> ## Documentation Index
> Fetch the complete documentation index at: https://docs.keystoneos.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Revoke a session token

> Requires the `sessions:write` scope (as an M2M scope or a user permission).

Immediately invalidate a session token before it expires. Revocation is scoped to the caller's own environment, matching minting: the caller must be acting in the environment the token was minted in (for user tokens, the environment selected via the X-Keystone-Environment header). Any credential of that environment may revoke, not only the one that minted the token. A token minted in any other environment returns 404.



## OpenAPI

````yaml /api-reference/openapi.json delete /v1/sessions/{token_id}
openapi: 3.1.0
info:
  title: Keystone API
  description: Settlement orchestration API for tokenized Real-World Assets (RWAs).
  version: 0.9.0
  x-keystone-api-contract-version: 0.9.0
  x-keystone-source-revision: c094c5ec38de81d550cde98e6366efaac99cffea
servers:
  - url: https://api-staging.keystoneos.xyz
    description: Staging (sandbox)
  - url: https://api.keystoneos.xyz
    description: Production
security:
  - bearerAuth: []
tags:
  - name: health
    description: Health and version checks.
  - name: platforms
    description: Register and manage your platform profile.
  - name: environments
    description: Manage platform environments (sandbox, production).
  - name: settlement-templates
    description: View and manage settlement templates.
  - name: settlements
    description: Initiate, monitor, and manage settlements.
  - name: sessions
    description: Create and manage browser-safe session tokens for frontend widgets.
  - name: instructions
    description: Submit and manage settlement instructions.
  - name: invitations
    description: Invite team members to your platform.
  - name: members
    description: Manage platform team members and roles.
  - name: webhooks
    description: Configure webhook endpoints for real-time event notifications.
  - name: security
    description: IP allowlisting and API access controls.
  - name: activity
    description: Audit trail of platform actions.
  - name: dashboard
    description: Dashboard metrics and statistics.
  - name: callbacks
    description: Provider callback handlers (internal).
  - name: alchemy-webhooks
    description: Alchemy blockchain event webhooks (internal).
  - name: chains
    description: Supported blockchain networks for settlement.
  - name: admin
    description: KeyStone internal administration endpoints.
  - name: admin-platforms
    description: Admin platform management.
  - name: admin-settlements
    description: Admin settlement oversight and intervention.
  - name: admin-compliance
    description: Admin compliance check management.
  - name: admin-activity
    description: Admin system-wide activity logs.
  - name: admin-webhooks
    description: Admin webhook diagnostics.
  - name: internal
    description: Keystone-internal worker endpoints.
  - name: internal-compliance
    description: Internal compliance engine endpoints.
paths:
  /v1/sessions/{token_id}:
    delete:
      tags:
        - sessions
      summary: Revoke a session token
      description: >-
        Requires the `sessions:write` scope (as an M2M scope or a user
        permission).


        Immediately invalidate a session token before it expires. Revocation is
        scoped to the caller's own environment, matching minting: the caller
        must be acting in the environment the token was minted in (for user
        tokens, the environment selected via the X-Keystone-Environment header).
        Any credential of that environment may revoke, not only the one that
        minted the token. A token minted in any other environment returns 404.
      operationId: revoke_session_v1_sessions__token_id__delete
      parameters:
        - name: token_id
          in: path
          required: true
          schema:
            type: string
            format: uuid
            title: Token Id
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SessionTokenRevokeResponse'
        '404':
          description: Session token not found.
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    SessionTokenRevokeResponse:
      properties:
        revoked:
          type: boolean
          title: Revoked
          default: true
        token_id:
          type: string
          format: uuid
          title: Token Id
      type: object
      required:
        - token_id
      title: SessionTokenRevokeResponse
      description: Response after revoking a session token.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
        code:
          type: string
          enum:
            - VALIDATION_ERROR
          title: Code
        docs_url:
          type: string
          title: Docs Url
          examples:
            - https://docs.keystoneos.xyz/guides/error-codes#validation-error
      type: object
      title: HTTPValidationError
      required:
        - detail
        - code
        - docs_url
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Auth0 JWT access token. See
        [Authentication](/getting-started/authentication) for details.

````