v1

latestOpenAPI 3.1.0CC-BY-NC-SA-4.02026-07-2413803.8 MB
OAuth API

Revoke tokens

Revoke an access token or refresh token. Once revoked, the token can no longer be used.

Revoking a refresh token revokes all access tokens that were created using the same authorization.

This endpoint can only be accessed using OAuth client credentials.

🔑 Access with

Basic authentication

delete/oauth2/tokens

Headers

Authorizationstring required

The OAuth client ID and client secret as basic access credentials.

Pseudo code: "Basic " + toBase64(client_id + ":" + client_secret)

For example: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==

Content-Typestring

This header value must match the type of the request body you send, if there is a request body. For example, if you send the request body as JSON, this header must be set to application/json, and if you send it as form encoded you must set this header to application/x-www-form-urlencoded.

Request body

token_type_hintstring required

The type of token you want to revoke.

Possible values: access_token refresh_token

tokenstring required

The token you want to revoke.

Example request

{
  "token_type_hint": "access_token",
  "token": "access_..."
}

Response

An empty response.

{"stackTrail":"paths:/oauth2/tokens:delete:responses:204:content:application/json:schema","oasType":"schema","type":"unknown"}