Revoke a subject's outstanding credentials

Deauthorizes a subject by revoking every outstanding credential your organization minted for it — the person (principal_ref) or the business (business_ref), whichever the request names. Revocation flips the credentials' bits on the published status list, so relying parties that check status see the deauthorization within the list's cache TTL. Idempotent: re-revoking an already-revoked subject reports zero.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params

Body for POST /credentials/revocations: deauthorize a subject by
revoking every outstanding credential the calling organization minted
for it.

Exactly one subject reference — the unit of deauthorization is the
subject, never a single wire credential, because agents re-mint
short-lived credentials on demand.

length between 1 and 255

Pairwise reference to the person whose credentials to revoke, as issued to the calling organization.

length between 1 and 255

Pairwise reference to the business whose credentials to revoke (operator and counterparty credentials alike), as issued to the calling organization.

Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
string
enum
Defaults to application/json

Generated from available request content types

Allowed:
Responses

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/vnd.baselayer.v1+json