WalletD developers
Staff sessions

Revoke every live session a staff member holds

Kills all of a staff member's unexpired sessions at once: a platform operator's incident action for a compromised or departing account.

POST/v1/staff/{staffId}/revoke-sessions

Kills all of a staff member's unexpired sessions at once: a platform operator's incident action for a compromised or departing account. The response reports how many sessions were ended, which is zero when the member had none.

Requires a staff token with a platform role. The action is recorded in audit_log attributed to the calling operator.

Propagation. Revoked session ids are published on the internal revocation list that walletd polls beside the JWKS; the staff token itself stays cryptographically valid until its exp, so the effect is as prompt as that poll, not instantaneous.

The request takes no body.

Authorization

staffToken
AuthorizationBearer <token>

A portal staff session JWT (typ=staff), either minted by this service through POST /v1/auth/login or, where SSO is configured, issued by the configured identity realm. The operator endpoints additionally require a platform role (platform_ops or global_admin).

In: header

Path Parameters

staffId*string

The staff member's uuid.

Formatuuid

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X POST "https://example.com/v1/staff/497f6eca-6276-4993-bfeb-53cbbbba6f08/revoke-sessions"
{  "revoked": 3}