---
title: "Revoke User Sessions"
method: POST
path: "/api/admin/users/{user_id}/revoke-sessions"
tags: ["admin"]
---

# Revoke User Sessions

`POST /api/admin/users/{user_id}/revoke-sessions`

Bump ``users.session_version`` to invalidate the user's active JWTs.

Platform-admin only. Used for incident response when WorkOS Directory
Sync can't deliver fast enough — phished credentials, urgent offboard,
customer security request, etc. The next request from any of the user's
sessions will fail with ``session_revoked``; they can re-authenticate
immediately to mint a fresh token.

## Path parameters

- `user_id` integer, required

## Response `204`

Successful Response

## Other responses

- `422` — Validation Error

## Changes

- **2026-09-18** `abf76937a751` — 2 info
  - added the optional property `detail/items/ctx` to the response with the `422` status
  - added the optional property `detail/items/input` to the response with the `422` status

[Change history](https://skmtc.dev/quadrillion/apis/quadrillion-cloud-api/changes/api/admin/users/:user_id/revoke-sessions/post.md)

---

[API](https://skmtc.dev/quadrillion/apis/quadrillion-cloud-api.md) · [All operations](https://skmtc.dev/quadrillion/apis/quadrillion-cloud-api/llms.txt) · [OpenAPI document](https://skmtc.dev/quadrillion/apis/quadrillion-cloud-api/revisions/d7f2f3b8e82d?raw)
