Skip to content
API documentation
View as MarkdownOpen in Claude

API account

Revoke the token you send, before it expires

POST
/v1/api-account/revoke-token

Revokes the bearer token this request carries. Send no body. From now on that token answers 401 unauthorized everywhere, this operation included, so sending it again with the same token answers 401. Only this token is revoked: your other tokens work until they expire.

data.expiresIn is how many seconds the revocation is held: what was left of the token’s life plus 30 seconds of clock tolerance, at least 1 and at most 3660. After that the token would be refused as expired anyway.

Use it when a token may have leaked, or when the session it served ends. It needs the api/* permission, which only a role whose action is api/*, */* or * grants; a role for the student or exam operations does not. An account without it cannot revoke its tokens, so keep them short-lived.

Responses

200 OK

Success: message is "Token revoked successfully".

Body

  • successbooleanrequired

    Always true on a success.

    one oftrue

  • messagestringrequired

    exampleToken revoked successfully

  • dataobject · RevokeTokenResponserequired

    The token you sent is revoked.

    1 field of data
    • expiresInintegerrequired

      How many seconds the revocation is held: what was left of the token’s life plus 30 seconds of clock tolerance, and at least 1. The token is refused from now on; after this it would be refused as expired anyway.

      min1example1830

Headers

X-RateLimit-Limit integer

Requests your account may make to this operation per window (100).

X-RateLimit-Remaining integer

Requests left in the current window.

X-RateLimit-Reset integer

Seconds until the current window ends.

Example

{
  "success": true,
  "message": "Token revoked successfully",
  "data": {
    "expiresIn": 1830
  }
}

Example request

# $TOKEN: a short-lived token you minted with your API key and secret
curl -sS -X POST 'https://api.main-team.org/v1/api-account/revoke-token' \
  -H "Authorization: Bearer $TOKEN"

Search the API documentation

Guides, endpoints by name, path or permission, and error codes such as not_found.