Credentials
Revoke a credential
Permanently revoke an issued credential. Sets its status to revoked and flips its bit in the tenant's IETF Token Status List, so any verifier that fetches the status list will reject it from this point on. Revocation is final — unlike suspension it cannot be reversed by reactivation. Takes no request body. The credential must belong to the authenticated tenant; otherwise the request returns 404. Requires Authorization: Bearer <tenant API key>.
post/v1/credentials/{uuid}/revoke
Path parameters
uuidstring uuid required
UUID of the issued credential to revoke. Must belong to the authenticated tenant; otherwise the request returns 404.
Response
The credential was revoked. Returns the updated issued-credential record with status revoked.
Example response
{
"uuid": "c1d2e3f4-5a6b-4c7d-8e9f-0a1b2c3d4e5f",
"vct": "https://acme-air.didit.me/credentials/loyalty-membership",
"iss": "https://acme-air.didit.me",
"status": "revoked",
"status_idx": 4213,
"issued_at": "2026-06-30T12:00:00+00:00",
"expires_at": "2027-06-30T12:00:00+00:00",
"holder_cnf": {
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "f83OJ3D2xF1Bg8vub9tLe1gHMzV76e8Tus9uPHvRVEU",
"y": "x_FEzRu9m36HLN_tue659LNpXW6pCyStikYjKIWI5a0"
}
},
"source_session_id": "11111111-2222-3333-4444-555555555555"
}