Security and audit
Sign out a session
Ends the session right away: the next request from that browser gets 401 and the person has to sign in again. Check can_revoke in the sessions list first. The sign-out is recorded in the audit log as session.revoked. API keys are not accepted.
- Console only: signed-in session
- Workspace:
X-Tenant-ID
Path parameters
iduuidrequiredSession id (
idfrom the sessions list).
Headers
CookiestringrequiredThe
whatsappx_sessioncookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.X-Tenant-IDuuidrequiredWorkspace id. Required for session requests. You can pass
?tenant=<id>instead.
Response
200 OKapplication/json
okbooleanAlways
true.
Status codes
- 200OK. The session was signed out.
- 401Unauthorized. No signed-in session (
unauthorized). - 403Forbidden. The session belongs to someone you may not sign out (its
can_revokeisfalse). - 404Not found. No signed-in session with this id in the workspace.
- 500Server error. Something went wrong on our side. Retry with backoff.