---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Revoke an API key"
description: "`access.api_keys.revoke` (POST /v1/{name}:revoke): Revokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data."
type: reference
product: platform
summary: "Revokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data."
updated: 2026-09-28
nav: false
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Revokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key:revoke`
- **Scope** `access:keys:write`
- **Effect** `destructive` — a successful call removes data; the CLI asks before it runs.
- **Collection** [api_keys](/docs/api/api_keys)

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | The name of the API key to revoke. Required. |
| `etag` | `string` | Revoke only if the current etag matches. |
| `validate_only` | `bool` | Validate without revoking. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/api_keys/{api_key}`, or `orgs/{org}/api_keys/{api_key}` for an org-wide key. |
| `uid` | `string` | `key_<cell><ulid>`; equals the name segment. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `ApiKeySpec` | Desired state. Required. |
| `status` | `ApiKeyStatus` | Observed state. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

### ApiKeySpec

| Field | Type | What it is |
| --- | --- | --- |
| `kind` | `ApiKeyKind` | Secret (server-side) or publishable (browser, `publishable_ok` methods only). Required. One of `secret`, `publishable`. |
| `scopes` | `string[]` | Scopes `<service>:<action>`, a subset of the creator's effective scopes. Required. |
| `label` | `string` | A free-form label, for example the talent id a key was minted for. |
| `expire_time` | `timestamp` | When the key stops verifying; required in unclaimed projects. |

### ApiKeyStatus

| Field | Type | What it is |
| --- | --- | --- |
| `observed_generation` | `int64` | The generation this status was computed from. Output only. |
| `conditions` | `Condition[]` | Ready, Reconciling, Stalled. Output only. |
| `secret` | `string` | The full key. Set only in the responses of Create and Roll. Output only. Never returned again. |
| `last4` | `string` | The last four characters, for display. Output only. |
| `principal` | `string` | The key's own principal. Output only. |
| `revoke_time` | `timestamp` | Set when the key was revoked. Output only. |
| `revoke_reason` | `RevokeReason` | Why the key was revoked. Output only. One of `user`, `rotation`, `leaked`, `claimed`, `claim_expired`, `org_deleted`, `admin`, `role_changed`, `logout`. |
| `last_use_time` | `timestamp` | When the key last verified, at snapshot granularity. Output only. |
| `last_use_ip` | `string` | The client address of the key's last use. Output only. |
| `role_bound` | `bool` | A device key (`sylphx login`): bound to the approving human's role in the org, and revoked when that role changes or the human leaves. Output only. |

### Condition

| Field | Type | What it is |
| --- | --- | --- |
| `type` | `string` | The condition type, for example `Ready`. |
| `status` | `ConditionStatus` | Whether the condition holds. One of `true`, `false`, `unknown`. |
| `observed_generation` | `int64` | The generation this observation was made against. |
| `reason` | `string` | A machine-readable UpperCamelCase reason. |
| `message` | `string` | A customer-safe human-readable message. |
| `severity` | `Severity` | How severe a FALSE condition is. One of `info`, `warning`, `error`. |
| `transition_time` | `timestamp` | When `status` last changed. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`RESOURCE_NOT_FOUND`](/docs/api/errors/RESOURCE_NOT_FOUND) — The named Resource does not exist or is not visible.
- [`ETAG_MISMATCH`](/docs/api/errors/ETAG_MISMATCH) — The etag sent does not match the Resource's current etag.
- [`INVALID_STATE`](/docs/api/errors/INVALID_STATE) — The Resource is in a state that forbids the call.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key:revoke" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{}'
```

**TypeScript**

```ts
const response = await sylphx.access.apiKeys.revoke({ name: 'orgs/acme/projects/shop/envs/production/api_keys/api-key' })
```

**Rust**

```rust
let mut req = sylphx::access::RevokeApiKeyRequest::default();
req.name = "orgs/acme/projects/shop/envs/production/api_keys/api-key".to_string();
let response = sx.access().api_keys().revoke(req).await?;
```

**CLI**

```bash
sylphx access api-keys revoke orgs/acme/projects/shop/envs/production/api_keys/api-key --yes
```

**MCP**

```json
{ "method_id": "access.api_keys.revoke", "args": {"name":"orgs/acme/projects/shop/envs/production/api_keys/api-key"} }
```
