curl --request POST \
--url https://iam.basaltic.sh/v1/oauth/revoke \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data 'token=<string>' \
--data token_type_hint=access_tokenimport requests
url = "https://iam.basaltic.sh/v1/oauth/revoke"
payload = {
"token": "<string>",
"token_type_hint": "access_token"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/x-www-form-urlencoded"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
Authorization: 'Bearer <token>',
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({token: '<string>', token_type_hint: 'access_token'})
};
fetch('https://iam.basaltic.sh/v1/oauth/revoke', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://iam.basaltic.sh/v1/oauth/revoke",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "token=%3Cstring%3E&token_type_hint=access_token",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/x-www-form-urlencoded"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://iam.basaltic.sh/v1/oauth/revoke"
payload := strings.NewReader("token=%3Cstring%3E&token_type_hint=access_token")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://iam.basaltic.sh/v1/oauth/revoke")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/x-www-form-urlencoded")
.body("token=%3Cstring%3E&token_type_hint=access_token")
.asString();require 'uri'
require 'net/http'
url = URI("https://iam.basaltic.sh/v1/oauth/revoke")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/x-www-form-urlencoded'
request.body = "token=%3Cstring%3E&token_type_hint=access_token"
response = http.request(request)
puts response.read_body{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication required",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "An internal error occurred",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}Revogar um token de portador
Revogar um token de acesso, terminando a sessão por trás dele. Todas as credenciais emitidas por essa sessão param de funcionar na próxima solicitação, em vez de na expiração do token.
Responde 200 se alguma coisa foi ou não revogada — um token desconhecido, expirado ou já revogado não é distinguido de um token ativo. Isso é exigido pela RFC 7009 e é o ponto: um endpoint que reportasse a diferença diria a qualquer pessoa que tivesse um token se ele ainda é válido.
Um token pertencente a outra organização é ignorado silenciosamente pelo mesmo motivo.
curl --request POST \
--url https://iam.basaltic.sh/v1/oauth/revoke \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data 'token=<string>' \
--data token_type_hint=access_tokenimport requests
url = "https://iam.basaltic.sh/v1/oauth/revoke"
payload = {
"token": "<string>",
"token_type_hint": "access_token"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/x-www-form-urlencoded"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
Authorization: 'Bearer <token>',
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({token: '<string>', token_type_hint: 'access_token'})
};
fetch('https://iam.basaltic.sh/v1/oauth/revoke', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://iam.basaltic.sh/v1/oauth/revoke",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "token=%3Cstring%3E&token_type_hint=access_token",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/x-www-form-urlencoded"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://iam.basaltic.sh/v1/oauth/revoke"
payload := strings.NewReader("token=%3Cstring%3E&token_type_hint=access_token")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://iam.basaltic.sh/v1/oauth/revoke")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/x-www-form-urlencoded")
.body("token=%3Cstring%3E&token_type_hint=access_token")
.asString();require 'uri'
require 'net/http'
url = URI("https://iam.basaltic.sh/v1/oauth/revoke")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/x-www-form-urlencoded'
request.body = "token=%3Cstring%3E&token_type_hint=access_token"
response = http.request(request)
puts response.read_body{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication required",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "An internal error occurred",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}Autorizações
Um token bearer OAuth 2.0, enviado como Authorization: Bearer <token>. Esta é a forma recomendada de autenticação.
Obtenha o token trocando o par de chaves de acesso de uma conta de serviço em POST /v1/oauth/token com grant_type=client_credentials. Esse é o fluxo padrão de credenciais de cliente; bibliotecas compatíveis com OAuth podem obter e renovar o token para você.
curl -s -u "$KEY_ID:$SECRET" -d grant_type=client_credentials \
https://iam.basaltic.sh/v1/oauth/token
Os tokens duram uma hora por padrão. O mesmo par de chaves de acesso também serve como credencial AWS SigV4 para o endpoint de objetos compatível com S3, que aceita somente esse método de autenticação.
Corpo
Resposta
Processado. Não carrega nenhum corpo e não diz nada sobre se o token existiu.

