---
title: "Changes to Revoke an access token or refresh token"
method: POST
path: "/oauth2/revoke"
---

# Changes to Revoke an access token or refresh token

`POST /oauth2/revoke`

> Every recorded change to this endpoint, newest first.

## Timeline

Changed in 3 of 7 revisions.

- **2026-03-18** `e271d0e41f6d` — 3 breaking, 3 info
- **2026-03-06** `61b60b0c0d52` — 3 info
- **2026-02-03** `fc0a40f3b859` — 1 breaking, 4 warning, 5 info

## Changes

- **2026-03-18** `e271d0e41f6d` — 3 breaking, 3 info
  - request body became required
  - removed the media type `application/json` from the request body
  - the `success` response's property type changed from `string` to `boolean` for status `200`
  - api operation id `post_oauth2_revoke` removed and replaced with `postOauth2Revoke`
  - added the new optional `header` request parameter `XF-Api-User` to all path's operations
  - added the new optional `query` request parameter `api_bypass_permissions` to all path's operations
- **2026-03-06** `61b60b0c0d52` — 3 info
  - api tag `OAuth2` added
  - api tag `oauth2` removed
  - added the media type `application/json` for the response with the status `200`
- **2026-02-03** `fc0a40f3b859` — 1 breaking, 4 warning, 5 info
  - removed the media type `application/json` for the response with the status `200`
  - the optional response header `XF-Latest-Api-Version` removed for the status `200`
  - the optional response header `XF-Request-User` removed for the status `200`
  - the optional response header `XF-Request-User-Extras` removed for the status `200`
  - the optional response header `XF-Used-Api-Version` removed for the status `200`
  - api operation id `postOauth2Revoke` removed and replaced with `post_oauth2_revoke`
  - api tag `oauth2` added
  - api tag `OAuth2` removed
  - request body became optional
  - added the media type `application/json` to the request body

---

[Operation](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/docs/oauth2/revoke/post.md) · [API](https://skmtc.dev/xenforo-ltd/apis/xenforo-api.md) · [Page](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/changes/oauth2/revoke/post)
