Revoke a public-API token by setting its SystemUser.is_active to False.
The token will no longer authenticate requests via check_system_user_token. This is idempotent: revoking an already-revoked token is a 200 no-op.
Returns HTTP 200 with the updated token serialized via SystemUserTokenSerializer. HTTP 403 is returned for non-admin callers; HTTP 404 if the token does not exist or belongs to another organization; HTTP 401 for unauthenticated.
Request
- The document declares no server URL.
- Auth: one of:
- HTTP bearer
- API key in cookie sessionid
Path parameters
Headers
Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.
Request body
Response
Changes
- ○
added the new optional
headerrequest parameterX-Organization-Id
- ○
- ○
added the required property
to the response with the status
- ○