Appearance
Token Revocation
The Knowify OAuth API supports RFC 7009 token revocation, allowing clients to invalidate access tokens and refresh tokens when they are no longer needed.
When to Revoke Tokens
- User logs out — revoke the refresh token to prevent further access
- User disconnects your integration — revoke all tokens for that user
- Token compromise — immediately revoke if a token may have been leaked
- Application uninstall — clean up tokens on removal
Revocation Endpoint
POST /oauth/revocation
Content-Type: application/x-www-form-urlencodedParameters
| Parameter | Type | Required | Description |
|---|---|---|---|
token | string | Yes | The token to revoke |
token_type_hint | string | No | access_token or refresh_token |
client_id | string | Yes | Your client ID |
client_secret | string | Conditional | Required for confidential clients |
Example: Revoke a Refresh Token
bash
curl -X POST https://developers.knowify.com/oauth/revocation \
-d "token=REFRESH_TOKEN" \
-d "token_type_hint=refresh_token" \
-d "client_id=YOUR_CLIENT_ID" \
-d "client_secret=YOUR_CLIENT_SECRET"Example: Revoke with HTTP Basic Auth
bash
curl -X POST https://developers.knowify.com/oauth/revocation \
-u "YOUR_CLIENT_ID:YOUR_CLIENT_SECRET" \
-d "token=ACCESS_TOKEN" \
-d "token_type_hint=access_token"JavaScript Example
js
async function revokeToken(token, tokenTypeHint = 'refresh_token') {
const response = await fetch('https://developers.knowify.com/oauth/revocation', {
method: 'POST',
headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
body: new URLSearchParams({
token,
token_type_hint: tokenTypeHint,
client_id: CLIENT_ID,
client_secret: CLIENT_SECRET,
}),
});
// Revocation always returns 200, even if the token was already invalid
return response.ok;
}Response
The revocation endpoint always returns HTTP 200 with an empty body on success, regardless of whether the token was valid. This prevents token existence probing.
If the client credentials are invalid, the endpoint returns HTTP 401.
Token Introspection
You can check whether a token is still valid using the introspection endpoint:
POST /oauth/introspection
Content-Type: application/x-www-form-urlencoded| Parameter | Type | Required | Description |
|---|---|---|---|
token | string | Yes | The token to inspect |
client_id | string | Yes | Your client ID |
client_secret | string | Conditional | Required for confidential clients |
Example
bash
curl -X POST https://developers.knowify.com/oauth/introspection \
-u "YOUR_CLIENT_ID:YOUR_CLIENT_SECRET" \
-d "token=ACCESS_TOKEN"Active token response:
json
{
"active": true,
"sub": "12345",
"client_id": "your-client-id",
"scope": "openid profile projects:read",
"exp": 1700000000,
"iat": 1699999100,
"token_type": "Bearer"
}Revoked or expired token response:
json
{
"active": false
}