v3
latestOpenAPI 3.1.02026-07-311,4541,5202.3 MBauthentication
Auth Jwt Revoke Create
Per-token revocation — Phase 7 of the staff step-up auth rollout.
Stateless JWT auth means the natural exp is the only kill switch by default. This view writes a Redis denylist key for the supplied jti so the next time the auth class sees that token, it raises AuthenticationFailed instead of accepting it. The TTL is bounded by the access-token lifetime so the denylist never grows unbounded.
Authorization:
- jti matches the caller's PRESENTED token: always allowed (self-revoke / logout-like — kill my current session NOW).
- jti is a DIFFERENT token: requires staff_write scope. Admin emergency revocation — used when a colleague's JWT is confirmed compromised. The actor's own session is unaffected.
The OLD JWT's cryptographic validity is unchanged — denylist is a server-side gate. A token presented after revocation fails KeywordsAIJWTAuthentication.authenticate with a 401.
See implementation_logs/security/staff_step_up_auth_design.md §7b.
post/auth/jwt/{jti}/revoke/
Path parameters
jtistring required
Headers
Authorizationstring required
JWT access token or Respan API key
Response
No response body
AuthenticationAuthJwtRevokeCreateResponse200 required
Empty response body