Skip to content

Revoke an API key​

DELETE
/api-keys/{id}

Revokes one of the caller's own keys. Takes effect immediately. A key that belongs to someone else, does not exist, or is already revoked answers 404.

Requires a signed-in session: a request authenticated with an API key, or made while an administrator is viewing the account as its owner, answers 403.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Parameters​

Path Parameters

id*
Type
string
Required
Format
"uuid"

Responses​

Key revoked

application/json
JSON
{
"message": "string",
"id": "string"
}

Playground​

Server
Authorization
Variables
Key
Value

Samples​

Powered by VitePress OpenAPI

Built with VitePress