Revoke the current key
/auth/revokeRevokes the key that makes the call. Every later call with it answers 401 unauthorized. It is the sign-out behind chartnaut logout.
Scope | Heavy call | Long poll | CLI |
|---|---|---|---|
Any key | No | No |
|
Guidance
Call it when your program signs out, or when a key may have leaked: in a commit, a log or a chat. It cannot be undone.
It revokes only the key in the
Authorizationheader. To revoke another key, use it to make this call, or revoke it on the Developers page.Any valid key can call it, whatever its scopes.
Called with an OAuth access token, it ends that app's whole connection, as Disconnect under Connected apps does. Revoke a token is the OAuth way to do the same.
On Free every call gets
403 plan_limitbefore it reaches this one, so revoke the key on the Developers page instead. Revoking there works on every plan.Delete your stored copy of the key after a
204. If the call fails, delete it anyway and revoke the key on the Developers page.
Response
204 with no body.
Status codes
Status | Code | Meaning |
|---|---|---|
| - | The key is revoked |
|
| The key was already wrong, expired or revoked |
|
| The account is on Free. Revoke the key on the Developers page |
|
| The key could not be revoked. Retry |
