Skip to main content

Projects and platform APIs

The SDK exposes typed helpers for project setup and administration. The server enforces project membership and admin permissions on every request. A hidden button or client-side check does not secure an operation.

Projects and memberships​

The client includes methods to list and bootstrap projects, read the current tenant code, list project members, invite members, update member admin status, and remove a member. These are authenticated project operations; link each UI action to the correct project context and handle authorization errors from the server.

Features and settings are different​

Use getProjectFeatures() and updateProjectFeatures() for project capabilities. Updating features replaces the full list, so read the current list, apply the intended change, then submit the complete list.

Use getProjectSettings() and the setting update methods for named project rules. Boolean settings and text values use different methods; text values can be cleared with null.

import { OVOK_PROJECT_FEATURE_VALUES } from '@ovok/core';

const { features } = await client.getProjectFeatures();
const enabled = new Set(features);
const nextFeatures = OVOK_PROJECT_FEATURE_VALUES.filter((feature) =>
enabled.has(feature),
);
if (!enabled.has('bots')) nextFeatures.push('bots');
await client.updateProjectFeatures(nextFeatures);

await client.updateProjectSetting('PATIENT_LOGIN_ENABLED', true);
await client.updateProjectTextSetting(
'PATIENT_APP_URL',
'https://your-allowlisted-app.example',
);

Replace the example app URL with an origin allowed for the project. An arbitrary URL may be rejected by the backend.

Do not confuse a setting with an AccessPolicy: settings control whether a flow is available, while an AccessPolicy defines what an authenticated principal can access. See Settings and features and Access policies.

Localization​

The client provides locale discovery and update methods, localization reads and writes, and I18next document methods. These APIs manage project content; they do not translate content automatically unless a separate translation workflow is invoked.

Backend compatibility​

Some methods require a specific Ovok backend release. Deploy the matching backend before exposing a new SDK workflow. Use capability discovery and the FHIR API reference to check the connected environment.