/v1/auth/sessions/{id}Revoke a session as an administrator
operation ID: delete_v1_auth_sessions_by_id
Overview
Revoke a session as an administrator. The authentication API establishes identity and manages the roles, grants, sessions, and service credentials used for authorization.
When to use it
- Use it when an application needs to revoke a session as an administrator.
- Use it when a client needs to sign in, inspect its identity, or an administrator needs to manage access.
Quick example
Set the base URL and replace generated identifiers or credentials with values from your installation.
cURL
curl --request DELETE \
--url "$ORDINATE_URL/v1/auth/sessions/00000000-0000-4000-8000-000000000001" \
--header "Authorization: Bearer $ORDINATE_TOKEN"Expected output · 204
Session revoked
No response body.
The cURL request identifies the target resource and asks OrdinateDB to revoke a session as an administrator. The documented 204 response is session revoked.
How it works
OrdinateDB resolves a session or bearer credential to a principal, then evaluates roles, capabilities, and resource scope for each protected operation.
Reference
- Required capability
- admin
- Authorization scope
- handler-resolved target
Parameters
| Name | In | Required | Type and constraints |
|---|---|---|---|
id | path | yes | string |
Request body
This operation has no request body.
Responses
204Session revoked
No response body.
401Authentication required
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 401 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}403Admin capability required
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 403 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}404Session not found
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 404 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}503Model database is not configured
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 503 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}Code examples
These examples are generated from the source contract. Replace the base URL, credentials, identifiers, and minimal generated values for your instance.
JavaScript
const ordinateUrl = "http://localhost:8080";
const token = "<bearer-token>";
const response = await fetch(`${ordinateUrl}/v1/auth/sessions/00000000-0000-4000-8000-000000000001`, {
method: "DELETE",
headers: {
Authorization: `Bearer ${token}`
}
});
if (!response.ok) {
throw new Error(`OrdinateDB returned ${response.status}: ${await response.text()}`);
}
const data = null;
console.log(data);Related topics
- Authentication guide — Understand the prerequisite concepts and transport behavior for this operation.
- REST endpoint index — Find other operations in Authentication.