All the major OAuth providers. One profile API.Explore the quickstart
Documentation navigation

Revocation

No body. Syntactically valid bearer tokens are revoked idempotently. Does not terminate the customer app session.

On this page
POSThttps://api.anyoauth.com/v1/revoke

Authentication: AnyOAuth profile bearer token.

Request

No request body. Pass the profile token in the Authorization: Bearer header.

SDK and HTTP examples

Revocation
import { AnyOAuth } from "@anyoauth/node";

const client = new AnyOAuth({
clientId: process.env.ANYOAUTH_CLIENT_ID ?? "YOUR_CLIENT_ID",
clientSecret: process.env.ANYOAUTH_CLIENT_SECRET ?? "YOUR_CLIENT_SECRET",
baseUrl: process.env.ANYOAUTH_API_ORIGIN ?? "https://api.anyoauth.com",
});

const result = await client.revoke({
accessToken: process.env.ANYOAUTH_ACCESS_TOKEN ?? "aop_aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
});

@anyoauth/node on GitHubConfidential backend SDK

Sample input bindings are illustrative. In a callback handler, take code and transaction values from the validated request and initiating session. Client-only SDKs do not perform confidential exchange.

Response

Success status: 204.

Empty response. Do not parse this response as JSON.

Errors

Application errors use the shared error model. Infrastructure may return non-JSON responses; SDKs expose structured transport/protocol errors. Do not automatically retry a one-time code exchange.

FieldTypeRequiredDescription and constraints
errorstringYes
messagestringNo
Illustrative error response
{
"error": "request_failed",
"message": "The request could not be completed."
}

Contract source

This page, its field tables and sample inputs derive from OpenAPI version 0.1.0. Download OpenAPI · Download JSON Schema