Revoke an API key
Stops this credential working. The next request made with it is refused the same way a string that was never issued is refused.
The row survives. DELETE stamps the key as revoked rather than
removing it, so it stays in the list with its revoked_at. Nothing in
this API removes a key.
Revocation only goes one way. No operation here revives a revoked key, and none mints a new one, so through this API the set of working credentials on a newsletter can only get smaller. Mint a replacement in Commune's settings.
A key may revoke itself, which is what an integration that knows it
has leaked, or a job finished with its credential, should do. self on
the list operation says which key that is.
A key may also revoke its siblings: the other credentials belonging to the same person.
A credential belonging to somebody else answers 403, even when it
reaches the same newsletter and GET /api-keys/{key} returns it.
Cutting a credential off one newsletter rather than off everything is
done in Commune's settings instead.
Revoking a key that is already revoked succeeds and returns it
unchanged, with its original revoked_at, so a retry after a dropped
response is not a failure.
Never refused for payment, so no 402. Publishes no event: the
credential that was revoked learns it on its next request.
Loading...
Waiting for a request to be sent.