> ## Documentation Index
> Fetch the complete documentation index at: https://developers.authlete.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Backchannel Logout Token Issuing

> The `/backchannel/logout/token` API issues a logout token for a client application in the context of [OpenID Connect Back-Channel Logout 1.0](https://openid.net/specs/openid-connect-backchannel-1_0.html).

<Accordion title="Full description" defaultOpen={false}>
  The caller provides a client identifier and either a subject, a session ID, or both.
  Authlete generates a logout token that the caller should then POST to the client's
  registered `backchannelLogoutUri`.

  A response from the `/backchannel/logout/token` API contains an `action` response
  parameter. The possible values are:

  ## OK

  When the action is `OK`, it indicates that the API call completed successfully and
  a logout token has been issued. The caller should deliver `logoutToken` to
  `backchannelLogoutUri`.

  ## SERVER\_ERROR

  When the action is `SERVER_ERROR`, it indicates that something has gone wrong on
  the Authlete side.

  ## CALLER\_ERROR

  When the action is `CALLER_ERROR`, it indicates that the API call contained a
  problem. For example, the call may have been missing required request parameters.
</Accordion>


## OpenAPI

````yaml https://spec.speakeasy.com/authlete/sdk-workspace/authlete-api-explorer-with-code-samples post /api/{serviceId}/backchannel/logout/token
openapi: 3.0.3
info:
  title: Authlete API
  description: ''
  version: 3.0.16
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
  - description: 🇺🇸 US Cluster
    url: https://us.authlete.com
  - description: 🇯🇵 Japan Cluster
    url: https://jp.authlete.com
  - description: 🇪🇺 Europe Cluster
    url: https://eu.authlete.com
  - description: 🇧🇷 Brazil Cluster
    url: https://br.authlete.com
security:
  - bearer: []
tags:
  - name: Service Management
    description: >-
      API endpoints for managing services, including creation, update, and
      deletion of services.
    x-tag-expanded: false
  - name: Client Management
    description: >-
      API endpoints for managing OAuth clients, including creation, update, and
      deletion of clients.
    x-tag-expanded: false
  - name: Authorization Endpoint
    description: API endpoints for implementing OAuth 2.0 Authorization Endpoint.
    x-tag-expanded: false
  - name: Pushed Authorization Endpoint
    description: >-
      API endpoints for implementing OAuth 2.0 Pushed Authorization Requests
      (PAR).
    x-tag-expanded: false
  - name: Token Endpoint
    description: API endpoints for implementing OAuth 2.0 Token Endpoint.
    x-tag-expanded: false
  - name: Token Operations
    description: >-
      API endpoints for various token related operations, including creating,
      revoking and deleting access_tokens with specified scopes.
    x-tag-expanded: false
  - name: Introspection Endpoint
    description: API endpoints for implementing OAuth 2.0 Introspection Endpoint.
    x-tag-expanded: false
  - name: Revocation Endpoint
    description: API endpoint for implementing OAuth 2.0 Revocation Endpoint.
    x-tag-expanded: false
  - name: UserInfo Endpoint
    description: API endpoints for implementing OpenID Connect UserInfo Endpoint.
    x-tag-expanded: false
  - name: JWK Set Endpoint
    description: API endpoints for to generate JSON Web Key Set (JWKS) for a service.
    x-tag-expanded: false
  - name: Discovery Endpoint
    description: API endpoints for implementing OpenID Connect Discovery.
    x-tag-expanded: false
  - name: Configuration Endpoint
    description: API endpoint for accessing configuration settings for a service.
    x-tag-expanded: false
  - name: Dynamic Client Registration
    description: API endpoints for implementing OAuth 2.0 Dynamic Client Registration.
    x-tag-expanded: false
  - name: CIBA
    description: >-
      API endpoints for implementing Client-Initiated Backchannel Authentication
      (CIBA).
    x-tag-expanded: false
  - name: Grant Management Endpoint
    description: >-
      API endpoint for implementing OAuth 2.0 grants, including grant management
      actions like updating and revoking grants.
    x-tag-expanded: false
  - name: Jose Object
    description: API endpoints for JOSE objects.
    x-tag-expanded: false
  - name: Device Flow
    description: API endpoints for implementing OAuth 2.0 Device Flow
    x-tag-expanded: false
  - name: Federation Endpoint
    description: API endpoints for implementing OpenID Federation using Authlete.
    x-tag-expanded: false
  - name: Verifiable Credential Issuer
    description: >-
      API endpoints for implementing and running a Verifiable Credential Issuer
      (VCI).
    x-tag-expanded: false
  - name: Hardware Security Key
    description: API endpoints for managing hardware security keys (HSK).
    x-tag-expanded: false
  - name: Utility Endpoints
    description: API endpoints for various utility operations.
    x-tag-expanded: false
  - name: Native SSO
    description: API endpoints for Native SSO
    x-tag-expanded: false
  - name: Audit Logs
    description: >-
      API endpoints for retrieving audit logs, hosted on the Authlete IdP
      server.
    x-tag-expanded: false
paths:
  /api/{serviceId}/backchannel/logout/token:
    post:
      tags:
        - Back-Channel Logout
      summary: Backchannel Logout Token Issuing
      description: >
        The `/backchannel/logout/token` API issues a logout token for a client
        application

        in the context of [OpenID Connect Back-Channel Logout
        1.0](https://openid.net/specs/openid-connect-backchannel-1_0.html).
      operationId: backchannel_logout_token_api
      parameters:
        - in: path
          name: serviceId
          description: A service ID.
          schema:
            type: string
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/backchannel_logout_token_request'
            example:
              clientIdentifier: '1140735077'
              subject: user123
              sessionId: my-sid
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/backchannel_logout_token_response'
              example:
                action: OK
                logoutToken: eyJhbGciOiJSUzI1NiJ9...
                backchannelLogoutUri: https://client.example.com/logout
                resultCode: A504001
                resultMessage: >-
                  [A504001] The backchannel logout token was successfully
                  issued.
          links:
            authz_process:
              $ref: '#/components/links/authz_process'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
      x-codeSamples:
        - lang: typescript
          label: Typescript (SDK)
          source: |-
            import { Authlete } from "@authlete/typescript-sdk";

            const authlete = new Authlete({
              bearer: process.env["AUTHLETE_BEARER"] ?? "",
            });

            async function run() {
              const result = await authlete.backChannelLogout.backchannelLogoutTokenApi({
                serviceId: "<id>",
                backchannelLogoutTokenRequest: {
                  clientIdentifier: "1140735077",
                  subject: "user123",
                  sessionId: "my-sid",
                },
              });

              console.log(result);
            }

            run();
components:
  schemas:
    backchannel_logout_token_request:
      type: object
      required:
        - clientIdentifier
      properties:
        clientIdentifier:
          type: string
          description: >
            The identifier of the client application. Either a client ID or a
            client

            alias.
        subject:
          type: string
          description: >
            The subject (end-user) identifier. The logout token will be issued
            for

            this subject. At least one of `subject` or `sessionId` must be
            provided.
        sessionId:
          type: string
          description: >
            The session ID (`sid`) identifying the user session to log out. At
            least

            one of `subject` or `sessionId` must be provided.
    backchannel_logout_token_response:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
        action:
          type: string
          enum:
            - OK
            - SERVER_ERROR
            - CALLER_ERROR
          description: |
            The next action that the API caller should take.
        logoutToken:
          type: string
          description: >
            The logout token issued for the client. The caller should deliver
            this

            token to the client's `backchannelLogoutUri`.
        backchannelLogoutUri:
          type: string
          description: |
            The backchannel logout URI of the client. The caller should POST the
            `logoutToken` to this URI.
    result:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
  responses:
    '400':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001201
            resultMessage: '[A001201] /auth/authorization, TLS must be used.'
    '401':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001202
            resultMessage: '[A001202] /auth/authorization, Authorization header is missing.'
    '403':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001215
            resultMessage: >-
              [A001215] /auth/authorization, The client (ID = 26837717140341) is
              locked.
    '429':
      description: The request exceeded the request rate permitted for the endpoint.
      headers:
        Retry-After:
          description: The number of seconds to wait before retrying the request.
          schema:
            type: integer
            example: 1
        RateLimit-Remaining:
          description: The number of requests remaining in the next second.
          schema:
            type: integer
            example: 10
        RateLimit-Reset:
          description: >-
            The number of seconds to wait before the request rate is fully
            replenished.
          schema:
            type: integer
            example: 1
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001311
            resultMessage: >-
              [A001311] /auth/authorization,  Too many requests, retry after 1
              seconds. (Entity: 23769878923/87122303)
    '500':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001101
            resultMessage: '[A001101] /auth/authorization, Authlete Server error.'
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Authenticate every request with a **Service Access Token** or
        **Organization Token**.

        Set the token value in the `Authorization: Bearer <token>` header.


        **Service Access Token**: Scoped to a single service. Use when
        automating service-level configuration or runtime flows.


        **Organization Token**: Scoped to the organization; inherits permissions
        across services. Use for org-wide automation or when managing multiple
        services programmatically.


        Both token types are issued by the Authlete console or provisioning
        APIs.

````