---
title: "Revoke OAuth grant"
method: POST
path: "/oauth-grants/{grant_id}:revoke"
tags: ["OAuth"]
---

# Revoke OAuth grant

`POST /oauth-grants/{grant_id}:revoke`

Revoke a consent→agent grant — one of the three revocation kill radii.

Allowed for the grant's owner (the consenting user) or an admin. Marks
the grant ``revoked`` and revokes every outstanding access/refresh token
minted under it in the same transaction; the live resolvers also re-check
grant status on every verdict (belt + braces). The client's next token
use or refresh fails closed. Idempotent on an already-revoked grant.

## Path parameters

- `grant_id` string, required

## Response `204`

Successful Response

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-09-01** `dceddff07ff7` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/oauth-grants/:grant_id:revoke/post.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc.dev/jentic/apis/jentic-control-plane-api/revisions/e4688b93dfc7?raw)
