---
title: "Invalidate access_token"
method: POST
path: "/item/access_token/invalidate"
tags: ["plaid"]
---

# Invalidate access_token

`POST /item/access_token/invalidate`

By default, the `access_token` associated with an Item does not expire and should be stored in a persistent, secure manner.

You can use the `/item/access_token/invalidate` endpoint to rotate the `access_token` associated with an Item. The endpoint returns a new `access_token` and immediately invalidates the previous `access_token`.

## Request body

- ItemAccessTokenInvalidateRequest — ItemAccessTokenInvalidateRequest defines the request schema for `/item/access_token/invalidate`
  - `client_id` string — Your Plaid API `client_id`. The `client_id` is required and may be provided either in the `PLAID-CLIENT-ID` header or as part of a request body.
  - `secret` string — Your Plaid API `secret`. The `secret` is required and may be provided either in the `PLAID-SECRET` header or as part of a request body.
  - `access_token` string, required — The access token associated with the Item for which data is being requested.

## Response `200`

OK

- ItemAccessTokenInvalidateResponse — ItemAccessTokenInvalidateResponse defines the response schema for `/item/access_token/invalidate`
  - `new_access_token` string, required — The access token associated with the Item for which data is being requested.
  - `request_id` string, required — A unique identifier for the request, which can be used for troubleshooting. This identifier, like all Plaid identifiers, is case sensitive.

## Other responses

- `default` — Error response

---

[API](https://skmtc.net/plaid/apis/the-plaid-api.md) · [All operations](https://skmtc.net/plaid/apis/the-plaid-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/plaid/the-plaid-api/versions/64c4514ea59b/schema)
