Token Revoke Endpoint
The Token Revoke endpoint allows your application to revoke access to a client by revoking the access or refresh token associated with that client. You can find this endpoint from the OAuth Discovery Endpoint.
OAuth Discovery Endpoint
https://<EID Server>/oauth/.well-known/openid-configuration
How to call the Token Revoke Endpoint
-
Initiate a request to the EmpowerID Token Revoke endpoint,
https://<EID Server>/oauth/v2/tokenrevokePOST /oauth/v2/tokenrevoke HTTP/1.1
Host: <EID Server>
Content-Type: application/x-www-form-urlencoded
Cache-Control: no-cache
Authorization: Basic base64Encode(<ClientID>:<ClientSecret>)
token={Your access token}
&token_type_hint=refresh_token/access_tokenHeader Parameter Required/Optional Description Content-Typerequired Must be application/x-www-form-urlencoded.Authorizationrequired Base64 encoded value of ClientID and Client Secret base64Encode(<client_id>:<client_secret>)Post Body Parameter Required/Optional Description tokenrequired Must be the access token or refresh token token_type_hint=refresh_tokenORtoken_type_hint=access_tokenrequired If the token is a refresh token, set token_type_hint=refresh_token; otherwise, settoken_type_hint=access_token -
Returns null if the token has been successfully removed.