Revoke an API key

posthttps://api.expiryedge.com/v1/revokeApiKey
bearer token of a signed-in person (not an API key); role admin60/min
Request
curl -X POST 'https://api.expiryedge.com/v1/revokeApiKey' \
  -H "Authorization: Bearer $EXPIRYEDGE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "id": "k7Qm2xKpA1"
}'
Response
{
  "api_key": {
    "id": "k7Qm2xKpA1",
    "name": "Nightly HR import",
    "prefix": "ee_live_4fQ9",
    "role": "editor",
    "status": "revoked",
    "created_by": "u_71bXq",
    "created_at": "2026-09-27T14:05:00.000Z",
    "last_used_at": "2026-09-27T22:00:04.000Z",
    "expires_at": null,
    "revoked_at": "2026-09-28T09:12:00.000Z"
  }
}

The key stops working immediately (401) and cannot be re-enabled. Revoking an already revoked key returns 200. Keys of another organization return 404.

Body parameters

application/json
  • idstringrequired
    API key id from createApiKey or getApiKeys.

Returns

200
The revoked key.
  • api_keyobject
    An organization API key without the secret. Only the first 12 characters (prefix) are ever shown again.

Errors

400
The request is missing required fields or contains invalid values.
401
Missing, expired or invalid bearer token.
403
Authenticated, but your role or organization does not allow this action.
404
The record does not exist or is not in your organization.
405
The endpoint does not accept this HTTP method.
429
Too many requests for this endpoint from your IP. Wait Retry-After seconds.
500
Unexpected server error. Retry later; quote requestId to support.