> ## Documentation Index
> Fetch the complete documentation index at: https://developers.authlete.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Process Revocation Request

> This API revokes access tokens and refresh tokens.

<Accordion title="Full description" defaultOpen={false}>
  This API is supposed to be called from within the implementation of the revocation endpoint ([RFC
  7009](tools.ietf.org/html/rfc7009)) of the authorization server implementation in order to revoke
  access tokens and refresh tokens.
  The response from `/auth/revocation` API has some parameters. Among them, it is `action` parameter
  that the authorization server implementation should check first because it denotes the next action
  that the authorization server implementation should take. According to the value of `action`, the
  authorization server implementation must take the steps described below.

  ## INTERNAL\_SERVER\_ERROR

  When the value of `action` is `INTERNAL_SERVER_ERROR`, it means that the request from the authorization
  server implementation was wrong or that an error occurred in Authlete.
  In either case, from the viewpoint of the client application, it is an error on the server side.
  Therefore, the service implementation should generate a response to the client application with
  HTTP status of "500 Internal Server Error".
  The value of `responseContent` is a JSON string which describes the error, so it can be
  used as the entity body of the response.

  ***

  The following illustrates the response which the service implementation should generate and return
  to the client application.

  ```
  HTTP/1.1 500 Internal Server Error
  Content-Type: application/json
  Cache-Control: no-store
  Pragma: no-cache
  &#123;responseContent&#125;
  ```

  ## INVALID\_CLIENT

  When the value of `action` is `INVALID_CLIENT`, it means that authentication of the client failed.
  In this case, the HTTP status of the response to the client application is either "400 Bad Request"
  or "401 Unauthorized".     The description about `invalid_client` shown below is an excerpt from [RFC
  6749](https://datatracker.ietf.org/doc/html/rfc6749).

  ***

  Client authentication failed (e.g., unknown client, no client authentication included, or unsupported
  authentication method). The authorization server MAY return an HTTP 401 (Unauthorized) status code
  to indicate which HTTP authentication schemes are supported. If the client attempted to authenticate
  via the `Authorization` request header field, the authorization server MUST respond with an HTTP
  401 (Unauthorized) status code and include the `WWW-Authenticate` response header field matching
  the authentication scheme used by the client.

  ***

  In either case, the value of `responseContent` is a JSON string which can be used as the entity
  body of the response to the client application.

  ***

  The following illustrates the response which the service implementation should generate and return
  to the client application.

  ```
  HTTP/1.1 400 Bad Request
  Content-Type: application/json
  Cache-Control: no-store
  Pragma: no-cache
  &#123;responseContent&#125;
  ```

  ```
  HTTP/1.1 401 Unauthorized
  WWW-Authenticate: &#123;challenge&#125;
  Content-Type: application/json
  Cache-Control: no-store
  Pragma: no-cache
  &#123;responseContent&#125;
  ```

  ## BAD\_REQUEST

  When the value of `action` is `BAD_REQUEST`, it means that the request from the client application
  is invalid.
  The HTTP status of the response returned to the client application must be "400 Bad Request" and
  the content type must be `application/json`. [RFC 7009](https://datatracker.ietf.org/doc/html/rfc7009),
  [2.2.1. Error Respons](https://datatracker.ietf.org/doc/html/rfc7009#section-2.2.1) states "The
  error presentation conforms to the definition in [Section 5.2](https://datatracker.ietf.org/doc/html/rfc6749#section-5.2)
  of \[[RFC 6749](https://datatracker.ietf.org/doc/html/rfc6749)]."
  The value of `responseContent` is a JSON string which describes the error, so it can be used
  as the entity body of the response.

  ***

  The following illustrates the response which the authorization server implementation should generate
  and return to the client application.

  ```
  HTTP/1.1 400 Bad Request
  Content-Type: application/json
  Cache-Control: no-store
  Pragma: no-cache
  &#123;responseContent&#125;
  ```

  ## OK

  When the value of `action` is `OK`, it means that the request from the client application is valid
  and the presented token has been revoked successfully or if the client submitted an invalid token.
  Note that invalid tokens do not cause an error. See [2.2. Revocation Response](https://datatracker.ietf.org/doc/html/rfc7009#section-2.2) for details.
  The HTTP status of the response returned to the client application must be 200 OK.
  If the original request from the client application contains callback request parameter and its
  value is not empty, the content type should be `application/javascript` and the content should be
  a JavaScript snippet for JSONP.
  The value of `responseContent` is JavaScript snippet if the original request from the client application
  contains callback request parameter and its value is not empty. Otherwise, the value of `responseContent`
  is `null`.

  ```
  HTTP/1.1 200 OK
  Content-Type: application/javascript
  Cache-Control: no-store
  Pragma: no-cache
  &#123;responseContent&#125;
  ```
</Accordion>


## OpenAPI

````yaml https://spec.speakeasy.com/authlete/sdk-workspace/authlete-api-explorer-with-code-samples post /api/{serviceId}/auth/revocation
openapi: 3.0.3
info:
  title: Authlete API
  description: ''
  version: 3.0.16
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
  - description: 🇺🇸 US Cluster
    url: https://us.authlete.com
  - description: 🇯🇵 Japan Cluster
    url: https://jp.authlete.com
  - description: 🇪🇺 Europe Cluster
    url: https://eu.authlete.com
  - description: 🇧🇷 Brazil Cluster
    url: https://br.authlete.com
security:
  - bearer: []
tags:
  - name: Service Management
    description: >-
      API endpoints for managing services, including creation, update, and
      deletion of services.
    x-tag-expanded: false
  - name: Client Management
    description: >-
      API endpoints for managing OAuth clients, including creation, update, and
      deletion of clients.
    x-tag-expanded: false
  - name: Authorization Endpoint
    description: API endpoints for implementing OAuth 2.0 Authorization Endpoint.
    x-tag-expanded: false
  - name: Pushed Authorization Endpoint
    description: >-
      API endpoints for implementing OAuth 2.0 Pushed Authorization Requests
      (PAR).
    x-tag-expanded: false
  - name: Token Endpoint
    description: API endpoints for implementing OAuth 2.0 Token Endpoint.
    x-tag-expanded: false
  - name: Token Operations
    description: >-
      API endpoints for various token related operations, including creating,
      revoking and deleting access_tokens with specified scopes.
    x-tag-expanded: false
  - name: Introspection Endpoint
    description: API endpoints for implementing OAuth 2.0 Introspection Endpoint.
    x-tag-expanded: false
  - name: Revocation Endpoint
    description: API endpoint for implementing OAuth 2.0 Revocation Endpoint.
    x-tag-expanded: false
  - name: UserInfo Endpoint
    description: API endpoints for implementing OpenID Connect UserInfo Endpoint.
    x-tag-expanded: false
  - name: JWK Set Endpoint
    description: API endpoints for to generate JSON Web Key Set (JWKS) for a service.
    x-tag-expanded: false
  - name: Discovery Endpoint
    description: API endpoints for implementing OpenID Connect Discovery.
    x-tag-expanded: false
  - name: Configuration Endpoint
    description: API endpoint for accessing configuration settings for a service.
    x-tag-expanded: false
  - name: Dynamic Client Registration
    description: API endpoints for implementing OAuth 2.0 Dynamic Client Registration.
    x-tag-expanded: false
  - name: CIBA
    description: >-
      API endpoints for implementing Client-Initiated Backchannel Authentication
      (CIBA).
    x-tag-expanded: false
  - name: Grant Management Endpoint
    description: >-
      API endpoint for implementing OAuth 2.0 grants, including grant management
      actions like updating and revoking grants.
    x-tag-expanded: false
  - name: Jose Object
    description: API endpoints for JOSE objects.
    x-tag-expanded: false
  - name: Device Flow
    description: API endpoints for implementing OAuth 2.0 Device Flow
    x-tag-expanded: false
  - name: Federation Endpoint
    description: API endpoints for implementing OpenID Federation using Authlete.
    x-tag-expanded: false
  - name: Verifiable Credential Issuer
    description: >-
      API endpoints for implementing and running a Verifiable Credential Issuer
      (VCI).
    x-tag-expanded: false
  - name: Hardware Security Key
    description: API endpoints for managing hardware security keys (HSK).
    x-tag-expanded: false
  - name: Utility Endpoints
    description: API endpoints for various utility operations.
    x-tag-expanded: false
  - name: Native SSO
    description: API endpoints for Native SSO
    x-tag-expanded: false
paths:
  /api/{serviceId}/auth/revocation:
    post:
      tags:
        - Revocation Endpoint
      summary: Process Revocation Request
      description: |
        This API revokes access tokens and refresh tokens.
      operationId: auth_revocation_api
      parameters:
        - in: path
          name: serviceId
          description: A service ID.
          schema:
            type: string
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/revocation_request'
            example:
              parameters: >-
                VFGsNK-5sXiqterdaR7b5QbRX9VTwVCQB87jbr2_xAI&token_type_hint=access_token
              clientId: '26478243745571'
              clientSecret: >-
                gXz97ISgLs4HuXwOZWch8GEmgL4YMvUJwu3er_kDVVGcA0UOhA9avLPbEmoeZdagi9yC_-tEiT2BdRyH9dbrQQ
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/revocation_request'
      responses:
        '200':
          description: Token revoked successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/revocation_response'
              example:
                resultCode: A113001
                resultMessage: '[A113001] The token has been revoked successfully.'
                action: OK
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '500':
          $ref: '#/components/responses/500'
      x-codeSamples:
        - lang: typescript
          label: Typescript (SDK)
          source: |-
            import { Authlete } from "@authlete/typescript-sdk";

            const authlete = new Authlete({
              bearer: process.env["AUTHLETE_BEARER"] ?? "",
            });

            async function run() {
              const result = await authlete.revocation.process({
                serviceId: "<id>",
                revocationRequest: {
                  parameters: "VFGsNK-5sXiqterdaR7b5QbRX9VTwVCQB87jbr2_xAI&token_type_hint=access_token",
                  clientId: "26478243745571",
                  clientSecret: "gXz97ISgLs4HuXwOZWch8GEmgL4YMvUJwu3er_kDVVGcA0UOhA9avLPbEmoeZdagi9yC_-tEiT2BdRyH9dbrQQ",
                },
              });

              console.log(result);
            }

            run();
        - lang: ruby
          label: Ruby (SDK)
          source: >-
            require 'authlete_ruby_sdk'


            Models = ::Authlete::Models

            s = ::Authlete::Client.new(
              bearer: '<YOUR_BEARER_TOKEN_HERE>'
            )

            res = s.revocation.process_request(service_id: '<id>',
            revocation_request: Models::Components::RevocationRequest.new(
              parameters: 'VFGsNK-5sXiqterdaR7b5QbRX9VTwVCQB87jbr2_xAI&token_type_hint=access_token',
              client_id: '26478243745571',
              client_secret: 'gXz97ISgLs4HuXwOZWch8GEmgL4YMvUJwu3er_kDVVGcA0UOhA9avLPbEmoeZdagi9yC_-tEiT2BdRyH9dbrQQ'
            ))


            unless res.revocation_response.nil?
              # handle response
            end
        - lang: go
          label: Go (SDK)
          source: "package main\n\nimport(\n\t\"context\"\n\t\"os\"\n\tauthlete \"github.com/authlete/authlete-go-sdk\"\n\t\"github.com/authlete/authlete-go-sdk/models/components\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := authlete.New(\n        authlete.WithSecurity(os.Getenv(\"AUTHLETE_BEARER\")),\n    )\n\n    res, err := s.Revocation.Process(ctx, \"<id>\", components.RevocationRequest{\n        Parameters: \"VFGsNK-5sXiqterdaR7b5QbRX9VTwVCQB87jbr2_xAI&token_type_hint=access_token\",\n        ClientID: authlete.Pointer(\"26478243745571\"),\n        ClientSecret: authlete.Pointer(\"gXz97ISgLs4HuXwOZWch8GEmgL4YMvUJwu3er_kDVVGcA0UOhA9avLPbEmoeZdagi9yC_-tEiT2BdRyH9dbrQQ\"),\n    })\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.RevocationResponse != nil {\n        // handle response\n    }\n}"
      x-code-samples:
        - lang: shell
          label: curl
          source: >
            curl -v -X POST
            https://us.authlete.com/api/21653835348762/auth/revocation \

            -H 'Content-Type:application/json' \

            -H 'Authorization: Bearer
            V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F' \

            -d '{ "parameters":
            "token=VFGsNK-5sXiqterdaR7b5QbRX9VTwVCQB87jbr2_xAI&token_type_hint=access_token",
            "clientId": "26478243745571", "clientSecret":
            "gXz97ISgLs4HuXwOZWch8GEmgL4YMvUJwu3er_kDVVGcA0UOhA9avLPbEmoeZdagi9yC_-tEiT2BdRyH9dbrQQ"
            }'
        - lang: java
          label: java
          source: |
            AuthleteConfiguration conf = ...;
            AuthleteApi api = AuthleteApiFactory.create(conf);

            RevocationRequest req = new RevocationRequest();
            request.setParameters(...);

            api.revocation(req);
        - lang: python
          source: |
            conf = ...
            api = AuthleteApiImpl(conf)

            req = RevocationRequest()
            req.parameters = ...

            api.revocation(req)
components:
  schemas:
    revocation_request:
      type: object
      required:
        - parameters
      properties:
        parameters:
          type: string
          description: >
            OAuth 2.0 token revocation request parameters which are the request
            parameters that the OAuth 2.0 token revocation endpoint

            ([RFC 7009](https://datatracker.ietf.org/doc/html/rfc7009)) of the
            authorization server implementation received from the

            client application.


            The value of parameters is the entire entity body (which is
            formatted in `application/x-www-form-urlencoded`) of the request

            from the client application.
        clientId:
          type: string
          description: >
            The client ID extracted from `Authorization` header of the
            revocation request from the client application.


            If the revocation endpoint of the authorization server
            implementation supports Basic Authentication

            as a means of client authentication, and the request from the client
            application contains its client ID in

            `Authorization` header, the value should be extracted and set to
            this parameter.
        clientSecret:
          type: string
          description: >
            The client secret extracted from `Authorization` header of the
            revocation request from the client application.


            If the revocation endpoint of the authorization server
            implementation supports basic authentication as a means of

            client authentication, and the request from the client application
            contained its client secret in `Authorization` header,

            the value should be extracted and set to this parameter.
        clientCertificate:
          type: string
          description: >
            The client certificate used in the TLS connection between the client
            application and the revocation endpoint.
        clientCertificatePath:
          type: array
          items:
            type: string
          description: >
            The certificate path presented by the client during client
            authentication.
        oauthClientAttestation:
          type: string
          description: >
            The value of the `OAuth-Client-Attestation` HTTP header, which is
            defined in the specification

            of [OAuth 2.0 Attestation-Based Client
            Authentication](https://datatracker.ietf.org/doc/draft-ietf-oauth-attestation-based-client-auth/).
        oauthClientAttestationPop:
          type: string
          description: >
            The value of the `OAuth-Client-Attestation-PoP` HTTP header, which
            is defined in the specification

            of [OAuth 2.0 Attestation-Based Client
            Authentication](https://datatracker.ietf.org/doc/draft-ietf-oauth-attestation-based-client-auth/).
    revocation_response:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
        action:
          type: string
          enum:
            - INTERNAL_SERVER_ERROR
            - INVALID_CLIENT
            - BAD_REQUEST
            - OK
          description: >-
            The next action that the authorization server implementation should
            take.
        responseContent:
          type: string
          description: >
            The content that the authorization server implementation is to
            return to the client application.

            Its format varies depending on the value of `action` parameter.
    result:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
  responses:
    '400':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001201
            resultMessage: '[A001201] /auth/authorization, TLS must be used.'
    '401':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001202
            resultMessage: '[A001202] /auth/authorization, Authorization header is missing.'
    '403':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001215
            resultMessage: >-
              [A001215] /auth/authorization, The client (ID = 26837717140341) is
              locked.
    '500':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001101
            resultMessage: '[A001101] /auth/authorization, Authlete Server error.'
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Authenticate every request with a **Service Access Token** or
        **Organization Token**.

        Set the token value in the `Authorization: Bearer <token>` header.


        **Service Access Token**: Scoped to a single service. Use when
        automating service-level configuration or runtime flows.


        **Organization Token**: Scoped to the organization; inherits permissions
        across services. Use for org-wide automation or when managing multiple
        services programmatically.


        Both token types are issued by the Authlete console or provisioning
        APIs.

````