Skip to main content
POST
Token revocation (RFC 7009)

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/x-www-form-urlencoded
token
string
required
client_id
string
required
token_type_hint
enum<string>
Available options:
access_token,
refresh_token
client_secret
string

Required only for confidential clients.

Response

Token revoked. Per RFC 7009 §2.2 the body is empty — there is no JSON payload to parse, and this is also the response for a token that was already unknown or revoked.