v1

latestOpenAPI 3.1.0Apache 2.02026-07-264001921002.3 KB
MCP

Revoke an MCP session

Revokes a session by primary key. Accepts these row kinds:

  • OAuth token rows → hard-deletes the token plus any pending OAuth flow for the same binding (so an in-flight callback can't undo the revoke)
  • Header credential rows → hard-deletes the credential plus any pending header submission flow for the same binding
  • Pending per-user-headers flow rows → hard-deletes just the flow

Note: pending per-user OAuth flow rows are not revocable by this endpoint — they expire naturally or are cleared when the bound token row is revoked. To cancel a pending OAuth flow, revoke its parent token (if one exists) or wait for expiry.

Bifrost does not call the upstream provider's revoke endpoint — revocation is local. Per-user-headers credentials never call upstream.

delete/api/mcp/sessions/{id}

Path parameters

idstring required

Session / credential / flow row ID

Response

Revoked