Api tokens
Delete Customer Token
Permanently revokes a customer-scoped API token. Users can only delete tokens within their customer scope.
DELETE /api/customer/tokens/:id
Example (cURL)
curl -X DELETE "$BASE_URL/api/customer/tokens/2" \
-H "Cookie: $SESSION_COOKIE"Response
{ "success": true }Common errors
403 Forbiddenwhen the token is outside your customer scope, or when the token is org-scoped (nocustomerId)404 Token not foundwhen the token doesn't exist or belongs to another org
Permissions
Open to organization admins and to the readonly role; editor and responder are refused with
insufficientPermissions. A customer-restricted caller may only revoke tokens bound to its own
customers: an organization-wide token (no customerId) is refused outright.
api_token records no issuer for tokens created before 04.09.2026, so a read-only user can revoke
a customer-scoped token that an admin issued for the same customer.