Version
DESTRUCTIVE

revoke_token

Revoke one of the authenticated user's own tokens by id. Self-revocation is refused.

Revoke one of the authenticated user's own personal access tokens by id. Refuses self-revocation — the token authenticating this call cannot delete its own row. Revoke the current session from the dashboard (Settings → API Tokens) or from a different token instead.

Requires ability

The token behind the MCP session must hold it, or the call is refused with TOKEN_MISSING_ABILITY.

Runs the same action as

The REST endpoint and this tool share one action, so validation, permissions and events are identical.

Annotations

DestructiveIdempotent

A client that honours annotations asks a person before running it. Sending the same arguments twice changes nothing the second time.

Arguments

token_id*string

UUID of the token to revoke. Must belong to the authenticated user. Cannot be the id of the token authenticating this call.

What it returns

{  "data": {    "token_id": "1284",    "revoked": true  }}

How it fails

AUTHENTICATION_REQUIRED

no authenticated user on the request.

VALIDATION_FAILED

token_id is empty, or caller tried to revoke the current session (self-revoke blocked).

RESOURCE_NOT_FOUND

token doesn't belong to the authenticated user.

How is this guide?

Last updated on