Invalidate all previously issued authentication tokens for the user including active browser sessions and long-lived development tokens. If the user has active sessions in a browser, this will force re-authentication.
Previously issued authentication tokens may not appear as explicitly revoked but they will not be considered valid when used to authenticate requests. The invalidation may not take effect immediately, but will take effect within a couple of minutes.
The caller must have permission to manage users for the target user's organization.
Third-party applications using this endpoint via OAuth2 must request the following operation scope: api:admin-write.
1
2
3
curl -X POST \
\t-H "Authorization: Bearer $TOKEN" \
"https://$HOSTNAME/api/v2/admin/users/dd05feb8-662a-445d-8f4c-ce92d46bedeb/revokeAllTokens"| Error Name | ||
|---|---|---|
User | Error Code | INVALID_ARGUMENT |
| Status Code | 400 | |
| Description | The user is deleted. | |
| Parameters | principalId | |
Revoke | Error Code | PERMISSION_DENIED |
| Status Code | 403 | |
| Description | Could not revokeAllTokens the User. | |
| Parameters | userId | |
User | Error Code | NOT_FOUND |
| Status Code | 404 | |
| Description | The given User could not be found. | |
| Parameters | userId | |
See Errors for a general overview of errors in the platform.