POST/organizations/{organizationId}/api-keys/{apiKeyId}/revoke

Revoke an API key

Revokes an API key immediately and records an immutable audit event.

Send request

Use the documented inputs to call this endpoint directly.

API serverbase URL
Bearer tokenBearerAuthoptional
Stored only in this browser for the BearerAuth security scheme and reused on every API page in this group.

Parameters

Values are applied to the request and the example on the right.

organizationIdpath · stringrequired

Opaque organization identifier.

apiKeyIdpath · stringrequired
Idempotency-Keyheader · string · uuidoptional

Unique key for retry-safe writes, retained for 24 hours.

Responses

200application/json

API key revoked.

{
  "id": "key_01J8FF6Q2N4T8P9V3M5",
  "name": "Production data sync",
  "prefix": "heyo_live_",
  "scopes": [
    "contacts:write",
    "exports:read",
    "webhooks:write"
  ],
  "project_ids": [
    "prj_01J8F5KM4MAB0V7YQ6P3N2R8D1"
  ],
  "status": "active",
  "last_used_at": "2026-09-03T11:45:00Z",
  "expires_at": "2027-09-03T00:00:00Z",
  "created_at": "2026-09-01T09:00:00Z"
}
idstringoptional
namestringoptional
prefixstringoptional
scopesarray<string>optional
project_idsarray<string>optional
statusstringoptional
last_used_atobject · date-timeoptional
expires_atobject · date-timeoptional
created_atstring · date-timeoptional
404

API key not found.