public-api-tokens

Revoke a public-API token by setting its SystemUser.is_active to False.

The token will no longer authenticate requests via check_system_user_token. This is idempotent: revoking an already-revoked token is a 200 no-op.

Returns HTTP 200 with the updated token serialized via SystemUserTokenSerializer. HTTP 403 is returned for non-admin callers; HTTP 404 if the token does not exist or belongs to another organization; HTTP 401 for unauthenticated.

post/public-api-tokens/{id}/revoke/

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Path parameters

idstring required

Headers

X-Organization-Idstring

Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.

Request body

idinteger required
integration_namestring required
is_activeboolean required

Indicates if the user is active.

available_resourcesstring[] required

Return a list of resource_name values from the prefetched ResourceAccess rows.

scoped_to_userinteger nullable required

Return the owner's User id from the denormalized membership column, or None.

scoped_to_membership_user_id is a concrete column already storing the membership's user_id, so the value is returned directly with no extra query.

Response

idinteger required
integration_namestring required
is_activeboolean required

Indicates if the user is active.

available_resourcesstring[] required

Return a list of resource_name values from the prefetched ResourceAccess rows.

scoped_to_userinteger nullable required

Return the owner's User id from the denormalized membership column, or None.

scoped_to_membership_user_id is a concrete column already storing the membership's user_id, so the value is returned directly with no extra query.

Changes