const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({reason: '<string>', minted_before: '2023-11-07T05:31:56Z'})
};
fetch('https://api-staging.keystoneos.xyz/v1/sessions/revoke', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api-staging.keystoneos.xyz/v1/sessions/revoke"
payload = {
"reason": "<string>",
"minted_before": "2023-11-07T05:31:56Z"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)curl --request POST \
--url https://api-staging.keystoneos.xyz/v1/sessions/revoke \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"reason": "<string>",
"minted_before": "2023-11-07T05:31:56Z"
}
'{
"operation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"minted_before": "2023-11-07T05:31:56Z",
"revoked_at": "2023-11-07T05:31:56Z",
"revoked_count": 1
}Revoke session tokens in bulk
Requires the sessions:write scope (as an M2M scope or a user permission).
Revoke every live session token of the caller’s environment minted strictly before a cutoff, in one request, for incident response when a backend credential that mints session tokens may have leaked. The cutoff is minted_before, or the moment the request is processed when omitted; a token minted at exactly the cutoff, an expired token and an already revoked token are left as they are. The environment is the credential’s own, as for minting: for user tokens the environment selected via the X-Keystone-Environment header. Every affected token is filed in the activity log as a session.revoked entry carrying the operation_id, beside one session.bulk_revoked entry for the operation, and the response carries the count rather than the ids. A retry with the same cutoff revokes nothing more and reports a count of zero. This does not revoke the backend credential itself or stop it minting further tokens; rotate that credential separately. A request the revoked tokens had already authorized before this call is not interrupted. Session tokens cannot revoke session tokens.
const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({reason: '<string>', minted_before: '2023-11-07T05:31:56Z'})
};
fetch('https://api-staging.keystoneos.xyz/v1/sessions/revoke', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api-staging.keystoneos.xyz/v1/sessions/revoke"
payload = {
"reason": "<string>",
"minted_before": "2023-11-07T05:31:56Z"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)curl --request POST \
--url https://api-staging.keystoneos.xyz/v1/sessions/revoke \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"reason": "<string>",
"minted_before": "2023-11-07T05:31:56Z"
}
'{
"operation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"minted_before": "2023-11-07T05:31:56Z",
"revoked_at": "2023-11-07T05:31:56Z",
"revoked_count": 1
}Authorizations
Auth0 JWT access token. See Authentication for details.
Body
Request body for revoking the caller's environment's live session tokens minted before a cutoff.
The target is the caller's own environment, taken from the credential; the body names no platform or environment, and an unknown field is refused rather than ignored: a caller that sent one meant to select a target, and revoking the caller's own environment instead would act on something it did not ask for.
Why the tokens are revoked, recorded on the operation's activity entry. Surrounding whitespace is trimmed; a blank value is refused.
1 - 500Exclusive cutoff: tokens minted strictly before this instant are revoked, one minted at exactly this instant is not. Must carry a timezone offset and must not be in the future. Omit it to revoke every live token minted before the request itself.
Response
Successful Response
What one bulk revocation did. The affected token ids are not listed here: they are filed as activity entries under the operation id, one per token, so the response stays bounded whatever the count.
Identifies this operation in the activity log: every affected token's entry carries it.
The exclusive cutoff that was applied, in UTC.
The instant every affected token was revoked at, in UTC.
How many tokens this operation revoked. A retry with the same cutoff reports only what it changed.
x >= 0