WalletD developers
Operations and audit

Revoke WalletD vendor-support access immediately (partner admin only)

Ends a support grant immediately; the engineer's next request is refused.

POST/v1/support_access_grants/{grantId}/revoke

Ends a support grant immediately; the engineer's next request is refused. Requires a partner administrator holding support_access:manage, so anyone else is refused partner_admin_required (403), and an unknown grant gives support_access_grant_not_found (404). The access already recorded under the grant stays readable after it is revoked.

Console-only. This path is not routed at the public API gateway: it is reachable from the partner administration console and from inside the deployment, never with a tenant API key over the internet. It additionally requires a partner administrator — a staff principal that is neither a platform nor a WalletD vendor-support identity.

Authorization

bearerAuth
AuthorizationBearer <token>

A tenant API key (sk_{env}_{id}_{secret}), a wallet user token, or an IdP access token. Which principal the credential resolves to decides the scopes it carries; see the authentication guide.

In: header

Path Parameters

grantId*string
Formatuuid

Response Body

application/json

application/problem+json

curl -X POST "https://example.com/v1/support_access_grants/497f6eca-6276-4993-bfeb-53cbbbba6f08/revoke"
{  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",  "staff_id": "string",  "reason": "string",  "ticket_reference": "string",  "created_by_type": "string",  "created_by_id": "string",  "created_at": "2019-08-24T14:15:22Z",  "expires_at": "2019-08-24T14:15:22Z",  "revoked_at": "2019-08-24T14:15:22Z",  "revoked_by_type": "string",  "revoked_by_id": "string"}