Skip to main content

Revoke a token

POST 

/oauth/revoke

RFC 7009. Revokes an access token (vh_oat_) or a refresh token (vh_ort_). Revoking a refresh token disconnects the app from the dealer: the whole authorisation and every token it issued are revoked. Answers 200 with an empty object whether or not the token existed, so the endpoint cannot be used to test tokens. Client authentication as for /oauth/token. No key is sent.

Request​

Responses​

Revoked, or there was nothing to revoke.