Revoke a refresh token family (idempotent).
POST /auth/token/revoke
POST
/auth/token/revoke
Revokes the entire refresh-token family associated with the submitted token. Idempotent: an unknown or already-revoked token returns success: true with no error — this prevents leaking whether a particular token ever existed.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Header Parameters
Section titled “Header Parameters ” X-API-Key-ID
required
string
Trusted App API key id (format pol_tai_<24 base64url>).
X-API-Key-Secret
required
string
Trusted App API key secret (64 hex). Never logged, never echoed.
Request Body required
Section titled “Request Body required ”object
refreshToken
required
string
Responses
Section titled “ Responses ”Family revoked (or token unknown — idempotent success).
object
success
required
boolean
Validation error.
Invalid API key credentials.
Rate limit exceeded.