Skip to content

Token Revocation ​

The Knowify OAuth API supports RFC 7009 token revocation, allowing clients to invalidate access tokens and refresh tokens when they are no longer needed.

When to Revoke Tokens ​

  • User logs out — revoke the refresh token to prevent further access
  • User disconnects your integration — revoke all tokens for that user
  • Token compromise — immediately revoke if a token may have been leaked
  • Application uninstall — clean up tokens on removal

Revocation Endpoint ​

POST /oauth/revocation
Content-Type: application/x-www-form-urlencoded

Parameters ​

ParameterTypeRequiredDescription
tokenstringYesThe token to revoke
token_type_hintstringNoaccess_token or refresh_token
client_idstringYesYour client ID
client_secretstringConditionalRequired for confidential clients

Example: Revoke a Refresh Token ​

bash
curl -X POST https://developers.knowify.com/oauth/revocation \
  -d "token=REFRESH_TOKEN" \
  -d "token_type_hint=refresh_token" \
  -d "client_id=YOUR_CLIENT_ID" \
  -d "client_secret=YOUR_CLIENT_SECRET"

Example: Revoke with HTTP Basic Auth ​

bash
curl -X POST https://developers.knowify.com/oauth/revocation \
  -u "YOUR_CLIENT_ID:YOUR_CLIENT_SECRET" \
  -d "token=ACCESS_TOKEN" \
  -d "token_type_hint=access_token"

JavaScript Example ​

js
async function revokeToken(token, tokenTypeHint = 'refresh_token') {
  const response = await fetch('https://developers.knowify.com/oauth/revocation', {
    method: 'POST',
    headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
    body: new URLSearchParams({
      token,
      token_type_hint: tokenTypeHint,
      client_id: CLIENT_ID,
      client_secret: CLIENT_SECRET,
    }),
  });

  // Revocation always returns 200, even if the token was already invalid
  return response.ok;
}

Response ​

The revocation endpoint always returns HTTP 200 with an empty body on success, regardless of whether the token was valid. This prevents token existence probing.

If the client credentials are invalid, the endpoint returns HTTP 401.

Token Introspection ​

You can check whether a token is still valid using the introspection endpoint:

POST /oauth/introspection
Content-Type: application/x-www-form-urlencoded
ParameterTypeRequiredDescription
tokenstringYesThe token to inspect
client_idstringYesYour client ID
client_secretstringConditionalRequired for confidential clients

Example ​

bash
curl -X POST https://developers.knowify.com/oauth/introspection \
  -u "YOUR_CLIENT_ID:YOUR_CLIENT_SECRET" \
  -d "token=ACCESS_TOKEN"

Active token response:

json
{
  "active": true,
  "sub": "12345",
  "client_id": "your-client-id",
  "scope": "openid profile projects:read",
  "exp": 1700000000,
  "iat": 1699999100,
  "token_type": "Bearer"
}

Revoked or expired token response:

json
{
  "active": false
}