Skip to main content
DELETE
Revoke or Delete API Key

Authentication

Requires an API key in the Authorization header.

Request

string
required
The key’s database id, as returned by List API keys. Not the key_prefix.
string
Set to the exact string true to permanently delete the key instead of revoking it. Any other value revokes.

Revoke (soft disable)

Delete (permanent removal)

Response

Or for permanent deletion:
Revocation is immediate - any request using the key returns 401. Permanent deletion removes the key record entirely and cannot be undone.

Permissions

readonly members get 403. A tech member can only revoke their own keys; only a workspace admin can revoke another member’s key. A key that is out of your scope returns 404, the same as an unknown id.

Errors

Errors return the shared envelope with success, result.code, message, and request_id. A legacy error key is included alongside it.