Revoke a specific session (any device other than the current one).
DELETE/auth/sessions/:familyId
Revokes the named refresh-token family. The user can revoke any session, including the current one; subsequent refresh attempts on that family will fail. Requires the self:session:manage permission.
Request
Responses
- 204
- 401
- 403
- 404
- 422
- 429
- 500
Session revoked.
Missing or invalid access token.
The authenticated caller does not carry the required permission or is scoped out of this resource by the object-authorization service (e.g. an agent trying to view another agent's referrals). Grant the missing permission via a role change or scope the query to resources the caller owns.
Session does not exist for the current user.
The request is syntactically valid but violates a business invariant — a referral state transition not permitted from the current status, a wallet withdrawal exceeding the available balance, or a POP being confirmed before it has been ZFA-verified. error.code is one of INVALID_TRANSITION, INVARIANT_VIOLATION, or a domain-specific value; error.message explains the invariant.
Rate limit exceeded. Global default is 120 requests/minute per IP; auth-flow, OTP, self-registration, WebAuthn, IRA lookup, and public-lead endpoints carry tighter per-endpoint limits. Retry after the delay indicated by the Retry-After header.
Response Headers
Seconds to wait before retrying.
Unhandled server error. The response carries a meta.requestId correlator you can hand to platform operations to trace the failure through structured logs and the hash-chained audit trail. Retry with the same Idempotency-Key header if the endpoint accepts idempotency.