Skip to main content

Revoke Token

POST 

/v1/open-api/oauth/revoke

Revoke one of your own tokens (RFC 7009). Revoking a refresh token (uysotrt_…) also invalidates the access tokens issued from it; revoking an access token (uysot_at_…) affects only that token.

client_id and client_secret are required — a token is only revoked when it belongs to that client. Per RFC 7009 an unknown or foreign token also returns 200, so the endpoint never reveals whether a token exists.

The request body is application/x-www-form-urlencoded.

Requires no token — the client authenticates with client_id + client_secret.

Request​

Responses​

The token was revoked, or did not exist / did not belong to this client — the response is the same either way.