---
title: "Revoke connected app"
method: DELETE
path: "/v1/me/connected-apps/{clientId}"
tags: ["Connected Apps"]
---

# Revoke connected app

`DELETE /v1/me/connected-apps/{clientId}`

Ends an app's access: invalidates the client's pending authorization codes and
revokes every live token it holds for the authenticated user. Takes effect on
the app's next request.

Idempotent while the authorization is still on record: revoking an app that
was already revoked returns 200 with `revokedTokens: 0`.

Requires a session or a full-access API key. A profile-scoped API key, a
restricted (zrk_) API key, or an OAuth access token is rejected with 403.

## Path parameters

- `clientId` string, required

## Response `200`

Revoked

- object
  - `revoked` boolean
  - `clientId` string
  - `revokedTokens` integer — Access and refresh tokens revoked by this call.
  - `invalidatedCodes` integer — Pending authorization codes invalidated by this call.

## Other responses

- `400` — Invalid request
- `401` — Unauthorized
- `403` — The API key is a restricted key (zrk_ prefix) and may not perform this operation. Three cases. (1) The operation's resource group (see the operation's x-resource-group) is disabled on the key: fix it by creating a key with the group enabled in the dashboard API keys tab and revoking the old one. (2) The operation is admin-plane (x-resource-group admin-plane: API keys, invites, connected apps, member identity), which is never grantable to restricted keys; the error reads "Restricted API keys cannot manage API keys, invites, or member identity." and the fix is a full-access key or the dashboard, never a new restricted key. (3) On webhook subscription writes, delivery-log reads and replays, a named event maps to a resource group the key does not hold, so a restricted key can never create or edit a subscription broader than itself (a no-messages key cannot subscribe to, test-fire, redeliver or read logs for message.* events).
- `404` — The authenticated user has never authorized this client. Error code: oauth_client_not_found.

---

[API](https://skmtc.net/zernio/apis/zernio-api.md) · [All operations](https://skmtc.net/zernio/apis/zernio-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/zernio/zernio-api/versions/51932b099b2f/schema)
