Skip to main content
DELETE
Kill an API key. It stops authenticating immediately.
Rotating credentials? Mint the replacement key with Create an API key and deploy it before revoking the old one — revocation takes effect the moment the call returns.

Authorization

This endpoint is dashboard-only: a dashboard JWT with role merchant_admin, merchant_member (with team permission api-keys:manage) or super_admin. API-key callers are rejected with 401 {"error":"Invalid or expired token"} — the JWT guard runs first and an API key is not a session token, so the call never reaches the role check. The key is not revoked; it simply cannot authenticate a dashboard-only route. Rate limit: 10/min.
A super_admin passes the role guard, but platform accounts carry no merchant context, so the handler short-circuits with 400 {"ok":false,"error":{"code":"NO_MERCHANT_CONTEXT","message":"No merchant context"}}. In practice this endpoint is for merchant accounts.
No MFA is needed — revoking only reduces capability, so it can’t be used to escalate anything.

Parameters

string
required
ID of the key to revoke (from List API keys).

Response fields

boolean
true — the key stops authenticating immediately.

Errors

See also