Skip to content

Revoke App Credential

DELETE
/apps/{app_id}/credentials/{client_id}

PREVIEW. This endpoint is deployed but gated: it returns 404 unless the hosted app platform is enabled for your organization. It is published here so the contract describes the whole surface, not so it can be called today.

Revoke a service credential. A status flip, never a delete.

Deleting would erase the evidence that the credential ever existed, which is precisely what an incident review needs. Tokens already minted from it are NOT retroactively invalid — they expire on their own short TTL — but no new one can be minted.

Authorizations

Parameters

Path Parameters

app_id
required
string
client_id
required
string

Header Parameters

X-Org-Id
Any of:
string

Responses

200

Successful Response

object
data
required

A service credential. Carries NO secret.

object
app_id
required
string
client_id
required
string
client_org_id
required
string
created_at
Any of:
string format: date-time
revoked
boolean
pagination
Any of:
object
has_next
required

Whether there are more pages

boolean
limit
required

Items per page

integer
next_cursor
Any of:
string
page
required

Current page number (1-indexed)

integer
total
required

Total number of items

integer

422

Validation Error

object
detail
Array<object>
object
loc
required
Array
msg
required
string
type
required
string