent. The account and its membership are created together or not at all.

POST /auth/signup with resourceType Practitioner always answers 403 with Practitioners register through POST /auth/tenant/Practitioner/register.

Gotchas​

  • The email check spans the whole platform. A practitioner whose email already has an account in any project gets 400 Registration failed. Invite them instead; see PRACTITIONER_INVITATION_ENABLED.
  • The 400 message is generic. It does not say whether the email already has an account, so do not build UI that promises to explain the failure.
  • Registration returns tokens even if PRACTITIONER_LOGIN_ENABLED is false.
  • Order matters when you enable it. With the policy missing, the project answers 409, not a silent success. Set the AccessPolicy first.
  • A policy that stops being valid breaks registration. If the AccessPolicy named by DEFAULT_PRACTITIONER_ACCESS_POLICY is deleted, cannot be read, or belongs to another project, step 5 returns 409 until you set a valid one.
  • Changing the policy does not touch practitioners who already registered.
  • Registration sends no confirmation email. The new account is signed in straight away; the route does not check that the address belongs to the person registering.