---
title: "POST /api/v1/agent-vault/access-bundles/{accessBundleId}/members/revoke"
method: POST
path: "/api/v1/agent-vault/access-bundles/{accessBundleId}/members/revoke"
tags: ["Agent Vault Access Bundles"]
---

# POST /api/v1/agent-vault/access-bundles/{accessBundleId}/members/revoke

`POST /api/v1/agent-vault/access-bundles/{accessBundleId}/members/revoke`

Revoke an Agent Vault access bundle from users, machine identities or groups

## Path parameters

- `accessBundleId` string, uuid, required

## Request body

- object
  - `userIds` string[] — The IDs of the users to revoke the access bundle from.
  - `machineIdentityIds` string[] — The IDs of the machine identities to revoke the access bundle from.
  - `groupIds` string[] — The IDs of the groups to revoke the access bundle from.

## Response `200`

Default Response

- object
  - `members` object[], required
    - `id` string, uuid, required — The ID of the access bundle membership.
    - `accessBundleId` string, uuid, required — The ID of the access bundle.
    - `createdAt` string, date-time, required — When the access bundle was granted.
    - `actor` union, required
      - object
        - `type` 'user', required — Whether this member is a user, a machine identity or a group.
        - `id` string, uuid, required — The ID of the user, machine identity or group.
      - object
        - `type` 'machineIdentity', required — Whether this member is a user, a machine identity or a group.
        - `id` string, uuid, required — The ID of the user, machine identity or group.
      - object
        - `type` 'group', required — Whether this member is a user, a machine identity or a group.
        - `id` string, uuid, required — The ID of the user, machine identity or group.
  - `skipped` union[], required — The requested grantees who did not have the access bundle, so nothing was revoked.
    - union
      - object
        - `type` 'user', required — Whether this member is a user, a machine identity or a group.
        - `id` string, uuid, required — The ID of the user, machine identity or group.
      - object
        - `type` 'machineIdentity', required — Whether this member is a user, a machine identity or a group.
        - `id` string, uuid, required — The ID of the user, machine identity or group.
      - object
        - `type` 'group', required — Whether this member is a user, a machine identity or a group.
        - `id` string, uuid, required — The ID of the user, machine identity or group.

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

## Changes

- **2026-09-22** `62b0ba9edfe9` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/infisical/apis/infisical-api/changes/api/v1/agent-vault/access-bundles/:accessBundleId/members/revoke/post.md)

---

[API](https://skmtc.dev/infisical/apis/infisical-api.md) · [All operations](https://skmtc.dev/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc.dev/infisical/apis/infisical-api/revisions/8d8e9d059648?raw)
