Skip to documentation

API · OAuth grants

Revoke Grant

Revoke an OAuth grant and immediately invalidate its tokens (requires full access). Missing or already revoked grants return 404.

DELETE/oauth/grants/{id}Full access

Request parameters

ParameterTypeDescription
id
path · required
stringResource identifier for id.

Request example

Set OPENSEND_BASE_URL to your API origin and OPENSEND_API_KEY to a full-access key. OAuth tokens with full_access also work.

bash
curl -X DELETE "$OPENSEND_BASE_URL/oauth/grants/YOUR_id" \
  -H "Authorization: Bearer $OPENSEND_API_KEY"

Response

200 · application/json. Example IDs stand for IDs returned by your installation.

json
{
  "object": "oauth_grant",
  "id": "YOUR_ID",
  "revoked_at": "2026-09-29T12:00:00Z",
  "revoked_reason": "revoked_from_api"
}

Behavior and errors

These operations use standard REST authentication, errors, request logging, and team rate limits. Listing returns the paginated object/has_more/data envelope. Grants cover the installation, so resource is null; historical or externally invalidated grants may lack revocation timestamps and reasons.

Revocation returns an oauth_grant object with id, revoked_at, and revoked_reason: "revoked_from_api". Its tokens immediately fail grant validation. Missing, foreign, or already-revoked grants return 404. See the shared REST contract.