Skip to main content

Endpoint

Authentication

Requires a Personal API Access Token.

Request

Headers

Path Parameters

Request Body

Same structure as Grant Access. Object containing an array of access objects.

Full JSON Body Example - Revoke Access from Single API Proxy

Full JSON Body Example - Revoke Access from Multiple Resources

Request Body Fields

Same as Grant Access. See Grant Access for field descriptions.

Notes

  • Request body must be an object with credentialAccessList array
  • Each access object must have name and type
  • name must match an existing API Proxy or API Proxy Group
  • type must be either API_PROXY or API_PROXY_GROUP
  • Access must exist to be revoked
  • Revocation is automatically deployed to all environments

Response

Success Response (200 OK)

Error Response (400 Bad Request)

or

Common Causes

  • Empty access object
  • Missing name or type field
  • API Proxy or API Proxy Group does not exist
  • Access does not exist (already revoked)

Error Response (401 Unauthorized)

Error Response (404 Not Found)

cURL Example

Example 1: Revoke Access from Single API Proxy

Example 2: Revoke Access from Multiple Resources

Notes and Warnings

  • Request Body Format:
    • Request body must be an object with credentialAccessList array
    • Even for single revocation, use object format with array inside
  • Access Must Exist:
    • Access must exist to be revoked
    • Revoking non-existent access will fail silently
  • Automatic Undeployment:
    • Access revocation is automatically undeployed from all environments
    • Undeployment results are returned in the response
  • API Proxy Group:
    • Revoking access from API Proxy Group revokes access to all APIs in the group
    • Individual API accesses are not affected if group access is revoked

Permissions

  • User must have IDENTITY + MANAGE permission in the project
  • For automatic undeployment, user must also have IDENTITY + DEPLOY_UNDEPLOY permission