v17

latestOpenAPI 3.0.3Apache 2.0raw.githubusercontent.com2026-08-0491166902.9 KB
Token Operations

Revoke Access Token

Revoke an access token.

post/api/{serviceId}/auth/token/revoke

Path parameters

serviceIdstring required

A service ID.

Request body

accessTokenIdentifierstring

The identifier of an access token to revoke

The hash of an access token is recognized as an identifier as well as the access token itself.

refreshTokenIdentifierstring

The identifier of a refresh token to revoke.

The hash of a refresh token is recognized as an identifier as well as the refresh token itself.

clientIdentifierstring

The client ID of the access token to be revoked.

Both the numeric client ID and the alias are recognized as an identifier of a client.

Bulk revocation with clientIdentifier only or clientIdentifier + subject deletes at most 20 tokens per request (the default of token.revoke.count.max in ServerConfiguration.java). If the target has more than 20 tokens, the response count will be 20 and the remainder is left untouched. To fully wipe them, call the endpoint repeatedly until count returns 0.

subjectstring

The subject of a resource owner.

Bulk revocation with clientIdentifier + subject or subject only deletes at most 20 tokens per request (the default of token.revoke.count.max in ServerConfiguration.java). If the target has more than 20 tokens, the response count will be 20 and the remainder is left untouched. To fully wipe them, call the endpoint repeatedly until count returns 0.

Response

Token revoked successfully

resultCodestring

The code which represents the result of the API call.

resultMessagestring

A short message which explains the result of the API call.

countinteger

The number of tokens revoked.

If the target has more than 20 tokens, the response count will be 20 and the remainder is left untouched. To fully wipe them, call the endpoint repeatedly until count returns 0.