Skip to main content
DELETE
Revoke an API key

Authorizations

Authorization
string
header
required

Bearer authentication using a factapi-issued API key (ffy_<env>_<base32_uuid><base62_random>). Cookie-based sessions are accepted automatically by user-facing endpoints but are not surfaced as an OpenAPI auth scheme.

Headers

X-Factify-Organization-Id
string

Optional. Factify-staff acting-as override: when set, factapi resolves the request against this organization instead of the session-bound one. Honored only for callers with @factify.com emails; non-staff requests carrying this header are rejected with 403. The value is a typed org id (e.g. org_01h2xcejqtf2nbrexx3vqjhp41).

Pattern: ^org_[0-9a-hjkmnp-tv-z]{26}$
Example:

"org_01h2xcejqtf2nbrexx3vqjhp41"

Path Parameters

api_key_id
string
required

TypedID of the API key to revoke. Pattern: key_[0-9a-hjkmnp-tv-z]{26}

Example:

"key_01h2xcejqtf2nbrexx3vqjhp41"

Body

application/json

Optional metadata for an API key revocation. The body itself is optional.

reason
string

Optional human-readable reason for revocation (audit only). The revoking user's identity and timestamp are captured in audit logs separately.

Example:

"rotated"

Response

No Content