Revoke an API key
DELETE
/api-keys/{id}
Revokes one of the caller's own keys. Takes effect immediately. A key that belongs to someone else, does not exist, or is already revoked answers 404.
Requires a signed-in session: a request authenticated with an API key, or made while an administrator is viewing the account as its owner, answers 403.
Authorizations
BearerAuth
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Type
HTTP (bearer)
Parameters
Path Parameters
id*
Type
Requiredstring
Format
"uuid"Responses
Key revoked
application/json
JSON
{
"message": "string",
"id": "string"
}