Skip to content
/oauth/revoke

Revoke a refresh token (RFC 7009) — 'Disconnect'

Revokes the presented refresh token and its whole rotation family. Always returns 200 per RFC 7009.

free

Parameters

NameInRequiredDefaultAllowedDescriptionExample
tokenbodyrequiredThe refresh token to revoke.<refresh token>

Response schema

FieldTypeNullableDescription
(empty body)nonenoHTTP 200 with an EMPTY body, always (RFC 7009) — the endpoint never reveals whether the token existed or was owned by the caller (no oracle). If the token and its client match a live rotation family, that family is revoked; otherwise the call is a no-op. There is no JSON response payload.

Errors

StatusLabelDescription
200OKRequest succeeded.
400Bad RequestInvalid query, body, or path parameter.
401UnauthorizedMissing or invalid Authorization header / api_Token.
402Payment RequiredInsufficient token balance for this call. Top up
429Too Many RequestsRate limit exceeded for your tier (see /pricing for tier limits). Tier limits
500Server ErrorUnexpected server-side failure. Retry with backoff; report if persistent.

Code samples

curl -X POST "https://api.finradar.ai/oauth/revoke" \
  -H "Authorization: Bearer YOUR_JWT_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "token": "<refresh token>"
}'

Generate an API key in /account/credentials to run live queries (literal YOUR_API_KEY placeholder shown until then).