ChartnautDocs

Revoke the current key

POST/auth/revoke

Revokes the key that makes the call. Every later call with it answers 401 unauthorized. It is the sign-out behind chartnaut logout.

Scope

Heavy call

Long poll

CLI

Any key

No

No

chartnaut logout

Guidance

  • Call it when your program signs out, or when a key may have leaked: in a commit, a log or a chat. It cannot be undone.

  • It revokes only the key in the Authorization header. To revoke another key, use it to make this call, or revoke it on the Developers page.

  • Any valid key can call it, whatever its scopes.

  • Called with an OAuth access token, it ends that app's whole connection, as Disconnect under Connected apps does. Revoke a token is the OAuth way to do the same.

  • On Free every call gets 403 plan_limit before it reaches this one, so revoke the key on the Developers page instead. Revoking there works on every plan.

  • Delete your stored copy of the key after a 204. If the call fails, delete it anyway and revoke the key on the Developers page.

Response

204 with no body.

Status codes

Status

Code

Meaning

204

-

The key is revoked

401

unauthorized

The key was already wrong, expired or revoked

403

plan_limit

The account is on Free. Revoke the key on the Developers page

500

internal

The key could not be revoked. Retry