Revoke Token
POST/v1/open-api/oauth/revoke
Revoke one of your own tokens (RFC 7009). Revoking a refresh token (uysotrt_…) also
invalidates the access tokens issued from it; revoking an access token (uysot_at_…)
affects only that token.
client_id and client_secret are required — a token is only revoked when it belongs to
that client. Per RFC 7009 an unknown or foreign token also returns 200, so the endpoint
never reveals whether a token exists.
The request body is application/x-www-form-urlencoded.
Requires no token — the client authenticates with client_id + client_secret.
Request
Responses
- 200
- 401
The token was revoked, or did not exist / did not belong to this client — the response is the same either way.
Unknown client_id, or a wrong or missing client_secret (401, error
invalid_client, message_code 6905). The body is the RFC 6749 §5.2 error
object, not the standard envelope.