Skip to main content

Sign in

Use login() to sign in a patient or practitioner with an email address and password. The method handles the sign-in exchange and returns either an authenticated result or an MFA step for the application to present.

Choose the account type and tenant​

login() accepts an account type of Patient or Practitioner, plus the account email and password.

Account typeTenant behavior
PatienttenantCode is required. The patient signs in to that tenant.
PractitionertenantCode is optional. Pass it when the application needs a specific project. When tenant memberships are returned with the sign-in start, the SDK uses the first one if tenantCode is omitted.

Practitioners can belong to more than one project. Pass the intended tenant code when the account may have multiple memberships. When MFA is enabled, pass it explicitly: the platform's MFA start response does not include the membership list, so the SDK needs the tenant code to finish sign-in. See Ovok's practitioner sign-in guide for how project membership works.

Patients and practitioners use distinct sign-in flows. A patient account must belong to the tenant named in the request. Review patient sign-in and practitioner sign-in for the platform requirements.

Handle multi-factor authentication​

When MFA is not required, login() resolves with an authenticated result. When MFA is required, it resolves with a pending step whose nextStep is mfa and whose verify(code) function completes sign-in after the user provides a current one-time code.

Build the screen around both outcomes:

  1. Submit the sign-in form and show progress while login() is pending.
  2. If the result is the MFA step, ask for the current one-time code and call verify() with it.
  3. Continue to the signed-in state only after the authenticated result is returned.

Keep the MFA prompt distinct from a failed password attempt. If verification fails, show an actionable error and let the user retry according to your authentication policy.

Use the authenticated result​

The authenticated result includes an access token, refresh token, access-token lifetime, profile reference, and project reference. Use the profile and project to render the signed-in account context. The project reference also helps an application confirm which tenant the practitioner entered.

The SDK does not provide login screens, tenant navigation, or MFA UI. Keep those parts in your application and make the selected account type and project clear to the user.

Example​

This example is split across the sign-in form and the MFA form. Keep the pending result from the first call so verification completes the same attempt.

async function submitPatientSignIn() {
const result = await client.login({
email,
password,
type: 'Patient',
tenantCode,
});

if ('nextStep' in result && result.nextStep === 'mfa') {
setPendingMfa(result);
return;
}

onSignedIn(result);
}

async function submitMfa(pendingMfa, code) {
const authenticated = await pendingMfa.verify(code);
onSignedIn(authenticated);
}

For practitioner sign-in, set type to Practitioner and pass the selected tenantCode, especially when MFA is enabled.

Check project configuration​

Before release, confirm that the target project allows the intended flow:

If sign-in fails, check the tenant code and account type first, then review authentication troubleshooting. The official guides also document how the platform handles invalid credentials, MFA, and disabled sign-in settings.