Skip to content

Security and audit

Sign out a session

Ends the session right away: the next request from that browser gets 401 and the person has to sign in again. Check can_revoke in the sessions list first. The sign-out is recorded in the audit log as session.revoked. API keys are not accepted.

DELETE/api/v1/security/sessions/{id}
  • Console only: signed-in session
  • Workspace: X-Tenant-ID

Path parameters

  • iduuidrequired

    Session id (id from the sessions list).

    Example
    0912a3b4-c5d6-4e7f-9081-92a3b4c5d6e7

Headers

  • Cookiestringrequired

    The whatsappx_session cookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.

    Example
    whatsappx_session=…
  • X-Tenant-IDuuidrequired

    Workspace id. Required for session requests. You can pass ?tenant=<id> instead.

    Example
    8d0f6c2e-3b1a-4c55-9a7e-2f4b6d1e9c30

Response

200 OKapplication/json

  • okboolean

    Always true.

Status codes

  • 200OK. The session was signed out.
  • 401Unauthorized. No signed-in session (unauthorized).
  • 403Forbidden. The session belongs to someone you may not sign out (its can_revoke is false).
  • 404Not found. No signed-in session with this id in the workspace.
  • 500Server error. Something went wrong on our side. Retry with backoff.