Tarsana docsDashboard

Revoke an API access token

Destructive · DELETE /v1/access-tokens/{token_id} · MCP tool revoke-access-token

Revokes one of your access tokens, by the token_id that issue-access-token returned. The next call that uses the token is refused, and the revocation is permanent. If the token is not yours or does not exist, the answer is revoked: false. You need to be signed in with a session to revoke a token.

Roles that can call it: viewer, builder, deployer.

Parameters

NameInRequiredDescription
token_idpathyesThe token ID that issue-access-token returned

Returns

A JSON object with these keys: revoked, token_id, login, guarantee, caller_authenticated.

Example request

curl -X DELETE https://api.tarsana.io/v1/access-tokens/67e94a06c977c24c \
  -H "X-Tarsana-Session: $SESSION"

Example response

{
  "revoked": true,
  "token_id": "67e94a06c977c24c",
  "login": "you@example.com",
  "guarantee": "namespaces are separated, callers are not authenticated",
  "caller_authenticated": false
}

Errors

CodeHTTPWhat it means
invalid_parameter400A value in your request does not have the expected format, for example a submission ID that is not a spec hash. Check the value against the field's description and try again.
unauthenticated401Your request has no credential, or one that Tarsana does not recognise. Sign in with login, or send a valid access token.
forbidden403Your role does not allow this operation. The response names the roles that do; ask for a credential with one of them.
rate_limited429You sent too many requests in a short time. Wait for the number of seconds in retry_after_seconds, then try again.
surface_fault500Something went wrong on our side. Try again later, and contact Tarsana support if it keeps happening.

View this page as Markdown