Skip to main content

Update user consents

MethodPath
POST/v1/slim/user/consents

Authentication · Access policies

Updates one or more consents of the signed-in practitioner. Use it to save the answers of a combined consent prompt.

Auth: Bearer token for a practitioner session (the profile must be a Practitioner). The caller's access policy must grant Consent:read, Consent:search, Consent:create and Consent:update (project admins skip this check). Scope: The caller's practitioner profile in the caller's project (from the token).

Behaviour​

  • Send at least one of medicalSettingsNotificationsConsent and termsAndConditionsConsent. Only the fields you send change.
  • true records acceptance of the currently published version of that consent. false withdraws it.
  • A termsAndConditionsConsent change also creates, re-activates or revokes the legal Consent read by GET /v1/me/consent/legal.
  • All changes commit together or not at all. Repeating the same values writes nothing.
  • The consent answers of /v1/me/consent/* are refreshed right away.
  • The response always carries the resulting state of every consent.

Example​

curl -X POST 'https://api.sandbox.ovok.com/v1/slim/user/consents' \
-H "Authorization: Bearer ${OVOK_TOKEN}" \
-H 'Content-Type: application/json' \
-d '{ "medicalSettingsNotificationsConsent": true, "termsAndConditionsConsent": true }'

Successful response​

201 — Consent statuses updated successfully.

Errors​

StatusMeaning
400Medplum refused the consent write.
401The bearer token is missing or invalid.
403The session is not a practitioner session, has no project, or its access policy lacks one of the Consent interactions.
409The consent write lost a conflict with a concurrent write. Retry.
422The body fails validation, or it contains neither consent field.