Skip to content

API keys

Revoke an API key

Revokes the key. Requests made with it then fail with 401 and invalid or expired API key. The key stays in the list with revoked: 1.

DELETE/api/v1/keys/{id}
  • Console only: owner or admin
  • Workspace: X-Tenant-ID

Path parameters

  • iduuidrequired

    Key id (not the key itself).

    Example
    8192a3b4-c5d6-4e7f-8091-a2b3c4d5e6f7

Headers

  • Cookiestringrequired

    The whatsappx_session cookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.

    Example
    whatsappx_session=…
  • X-Tenant-IDuuidrequired

    Workspace id. Required for session requests. You can pass ?tenant=<id> instead.

    Example
    8d0f6c2e-3b1a-4c55-9a7e-2f4b6d1e9c30

Response

200 OKapplication/json

  • okboolean

    Always true.

Status codes

  • 200OK. The key was revoked.
  • 400Bad request. The id is not a valid UUID.
  • 401Unauthorized. No signed-in session (unauthorized).
  • 403Forbidden. API keys can never call this endpoint (API keys cannot administer workspaces). A signed-in user who is not an owner or admin gets admin required; a user who is not a member of the workspace gets forbidden.
  • 404Not found. No active key with this id in the workspace (also returned for a key that is already revoked).
  • 500Server error. The key could not be revoked.