Skip to main content

Passwords and sessions

Use the account methods on OvokClient to change a password, start password recovery, complete a reset, review active sessions, and sign out. Your application supplies the forms and communicates each operation's result.

Change a password​

Call changePassword() with the current password, the new password, and its confirmation. Run this flow from the signed-in account experience and show the user whether the change succeeded. The SDK sends the confirmation value with the request; do not assume a password change is complete until the method resolves successfully.

Request a password reset​

Call resetPassword() with the account email and account type (Patient or Practitioner). An optional clientId can be supplied for the reset request; when omitted, the client uses its configured socialLoginClientId value.

The method returns an OperationOutcome from the reset request. Present a neutral confirmation after a reset is requested so the screen does not disclose whether an account exists for a given email address. The platform's authentication troubleshooting guide covers account recovery issues.

Complete a password reset​

When the user returns from the reset email, call setPasswordFromReset() with the reset id, secret, and new password supplied by the reset flow. The result is an OperationOutcome. Keep the reset secret within the recovery flow and do not log or display it.

These examples assume client is configured and the values come from the appropriate form or reset link.

async function requestPasswordReset() {
await client.resetPassword({ email, type: 'Patient' });
showResetInstructions();
}

// In the reset page reached from the email:
async function completePasswordReset() {
await client.setPasswordFromReset({ id, secret, password: newPassword });
showPasswordUpdated();
}

Review and revoke sessions​

getSessions() returns the server-side sessions for the current account. Session entries can include an ID, authentication method, remote address, and last-updated time. These details can support a “signed-in devices” screen; treat optional fields as potentially unavailable.

revokeSessions() can revoke the current session, other sessions, all sessions, or a selected session by ID. Refresh the session list after a successful revocation so the interface reflects the current account state.

Sign out​

Call logout() to revoke the current session and clear the local signed-in state. It also removes that account and its expired marker from this client's saved-account list, whether the server revocation succeeds or fails. If the device is offline, the server-side session may remain valid until it expires; the SDK cannot revoke it later because the login has been removed locally. If an account should stay available for a later retry when revocation fails, use removeAccount() instead.

async function signOutEverywhereElse() {
const sessions = await client.getSessions();
await client.revokeSessions('other');
return sessions;
}

async function signOut() {
await client.logout();
}

Refresh the profile​

Call refetchProfile() when the current account profile may have changed and the application needs to refresh its in-memory profile. This refresh is separate from password recovery and session revocation.