Skip to main content
Resend Docs

Search documentation

Type to search this documentation.

On this pageOverview

Revoke Token

POST

/

oauth

/

revoke

Public client
curl -X POST 'https://api.resend.com/oauth/revoke' \
     -H 'Content-Type: application/x-www-form-urlencoded' \
     -d 'client_id=550e8400-e29b-41d4-a716-446655440000&token=JcL7aYfE7S9h3L4qv0o2e1w8m6n5b3x9RkP2tD4uV6Q&token_type_hint=refresh_token'
Client Secret Basic
curl -X POST 'https://api.resend.com/oauth/revoke' \
     -H 'Content-Type: application/x-www-form-urlencoded' \
     -u '550e8400-e29b-41d4-a716-446655440000:CLIENT_SECRET' \
     -d 'token=JcL7aYfE7S9h3L4qv0o2e1w8m6n5b3x9RkP2tD4uV6Q&token_type_hint=refresh_token'
Client Secret Post
curl -X POST 'https://api.resend.com/oauth/revoke' \
     -H 'Content-Type: application/x-www-form-urlencoded' \
     -d 'client_id=550e8400-e29b-41d4-a716-446655440000&client_secret=CLIENT_SECRET&token=JcL7aYfE7S9h3L4qv0o2e1w8m6n5b3x9RkP2tD4uV6Q&token_type_hint=refresh_token'
Response
HTTP/1.1 200 OK

RFC 7009 token revocation. Revoking a refresh token revokes the entire grant: every access and refresh token issued under it stops working. Access tokens can’t be revoked individually. Revoke the grant’s refresh token instead. Per RFC 7009, this endpoint always returns 200 with an empty body. Confidential clients must authenticate the same way they do at the token endpoint, using client_secret_basic or client_secret_post. Public clients (none) send only client_id.

string

required

The refresh token to revoke.

string

Required, except with client_secret_basic, where the Authorization header already carries it.

string

Required for a confidential client using client_secret_post. Omit for public clients and for client_secret_basic (send the secret in the Authorization header instead).

string

Optional per RFC 7009. If set to "access_token", the request fails: access token revocation isn’t supported. Any other value (including "refresh_token") is accepted and ignored. Unknown hints don’t affect behavior.

Public client
curl -X POST 'https://api.resend.com/oauth/revoke' \
     -H 'Content-Type: application/x-www-form-urlencoded' \
     -d 'client_id=550e8400-e29b-41d4-a716-446655440000&token=JcL7aYfE7S9h3L4qv0o2e1w8m6n5b3x9RkP2tD4uV6Q&token_type_hint=refresh_token'
Client Secret Basic
curl -X POST 'https://api.resend.com/oauth/revoke' \
     -H 'Content-Type: application/x-www-form-urlencoded' \
     -u '550e8400-e29b-41d4-a716-446655440000:CLIENT_SECRET' \
     -d 'token=JcL7aYfE7S9h3L4qv0o2e1w8m6n5b3x9RkP2tD4uV6Q&token_type_hint=refresh_token'
Client Secret Post
curl -X POST 'https://api.resend.com/oauth/revoke' \
     -H 'Content-Type: application/x-www-form-urlencoded' \
     -d 'client_id=550e8400-e29b-41d4-a716-446655440000&client_secret=CLIENT_SECRET&token=JcL7aYfE7S9h3L4qv0o2e1w8m6n5b3x9RkP2tD4uV6Q&token_type_hint=refresh_token'
http
HTTP/1.1 200 OK
Status error When
400 invalid_request token or client_id is missing, token_type_hint is "access_token", or the client sent credentials via more than one mechanism.
401 invalid_client Unknown or disabled client_id, or a confidential client failed authentication (missing or wrong client_secret).

Was this page helpful?

⌘I

Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu