Token revocation (RFC 7009)
curl --request POST \
--url https://api.nexspace365.com/oauth/revoke \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data 'token=<string>' \
--data 'client_id=<string>' \
--data 'client_secret=<string>'import requests
url = "https://api.nexspace365.com/oauth/revoke"
payload = {
"token": "<string>",
"client_id": "<string>",
"client_secret": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/x-www-form-urlencoded"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
Authorization: 'Bearer <token>',
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({token: '<string>', client_id: '<string>', client_secret: '<string>'})
};
fetch('https://api.nexspace365.com/oauth/revoke', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.nexspace365.com/oauth/revoke",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "token=%3Cstring%3E&client_id=%3Cstring%3E&client_secret=%3Cstring%3E",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/x-www-form-urlencoded"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.nexspace365.com/oauth/revoke"
payload := strings.NewReader("token=%3Cstring%3E&client_id=%3Cstring%3E&client_secret=%3Cstring%3E")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.nexspace365.com/oauth/revoke")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/x-www-form-urlencoded")
.body("token=%3Cstring%3E&client_id=%3Cstring%3E&client_secret=%3Cstring%3E")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.nexspace365.com/oauth/revoke")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/x-www-form-urlencoded'
request.body = "token=%3Cstring%3E&client_id=%3Cstring%3E&client_secret=%3Cstring%3E"
response = http.request(request)
puts response.read_body{
"error": "invalid_client",
"error_description": "<string>"
}OAuth
Token revocation (RFC 7009)
Revokes a token. Revoking a refresh token invalidates it and its entire
rotation chain. Revoking an access token invalidates the associated
refresh-token chain so the session can’t be renewed; the stateless
access JWT itself remains valid until its short (1h) exp. Per RFC 7009
the response is always 200 with an empty body, even for unknown
tokens. The caller authenticates as the owning client (see
/oauth/introspect).
POST
/
oauth
/
revoke
Token revocation (RFC 7009)
curl --request POST \
--url https://api.nexspace365.com/oauth/revoke \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data 'token=<string>' \
--data 'client_id=<string>' \
--data 'client_secret=<string>'import requests
url = "https://api.nexspace365.com/oauth/revoke"
payload = {
"token": "<string>",
"client_id": "<string>",
"client_secret": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/x-www-form-urlencoded"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
Authorization: 'Bearer <token>',
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({token: '<string>', client_id: '<string>', client_secret: '<string>'})
};
fetch('https://api.nexspace365.com/oauth/revoke', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.nexspace365.com/oauth/revoke",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "token=%3Cstring%3E&client_id=%3Cstring%3E&client_secret=%3Cstring%3E",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/x-www-form-urlencoded"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.nexspace365.com/oauth/revoke"
payload := strings.NewReader("token=%3Cstring%3E&client_id=%3Cstring%3E&client_secret=%3Cstring%3E")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.nexspace365.com/oauth/revoke")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/x-www-form-urlencoded")
.body("token=%3Cstring%3E&client_id=%3Cstring%3E&client_secret=%3Cstring%3E")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.nexspace365.com/oauth/revoke")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/x-www-form-urlencoded'
request.body = "token=%3Cstring%3E&client_id=%3Cstring%3E&client_secret=%3Cstring%3E"
response = http.request(request)
puts response.read_body{
"error": "invalid_client",
"error_description": "<string>"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
application/x-www-form-urlencoded
Response
Token revoked (empty body)
⌘I

