v39

latestOpenAPI 3.0.0raw.githubusercontent.com2026-08-017897360.9 KB
Authorization Tokens

Revoke Authorization Token

Revoke an unverified Authorization Token. Once revoked, the code can no longer be verified. Tokens that have already been verified or expired cannot be revoked and will return status 412 Precondition Failed.

post/v1/authorization_tokens/{id}/revoke

Path parameters

idstring required

The unique id of the Authorization Token

Response

The token was revoked

idstring required

The unique identifier for this object.

donor_account_idstring required

The ID of the Donor Account this token is bound to.

status'pending' | 'verified' | 'revoked' | 'expired' required

The status of a Donor Authorization Token.

  • pending: The token has been issued but not yet verified.
  • verified: The token has been verified and can no longer be used.
  • revoked: The token was explicitly revoked before being verified.
  • expired: The token's expires_at has passed and it can no longer be verified.
codestring

The token's secret code value.

<Warning> The `code` is **only returned in the response of [Create Authorization Token](/api/authorization-tokens/create)**. It is omitted from all other responses (Get, List). If the code is lost, [revoke](/api/authorization-tokens/revoke) the token and create a new one. </Warning>

The format is a 12-character alphanumeric string designed to be easy for donors to read aloud or copy. Codes are not case-sensitive when verified.

created_atstring date-time required

Time when the token was issued. Expressed in RFC 3339 format.

expires_atstring date-time required

Time at which this token will expire and can no longer be verified. Defaults to 30 days after creation; configurable via the expires_in parameter on Create Authorization Token.

verified_atstring date-time

Time at which the token was verified. Only set when status is verified.

revoked_atstring date-time

Time at which the token was revoked. Only set when status is revoked.

metadataobject

A map of arbitrary string keys and values to store information about the object.

Example response

{
  "id": "auth_token_01jpjenf5q6cawy43yxfcrxhct",
  "donor_account_id": "donor_account_01jpjenf5q6cawy43yxfcrxhct",
  "status": "pending",
  "code": "DAFP-7K3X-9M4Q",
  "created_at": "2026-04-01T12:00:00Z",
  "expires_at": "2026-05-01T12:00:00Z",
  "verified_at": "2026-04-02T18:30:00Z",
  "revoked_at": "2026-04-02T18:30:00Z"
}