const response = await fetch('https://api.commune.email/oauth/revoke', {
method: 'POST',
headers: {
'Authorization': `Basic ${credentials}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({ token: 'comm_oauth_xxx...' }),
});
resp = httpx.post(
'https://api.commune.email/oauth/revoke',
headers={
'Authorization': f'Basic {credentials}',
'Content-Type': 'application/json',
},
json={'token': 'comm_oauth_xxx...'},
)
curl -X POST https://api.commune.email/oauth/revoke \
-H "Authorization: Basic $(echo -n 'comm_client_xxx:comm_secret_xxx' | base64)" \
-H "Content-Type: application/json" \
-d '{"token": "comm_oauth_xxx..."}'
{ "message": "Token revoked" }
Commune OAuth
Revoke Token
Invalidate an access token or refresh token. Use when an agent signs out of your app.
POST
/
oauth
/
revoke
const response = await fetch('https://api.commune.email/oauth/revoke', {
method: 'POST',
headers: {
'Authorization': `Basic ${credentials}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({ token: 'comm_oauth_xxx...' }),
});
resp = httpx.post(
'https://api.commune.email/oauth/revoke',
headers={
'Authorization': f'Basic {credentials}',
'Content-Type': 'application/json',
},
json={'token': 'comm_oauth_xxx...'},
)
curl -X POST https://api.commune.email/oauth/revoke \
-H "Authorization: Basic $(echo -n 'comm_client_xxx:comm_secret_xxx' | base64)" \
-H "Content-Type: application/json" \
-d '{"token": "comm_oauth_xxx..."}'
{ "message": "Token revoked" }
const response = await fetch('https://api.commune.email/oauth/revoke', {
method: 'POST',
headers: {
'Authorization': `Basic ${credentials}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({ token: 'comm_oauth_xxx...' }),
});
resp = httpx.post(
'https://api.commune.email/oauth/revoke',
headers={
'Authorization': f'Basic {credentials}',
'Content-Type': 'application/json',
},
json={'token': 'comm_oauth_xxx...'},
)
curl -X POST https://api.commune.email/oauth/revoke \
-H "Authorization: Basic $(echo -n 'comm_client_xxx:comm_secret_xxx' | base64)" \
-H "Content-Type: application/json" \
-d '{"token": "comm_oauth_xxx..."}'
{ "message": "Token revoked" }
Body
string
required
The access token or refresh token to revoke.
Behavior
- Always returns
200, even if the token was already revoked or doesn’t exist. - Revoking a refresh token also revokes all access tokens for that agent-client pair.
- Accepts both Basic Auth (integrator-initiated) and Bearer Auth (agent-initiated).
Last modified on March 19, 2026
Was this page helpful?

