> ## Documentation Index
> Fetch the complete documentation index at: https://docs.keystoneos.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Revoke session tokens in bulk

> Requires the `sessions:write` scope (as an M2M scope or a user permission).

Revoke every live session token of the caller's environment minted strictly before a cutoff, in one request, for incident response when a backend credential that mints session tokens may have leaked. The cutoff is minted_before, or the moment the request is processed when omitted; a token minted at exactly the cutoff, an expired token and an already revoked token are left as they are. The environment is the credential's own, as for minting: for user tokens the environment selected via the X-Keystone-Environment header. Every affected token is filed in the activity log as a session.revoked entry carrying the operation_id, beside one session.bulk_revoked entry for the operation, and the response carries the count rather than the ids. A retry with the same cutoff revokes nothing more and reports a count of zero. This does not revoke the backend credential itself or stop it minting further tokens; rotate that credential separately. A request the revoked tokens had already authorized before this call is not interrupted. Session tokens cannot revoke session tokens.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/sessions/revoke
openapi: 3.1.0
info:
  title: Keystone API
  description: Settlement orchestration API for tokenized Real-World Assets (RWAs).
  version: 0.9.0
  x-keystone-api-contract-version: 0.9.0
  x-keystone-source-revision: 667abd7797123860730f4713a75eaaed46fcba33
servers:
  - url: https://api-staging.keystoneos.xyz
    description: Staging (sandbox)
  - url: https://api.keystoneos.xyz
    description: Production
security:
  - bearerAuth: []
tags:
  - name: health
    description: Health and version checks.
  - name: platforms
    description: Register and manage your platform profile.
  - name: environments
    description: Manage platform environments (sandbox, production).
  - name: settlement-templates
    description: View and manage settlement templates.
  - name: settlements
    description: Initiate, monitor, and manage settlements.
  - name: sessions
    description: Create and manage browser-safe session tokens for frontend widgets.
  - name: instructions
    description: Submit and manage settlement instructions.
  - name: invitations
    description: Invite team members to your platform.
  - name: members
    description: Manage platform team members and roles.
  - name: webhooks
    description: Configure webhook endpoints for real-time event notifications.
  - name: security
    description: IP allowlisting and API access controls.
  - name: activity
    description: Audit trail of platform actions.
  - name: dashboard
    description: Dashboard metrics and statistics.
  - name: callbacks
    description: Provider callback handlers (internal).
  - name: alchemy-webhooks
    description: Alchemy blockchain event webhooks (internal).
  - name: chains
    description: Supported blockchain networks for settlement.
  - name: admin
    description: KeyStone internal administration endpoints.
  - name: admin-platforms
    description: Admin platform management.
  - name: admin-settlements
    description: Admin settlement oversight and intervention.
  - name: admin-compliance
    description: Admin compliance check management.
  - name: admin-activity
    description: Admin system-wide activity logs.
  - name: admin-webhooks
    description: Admin webhook diagnostics.
  - name: internal
    description: Keystone-internal worker endpoints.
  - name: internal-compliance
    description: Internal compliance engine endpoints.
paths:
  /v1/sessions/revoke:
    post:
      tags:
        - sessions
      summary: Revoke session tokens in bulk
      description: >-
        Requires the `sessions:write` scope (as an M2M scope or a user
        permission).


        Revoke every live session token of the caller's environment minted
        strictly before a cutoff, in one request, for incident response when a
        backend credential that mints session tokens may have leaked. The cutoff
        is minted_before, or the moment the request is processed when omitted; a
        token minted at exactly the cutoff, an expired token and an already
        revoked token are left as they are. The environment is the credential's
        own, as for minting: for user tokens the environment selected via the
        X-Keystone-Environment header. Every affected token is filed in the
        activity log as a session.revoked entry carrying the operation_id,
        beside one session.bulk_revoked entry for the operation, and the
        response carries the count rather than the ids. A retry with the same
        cutoff revokes nothing more and reports a count of zero. This does not
        revoke the backend credential itself or stop it minting further tokens;
        rotate that credential separately. A request the revoked tokens had
        already authorized before this call is not interrupted. Session tokens
        cannot revoke session tokens.
      operationId: revoke_sessions_v1_sessions_revoke_post
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SessionTokenBulkRevoke'
        required: true
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SessionTokenBulkRevokeResponse'
        '403':
          description: >-
            Missing sessions:write (INSUFFICIENT_SCOPES), a session token as the
            caller (SESSION_ESCALATION_DENIED), or no platform or environment
            context.
        '422':
          description: >-
            A minted_before without a timezone offset or in the future, a blank
            or over-long reason, or a field the body does not declare.
components:
  schemas:
    SessionTokenBulkRevoke:
      properties:
        minted_before:
          anyOf:
            - type: string
              format: date-time
            - type: 'null'
          title: Minted Before
          description: >-
            Exclusive cutoff: tokens minted strictly before this instant are
            revoked, one minted at exactly this instant is not. Must carry a
            timezone offset and must not be in the future. Omit it to revoke
            every live token minted before the request itself.
        reason:
          type: string
          maxLength: 500
          minLength: 1
          title: Reason
          description: >-
            Why the tokens are revoked, recorded on the operation's activity
            entry. Surrounding whitespace is trimmed; a blank value is refused.
      additionalProperties: false
      type: object
      required:
        - reason
      title: SessionTokenBulkRevoke
      description: |-
        Request body for revoking the caller's environment's live session
        tokens minted before a cutoff.

        The target is the caller's own environment, taken from the credential;
        the body names no platform or environment, and an unknown field is
        refused rather than ignored: a caller that sent one meant to select a
        target, and revoking the caller's own environment instead would act on
        something it did not ask for.
    SessionTokenBulkRevokeResponse:
      properties:
        operation_id:
          type: string
          format: uuid
          title: Operation Id
          description: >-
            Identifies this operation in the activity log: every affected
            token's entry carries it.
        minted_before:
          type: string
          format: date-time
          title: Minted Before
          description: The exclusive cutoff that was applied, in UTC.
        revoked_at:
          type: string
          format: date-time
          title: Revoked At
          description: The instant every affected token was revoked at, in UTC.
        revoked_count:
          type: integer
          minimum: 0
          title: Revoked Count
          description: >-
            How many tokens this operation revoked. A retry with the same cutoff
            reports only what it changed.
      type: object
      required:
        - operation_id
        - minted_before
        - revoked_at
        - revoked_count
      title: SessionTokenBulkRevokeResponse
      description: |-
        What one bulk revocation did. The affected token ids are not listed
        here: they are filed as activity entries under the operation id, one per
        token, so the response stays bounded whatever the count.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Auth0 JWT access token. See
        [Authentication](/getting-started/authentication) for details.

````