1. OpenAPI (Demo)
  2. API Keys
  3. Revoke an API key
ReadmeGitHub
  • Platform API overview
  • Quickstart
  • POSTCreate a member session
  • POSTRefresh a member session
  • DELETERevoke a member session
  • GETList organizations
  • POSTCreate an organization
  • GETGet an organization
  • PATCHUpdate an organization
  • GETList organization members
  • POSTInvite an organization member
  • DELETERemove an organization member
  • PATCHUpdate a member role
  • GETList projects
  • POSTCreate a project
  • GETGet a project
  • DELETEArchive a project
  • PATCHUpdate a project
  • GETList project environments
  • POSTCreate a project environment
  • GETList project documents
  • POSTCreate a project document
  • GETGet a document
  • DELETEArchive a document
  • PATCHUpdate a document
  • POSTPublish a document
  • GETList contacts
  • POSTCreate a contact
  • GETGet a contact
  • DELETEDelete a contact
  • PATCHUpdate a contact
  • GETList product events
  • GETGet analytics overview
  • GETList workflows
  • POSTCreate a workflow
  • GETList workflow runs
  • GETList webhook subscriptions
  • POSTCreate a webhook subscription
  • GETGet a webhook subscription
  • DELETEDelete a webhook subscription
  • PATCHUpdate a webhook subscription
  • GETList webhook deliveries
  • POSTReplay a webhook delivery
  • GETList files
  • POSTCreate a multipart file upload
  • GETGet file metadata
  • DELETEDelete a file
  • GETGet current subscription
  • PATCHUpdate subscription settings
  • GETList invoices
  • GETGet metered usage
  • GETList API keys
  • POSTCreate an API key
  • POSTRevoke an API key
  • GETList audit logs
  • GETList exports
  • POSTCreate an export
  • GETGet API health
POST/organizations/{organizationId}/api-keys/{apiKeyId}/revoke

Revoke an API key

Revokes an API key immediately and records an immutable audit event.

Send request

Use the documented inputs to call this endpoint directly.

API serverbase URL
Bearer tokenBearerAuthoptional
Stored only in this browser for the BearerAuth security scheme and reused on every API page in this group.

Parameters

Values are applied to the request and the example on the right.

organizationIdpath · stringrequired

Opaque organization identifier.

apiKeyIdpath · stringrequired
Idempotency-Keyheader · string · uuidoptional

Unique key for retry-safe writes, retained for 24 hours.

Responses

200application/json

API key revoked.

{
  "id": "key_01J8FF6Q2N4T8P9V3M5",
  "name": "Production data sync",
  "prefix": "heyo_live_",
  "scopes": [
    "contacts:write",
    "exports:read",
    "webhooks:write"
  ],
  "project_ids": [
    "prj_01J8F5KM4MAB0V7YQ6P3N2R8D1"
  ],
  "status": "active",
  "last_used_at": "2026-09-03T11:45:00Z",
  "expires_at": "2027-09-03T00:00:00Z",
  "created_at": "2026-09-01T09:00:00Z"
}
idstringoptional
namestringoptional
prefixstringoptional
scopesarray<string>optional
project_idsarray<string>optional
statusstringoptional
last_used_atobject · date-timeoptional
expires_atobject · date-timeoptional
created_atstring · date-timeoptional
404

API key not found.

Create an API key< PreviousList audit logsNext >

Powered by heyo

curl --request POST \  'https://api.demo.heyo.example/v3/organizations/org_01J8F1Q6N6VTX4E8W9R2D0A7B3/api-keys/key_01J8FF6Q2N4T8P9V3M5/revoke' \  --header 'Idempotency-Key: 5ba89923-8c6d-44a3-9ab7-2fbbdb865f9a'
{  "id": "key_01J8FF6Q2N4T8P9V3M5",  "name": "Production data sync",  "prefix": "heyo_live_",  "scopes": [    "contacts:write",    "exports:read",    "webhooks:write"  ],  "project_ids": [    "prj_01J8F5KM4MAB0V7YQ6P3N2R8D1"  ],  "status": "active",  "last_used_at": "2026-09-03T11:45:00Z",  "expires_at": "2027-09-03T00:00:00Z",  "created_at": "2026-09-01T09:00:00Z"}