Revoke user tokens
POST
/v1/auth/revoke
const url = 'https://api.neuramancer.dev/v1/auth/revoke';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"idToken":"example","refreshToken":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.neuramancer.dev/v1/auth/revoke \ --header 'Content-Type: application/json' \ --data '{ "idToken": "example", "refreshToken": "example" }'Revokes a user’s Firebase tokens, effectively logging them out from all devices. This is intentionally an unauthenticated endpoint - tokens are passed in the request body so that clients can revoke tokens without requiring an active middleware session.
Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/json
object
idToken
required
Firebase ID token to verify before revocation
string
refreshToken
required
Firebase refresh token to revoke
string
Examplegenerated
{ "idToken": "example", "refreshToken": "example"}Responses
Section titled “Responses”Tokens revoked successfully
Media typeapplication/json
Standardized success response with a confirmation message, following the APIResponse
object
success
required
boolean
data
required
object
message
required
Confirmation message
string
Example
{ "success": true}Missing idToken or refreshToken
Media typeapplication/json
Standardized error response following the APIResponse
object
success
required
boolean
message
required
string
Example
{ "success": false, "message": "Bad request"}Invalid token - verification failed
Media typeapplication/json
Standardized error response following the APIResponse
object
success
required
boolean
message
required
string
Example
{ "success": false, "message": "Bad request"}Server error during revocation
Media typeapplication/json
Standardized error response following the APIResponse
object
success
required
boolean
message
required
string
Example
{ "success": false, "message": "Bad request"}