# Revocation

Revoke a specific refresh token, making it no longer valid and forcing the user to re-authenticate if they need a new one.

Endpoint: POST /oidc/token/revocation

## Request fields (application/x-www-form-urlencoded):

  - `client_id` (string, required)
    Client ID.

  - `client_secret` (string, required)
    Client secret.

  - `token` (string, required)
    Token to revoke.

  - `token_type_hint` (string)
    A hint about the type of the token submitted for revocation.
    Enum: "access_token", "refresh_token"

## Response 200:

  - `200` (unknown)
    Token revoked successfully

## Response 400 fields (application/json):

  - `message` (array, required)
    Example: Bad request

  - `error_code` (number, required)
    Example: 400

## Response 500 fields (application/json):

  - `message` (string, required)
    Example: Something went wrong - Internal server error

  - `error_code` (number, required)
    Example: 500

