---
title: "Revoke an access token or refresh token"
method: POST
path: "/oauth2/revoke"
tags: ["OAuth2"]
---

# Revoke an access token or refresh token

`POST /oauth2/revoke`

Revoke an access token or refresh token.

## Response `200`

OK

- object
  - `success` boolean

## Other responses

- `default` — Error

## Changes

- **2026-03-18** `e271d0e41f6d` — 3 breaking, 3 info
  - request body became required
  - removed the media type `application/json` from the request body
  - the `success` response's property type changed from `string` to `boolean` for status `200`
  - api operation id `post_oauth2_revoke` removed and replaced with `postOauth2Revoke`
  - …2 more
- **2026-03-06** `61b60b0c0d52` — 3 info
  - api tag `OAuth2` added
  - api tag `oauth2` removed
  - added the media type `application/json` for the response with the status `200`
- **2026-02-03** `fc0a40f3b859` — 1 breaking, 4 warning, 5 info
  - removed the media type `application/json` for the response with the status `200`
  - the optional response header `XF-Latest-Api-Version` removed for the status `200`
  - the optional response header `XF-Request-User` removed for the status `200`
  - the optional response header `XF-Request-User-Extras` removed for the status `200`
  - …6 more

[Change history](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/changes/oauth2/revoke/post.md)

---

[API](https://skmtc.dev/xenforo-ltd/apis/xenforo-api.md) · [All operations](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/xenforo-ltd/xenforo-api/revisions/b15eba33657a/schema)
