Revoke a tenant API key
Ends a key immediately, so revoking a leaked credential does not require shell access to the pod.
/v1/tenants/{tenantId}/api_keys/{keyId}Ends a key immediately, so revoking a leaked credential does not
require shell access to the pod. The revocation is written to
audit_log in the same transaction as the status change, attributed to
the staff actor, and the service drops the key from its own
verification cache at once.
Requires a staff token with a platform role.
Propagation. authsvc caches successful verification for 60 seconds; walletd caches positive introspection for another 60 seconds. Revocation clears the receiving authsvc process's cache, not every replica's cache. With these defaults, stale acceptance can approach two minutes plus request latency. Verify rejection after that allowance. This is a source-derived cache bound, not a measured propagation SLA; revocation must not be the only control in a live incident.
Scoping. The revocation is scoped by the tenant in the path: a key
that does not belong to that tenant is not revoked. Revoking a key that
does not exist, belongs to another tenant, or is already revoked
answers 404 not_found, and the three cases are deliberately
indistinguishable so that a key id cannot be probed for existence.
Authorization
staffToken A portal staff session JWT (typ=staff), either minted by this service through POST /v1/auth/login or, where SSO is configured, issued by the configured identity realm. The operator endpoints additionally require a platform role (platform_ops or global_admin).
In: header
Path Parameters
The tenant's uuid.
uuidThe API key's uuid.
uuidResponse Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X DELETE "https://example.com/v1/tenants/497f6eca-6276-4993-bfeb-53cbbbba6f08/api_keys/497f6eca-6276-4993-bfeb-53cbbbba6f08"{ "revoked": true}