Skip to main content
POST
Revoke session tokens in bulk

Authorizations

Authorization
string
header
required

Auth0 JWT access token. See Authentication for details.

Body

application/json

Request body for revoking the caller's environment's live session tokens minted before a cutoff.

The target is the caller's own environment, taken from the credential; the body names no platform or environment, and an unknown field is refused rather than ignored: a caller that sent one meant to select a target, and revoking the caller's own environment instead would act on something it did not ask for.

reason
string
required

Why the tokens are revoked, recorded on the operation's activity entry. Surrounding whitespace is trimmed; a blank value is refused.

Required string length: 1 - 500
minted_before
string<date-time> | null

Exclusive cutoff: tokens minted strictly before this instant are revoked, one minted at exactly this instant is not. Must carry a timezone offset and must not be in the future. Omit it to revoke every live token minted before the request itself.

Response

Successful Response

What one bulk revocation did. The affected token ids are not listed here: they are filed as activity entries under the operation id, one per token, so the response stays bounded whatever the count.

operation_id
string<uuid>
required

Identifies this operation in the activity log: every affected token's entry carries it.

minted_before
string<date-time>
required

The exclusive cutoff that was applied, in UTC.

revoked_at
string<date-time>
required

The instant every affected token was revoked at, in UTC.

revoked_count
integer
required

How many tokens this operation revoked. A retry with the same cutoff reports only what it changed.

Required range: x >= 0