> ## Documentation Index
> Fetch the complete documentation index at: https://docs.quivr.thevibecompany.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Revoke a push token immediately

> Requires connectors:admin on the instance's Organization and Corpus. Revoke this token, even during rotation overlap or after the instance is disabled. Every authentication checks durable validity without a cache, so new authentications after the commit fail immediately; already admitted deliveries may finish. Revocation is idempotent and returns metadata only. Revoking an old token does not revoke its replacement; revoke each token_id that should lose access. No request body is needed.



## OpenAPI

````yaml /openapi.yaml delete /v0/connectors/{connector_id}/tokens/{token_id}
openapi: 3.1.0
info:
  title: Quivr HTTP API
  version: 0.0.0-draft
  description: >-
    Every endpoint of the Quivr v0 HTTP API. Send an API key as a bearer token;
    the key decides the Organization, the actions and the Corpora a request may
    reach.
servers: []
security:
  - ApiKey: []
paths:
  /v0/connectors/{connector_id}/tokens/{token_id}:
    parameters:
      - name: connector_id
        in: path
        required: true
        schema:
          type: string
          minLength: 1
      - name: token_id
        in: path
        required: true
        schema:
          type: string
          minLength: 1
    delete:
      tags:
        - Connectors
      summary: Revoke a push token immediately
      description: >-
        Requires connectors:admin on the instance's Organization and Corpus.
        Revoke this token, even during rotation overlap or after the instance is
        disabled. Every authentication checks durable validity without a cache,
        so new authentications after the commit fail immediately; already
        admitted deliveries may finish. Revocation is idempotent and returns
        metadata only. Revoking an old token does not revoke its replacement;
        revoke each token_id that should lose access. No request body is needed.
      operationId: revokeConnectorToken
      responses:
        '200':
          description: Revoked token metadata, never a secret.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConnectorToken'
        default:
          description: >-
            JSON Error envelope; 401 unauthenticated, 403 without admin
            permission, 404 unknown or foreign token, 503 unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ConnectorToken:
      type: object
      additionalProperties: false
      required:
        - token_id
        - prefix
        - created_at
      properties:
        token_id:
          type: string
        prefix:
          type: string
          description: Display prefix only; cannot authenticate.
        created_at:
          type: string
          format: date-time
        rotated_at:
          type: string
          format: date-time
        revoked_at:
          type: string
          format: date-time
        valid_until:
          type: string
          format: date-time
          description: >-
            Exclusive expiry of an old token after rotation; absent for an
            unrotated token.
    Error:
      type: object
      additionalProperties: false
      properties:
        code:
          type: string
          minLength: 1
        message:
          type: string
          minLength: 1
        retryable:
          type: boolean
        field:
          type: string
          minLength: 1
          description: >-
            JSON Pointer (RFC 6901) to the request member that caused a 422,
            when known (for example /config/url or /credential/secret/token on
            connector commands).
        resync_url:
          type: string
          format: uri-reference
      required:
        - code
        - message
        - retryable
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      description: >-
        API key, not necessarily a JWT. Server derives Organization, permitted
        actions and Corpus scope; every resource access is authorized.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.